Erick Fernando

73 posts

Erick Fernando

Erick Fernando

@erickfernandox

https://t.co/qju40dBXtK

Brazil Katılım Mayıs 2011
261 Takip Edilen1.6K Takipçiler
Erick Fernando
Erick Fernando@erickfernandox·
@Hacker0x01 is responding to Support quickly; this time it only took them 11 months and 22 days to reply. 🫤
Erick Fernando tweet media
English
0
0
17
468
Erick Fernando retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 WARNING: A 0day vulnerability in Adobe Acrobat Reader is being actively exploited in the wild for 4 months now. Simply opening a malicious PDF can lead to data theft and potentially full system compromise. Adobe has not released a patch for this vulnerability.
International Cyber Digest tweet media
English
40
446
1.8K
139.3K
Erick Fernando
Erick Fernando@erickfernandox·
Critical Vulnerability Rewarded by Deutsche Telekom (T-Mobile Germany/European Union) #bugbounty #p1
Erick Fernando tweet media
English
6
6
250
14.2K
Erick Fernando
Erick Fernando@erickfernandox·
@cyberx00t Next, I generated a token using the OAuth code, and the generated token was an Amazon Cognito JWT. Using any regular user's Amazon Cognito token, I could access resources in any company system that user had access to.
English
0
0
0
76
Erick Fernando
Erick Fernando@erickfernandox·
A simple open redirect can wreak havoc. Simple open redirect -> misconfigured OAuth authentication flow -> privilege abuse using Amazon Cognito token #bugbounty #bugcrowd
Erick Fernando tweet media
English
5
16
348
14.3K
Erick Fernando
Erick Fernando@erickfernandox·
@cyberx00t The application had a centralized API login using OAuth, and one of the domains had an open redirect vulnerability. It was possible to inject into the redirect_uri that returns the OAuth code to the application, allowing me to capture it.
English
0
0
6
480