Open in app
Home
Notifications
Lists
Stories

Write
Master SEC
Master SEC

Home

May 28, 2021

The beauty of chaining client-side bugs

This is part of a report of a bug that I sent back in 2020, changing of course the program name for obvious reasons. Introduction When someone asks me about how it is like hacking I tell them it’s like being an artist 🎨. This involves a lot of love, imagination…

Bug Bounty

10 min read

The beauty of chaining client-side bugs
The beauty of chaining client-side bugs

Dec 14, 2019

Weaponizing BURP to work as an evil SSRF Confluence Server.

I was doing bounty on a private H1 program that interacts with various external services one of them was Atlassian Confluence and Jira. As you know, you can run Atlassian on their cloud service at Atlassian.net, or in your own server. …

Ssrf

3 min read

Weaponizing BURP to work as an evil SSRF Confluence Server.
Weaponizing BURP to work as an evil SSRF Confluence Server.

Oct 11, 2019

Bypass Uppercase filters like a PRO (XSS Advanced Methods)

a code injection inside javascript code can be a headache… But nothing is impossible While we are not working on Pentesting for companies, we love to Bug Hunting on Hackerone. We founded a vulnerable section on a site, with some sort of google analytics code, vulnerable to a URL XSS. …

Xss Attack

4 min read

Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Bypass Uppercase filters like a PRO (XSS Advanced Methods)
Master SEC

Master SEC

It Security company from Argentina. Penetration Testing, Red Team, Bug Bounty, Training.

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable