r3s1n
68 posts

r3s1n
@ResinSec
ethical hacker, student, coder. working on many projects i’ll never finish. my kung fu is stronger than yours
New York, USA Katılım Ekim 2021
152 Takip Edilen20 Takipçiler
r3s1n retweetledi
r3s1n retweetledi
r3s1n retweetledi

After 6 months of hard work... Monad is finally going to be launched in its open beta phase!!!
It will be available at **beta.monad.ilioslabs.dev**.
Twitter: x.com/IliosLabs
ProductHunt: producthunt.com/posts/monad
Discord: discord.gg/b8ugMm7nvc
#Monad #launchday
English
r3s1n retweetledi
r3s1n retweetledi
r3s1n retweetledi

Monad is on ProductHunt! Check it out at producthunt.com/posts/monad and make sure to upvote + share the link so we can get a great launch on the 23rd!
English

Just wanted to let you all know, @IliosLabs is working on a new project called Monad, which lets you share your own code snippets with a really intuitive tagging system. I'd definitely suggest checking them out when it releases! #infosec #bugbountytips
English
r3s1n retweetledi

Shoutout to @ResinSec for hacking Monad and alerting us to many vulnerabilities!
English
r3s1n retweetledi
r3s1n retweetledi

Nginx Path Traversal @403Timeout
httpx -l url.txt -path "///////../../../../../../etc/passwd" -status-code -mc 200 -ms 'root:'
#bugbountytips #infosec

Filipino
r3s1n retweetledi
r3s1n retweetledi

If the main endpoint is forbidden we can also check for the backup file.
/blog/wp-config.php => 403 Forbidden
/blog/wp-config.php.bkp => 200 OK
#bugbountytips #bugbounty #infosec

English
r3s1n retweetledi
r3s1n retweetledi

Cache Poisoning at Scale:
Identifying and Exploiting over 70 Cache Poisoning Vulnerabilities
youst.in/posts/cache-po…
English

@rootxyash Biggest security risk to most WordPress sites is plugins/themes. Fingerprint the versions being used and try to see if a CVE exists. If so, how easy would it be to make a PoC? Is there an existing exploit on github/exploit-db?
English

@rootxyash Most of the time SSRF via xmlrpc.php will be closed as N/A or informational. Usually cited on the basis that HTTP and DNS requests aren't valid vulnerabilities unless you could exfiltrate information, which you can't do here
English
r3s1n retweetledi















