Ben Hayak – Security Blog
-
1
Google Security Vulnerability Reward Program: Google Finance Stored XSS
-
2
Google Security Vulnerability Reward Program: Google Bookmarks Stored XSS
-
3
Updates
-
4
Google Security Vulnerability Reward Program: Google Website Optimizer - Stored XSS
-
5
Google Security Vulnerability Reward Program: Take Control Over Adwords Service!
-
6
Google Security Vulnerability Reward Program: Google Adwords Billing poisoning
-
7
Facebook Vulnerability - Destroy Any advertisements/badges! (permission issue)
-
8
Uncrackable? - Exceptional Cracking
-
9
eBay Security 2011 & 2012 Wide Security Vulnerabilities
-
10
Twitter Vulnerability Potential XSS Worm!!! another hero?
dead && end
-
1
Dialogic PowerMedia XMS Multiple Vulnerabilities
-
2
Microcorruption Write-ups (1 - 10)
-
3
Argument Injection Hammer Burp Suite Extension
-
4
Cloudiot Write-ups (Internal NCC Group CTF 2019)
-
5
Multiple Vulnerabilities in Alcatel Flip 2
-
6
Eversec Cloud Write-ups (Internal NCC Group CTF 2020)
-
7
Multiple Vulnerabilities in Multiple Vulnerabilities in KaiOS Pre-installed Mobile Applications
-
8
Exploring the Security of KaiOS Mobile Applications
-
9
An Example WAF XSS Bypass
-
10
Multiple Vulnerabilities in TCPDF
g0tmi1k
-
1
Issues + Updates With 'Boots 2 Roots'
-
2
Vulnerable by Design (Part 3)
-
3
VulnImage - Automated Method
-
4
VulnImage - Manual Method
-
5
Hackademic RTB1
-
6
Hackademic RTB2
-
7
Kioptrix - Level 4 (Limited Shell)
-
8
Kioptrix - Level 4 (SQL Injection)
-
9
Kioptrix - Level 4 (Local File Inclusion)
-
10
Stripe CTF 2.0 (Web Edition)
Security Obscurity Blog
-
1
Wordpress TimThumb Exploit (Remote Code Execution)
-
2
OsCommerce Malware Infection
-
3
Wordpress XSS Vulnerability + IE 8 Exploit
-
4
Have fun with scammers
-
5
Ubuntu Server Exploit (Local Privilege Escalation)
-
6
Foxit Reader PDF Exploit + Windows 7 Backdoor
-
7
Windows Exploit Development Remote Stack BoF
-
8
Build Metasploit Module (Windows Exploit Development)
-
9
Poste Italiane phishing emails
-
10
CartaSi phising email part 1/2
The Cobra Den Blog
-
1
Words with Friends - Revisited
-
2
Making Persistent Changes to an Android Emulator
-
3
Maliciously Loading an Application's Native Libraries
-
4
Building a Better Emulator - Part 1
-
5
Fixing Resource Identifiers in Disassembled Apps
-
6
An Introduction to CobraDroid 1.0
-
7
Is Facebook Really Reading your Text Messages?
-
8
Hooking SQLCipher with Xposed
-
9
Attacking Bound Services on Android
-
10
Tool Release: sefcontext-parser / sefparse