Supras.io
Menu Close
  • Infosec
  • Open source
  • Various

Infosec

0

Road to SSRF : PDF generation and filter bypass on ASP.net application

Posted on 26 avril 2025 by Supr4s

Introduction When I’m on a bug bounty program, I prefer « big » applications that offer a wide range of features, different rendering interfaces and different roles. Here, after spending a good amount of time browsing the application and noting what it… Continuer la lecture →

Infosec
0

1-click ATO via XSS + cookie exfiltration despite HttpOnly

Posted on 15 février 2025 by Supr4s

Quick XSS write-up transformed into a 1-click account takeover despite a HttpOnly protected session cookie, on a HackerOne bug bounty program. The original XSS The XSS was found quickly, via an installation path and an injection directly into the URI… Continuer la lecture →

Infosec
0

New subdomain takeover case : Clever Cloud

Posted on 24 novembre 2023 by Supr4s

Image credit: DALL-E Recon It all started during a recon phase on a YesWeHack program, when I came across a rather curious 404 not found page that I’d never seen before :     The source code of the page… Continuer la lecture →

Infosec
0

Simple 1-click account takeover via Oauth misconfiguration

Posted on 11 juin 2023 by Supr4s

This is a vulnerability that I found on one of Bug Bounty CH’s customers, explained by their team in a blog post.

Infosec

Navigation des articles

Articles Précédents

About me

About me

© 2025 Supras.io. All rights reserved.
Hiero by aThemes