David Nechuta

10 posts

David Nechuta

David Nechuta

@david_nechuta

Software developer, bug bounty hunter

Prague, Czech Republic Katılım Aralık 2013
170 Takip Edilen796 Takipçiler
David Nechuta
David Nechuta@david_nechuta·
@smaury92 Nice :), I think the backend service is written for .NET, so that's probably why they use Windows.
English
0
0
0
0
smaury 4.7
smaury 4.7@smaury92·
@david_nechuta Great to know who was the one who turned my report into a duplicate 😂 At least I still found a P1 in AppSheet in the MySQL client which allowed a rogue server to read local files through the LOAD DATA LOCAL INFILE directive. I was really surprised they're using Windows servers.
English
1
0
1
0
Bug Bounty Reports Explained
Bug Bounty Reports Explained@gregxsunday·
The video about blind SSRF in Google Cloud for which @david_nechuta got $31k is out! Watch it to see how it's sometimes possible to exfiltrate data with blind SSRFs. You can also test your own skills with hands-on lab 😎 Enjoy! youtu.be/ashSoc59z1Y
YouTube video
YouTube
English
3
96
292
0
David Nechuta
David Nechuta@david_nechuta·
The SSRF GCloud Monitoring blog post has been updated. Added Google engineers solution for obtaining access token. They found a really cool way to get it by reducing number of requests required using regex and binary search. nechudav.blogspot.com/2020/11/31k-ss…
English
0
26
85
0