Tweets
@soaj1664ashar well done with the location hash xss at #Paypal :)
I've found a XSS issue on Twitter: http://majorsecurity.net/blog/2012/10/07/xss-via-hashtag-on-twitter-dot-com/ …
I've just reported 5 stored + 4 reflected xss on AT&T official website to secure@att.com .
@totally_unknown okay then I'll be forward to read the details whenever you'll share to the community after google has fixed it :)
@totally_unknown I bet it's the xss inside swfupload.swf found by neal poole. :)
currently pentesting some major websites as part of their bug bounty programs.
@garethheyes: 35 chars: http://challenge.hackvertor.co.uk/?challenge=3&input=/ …><svg onload='-/"/-[alert(1)]//'/>
Google Chrome's use of GPU acceleration leads to kernel panic in new macbook air: http://arstechnica.com/apple/2012/06/google-confirms-chrome-bug-is-causing-crashes-on-latest-macbook-air/ …
Paypal Bug Bounty for Security Researchers: https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=security/reporting_security_issues …
@0x6D6172696F do you know that paypal has started it's own "bug bounty" program for security researchers? https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=security/reporting_security_issues …
Die von mir gemeldete Sicherheitslücke ( CVE-2012-0674 ) wurde mit iOS 5.1.1 behoben: http://support.apple.com/kb/HT5278
Facebook's Sec-Team is using CVE-2012-1823 as honeypot to find new employees as "security engineer" in Menlo Park, CA: http://www.facebook.com/?-s
Google is upping their bug bounty to 20k for code execution, 10k for SQLi and 3,133.7 for XSS/XSRF: http://googleonlinesecurity.blogspot.com/2012/04/spurring-more-vulnerability-research.html …
xss - Apple Safari 5.1.4 on iOS 5.1 - Adressbar spoofing vulnerability: http://www.majorsecurity.net/safari-514-ios51-advisory.php …
Apple Safari 5.1.4 on iOS 5.1 - Adressbar spoofing vulnerability: http://www.majorsecurity.net/safari-514-ios51-advisory.php …
Cookies trotz "HttpOnly" auslesen: http://secalert.net/post.php?id=65
Burp Suite Pro 1.4.03 erschienen - nun mit CSRF Generator und weiteren Features: http://secalert.net/post.php?id=62
@CureSec Congratz zur eigenen GmbH. Wuensch euch alles erdenklich Gute und viel Erfolg. :)
@secalert har ikke tweetet ennå.
Det ser ut til at det tar en stund å laste.
Twitter kan være overbelastet eller under en midlertidlig stans. Prøv igjen eller besøk Twitter Status for mer informasjon.
Marker dette mediet
Dette har allerede blitt markert som sensitivt materiale.
David Vieira-Kurz
Pedram Amini