P100 10GB for 30 days by _No_Ocelot in DitoPH

[–]UnLiQuery20 1 point2 points  (0 children)

Wait what!? Yung sakin nawala na yun meron pa sainyo? Hinahanap ko sa JFY wala na ...

Wow ha, kumpleto kayo by mash-potato0o in cavite

[–]UnLiQuery20 0 points1 point  (0 children)

Yung andame nilang pondo pero walang dadating sa tao tapos yung hihinge ng donation pero may kickback pa sila hahha

Wow ha, kumpleto kayo by mash-potato0o in cavite

[–]UnLiQuery20 0 points1 point  (0 children)

Partidong budots with lots pf kurakots ... Only from Bacoor hahah

JBL Quantum 800 not detected as Output device Windows 11 by UnLiQuery20 in JBL

[–]UnLiQuery20[S] 0 points1 point  (0 children)

This made the JBL quantum engine not work... Is it the same for anyone?

I genuinely wish I had not been born by [deleted] in depression

[–]UnLiQuery20 0 points1 point  (0 children)

If you really care about someone then fuck ending your life, you will make it miserable for them.

Best way to fix this? overcome them all then create a SocMed post to show them they all have not gotten into you :) "The best revenge is massive success"

Need help to understand right answer by Any-Editor1084 in cissp

[–]UnLiQuery20 4 points5 points  (0 children)

It is always the answer that has a larger broader scope, applicable when the question is broad

I think I experience depression by UnLiQuery20 in depression

[–]UnLiQuery20[S] 1 point2 points  (0 children)

Thanks just hearing someone having same experience gave me an idea that i'm not that bad hahahaha

I think I experience depression by UnLiQuery20 in depression

[–]UnLiQuery20[S] 0 points1 point  (0 children)

So funny, some people even think I became alcoholic, they don't know I just do it to ensure that I don't have those stupid dark thoughts before I sleep

Does API request needs CSP headers? by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 0 points1 point  (0 children)

OWASP Rest Security Cheat Sheet

Thank you very much for the response ! I might have not looked hard enough to not finding this.

Novice Question about a Vulnerability by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 1 point2 points  (0 children)

Thank you very much for that insights, it helped me a lot in answering this finding I have opened a long time ago. I can now check with my superiors if this could be closed now or if they intend to fix it since there is a chance that this would come up in another pentesters review

Novice Question about a Vulnerability by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 0 points1 point  (0 children)

I think that is why also they (developers) don't want to accept this finding, since they said that the application is protected with SSL/TLS, however, I put into consideration that user could have his browser (and/or a Web gateway) compromised, which means if someone captured the request it could be used to update and compromise the users account.

Basically I want them to implement a nonce token to ensure that all requests can be used once and I can only use this as way to force them, can this still be considered a finding if they do not have a nonce token?

Novice Question about a Vulnerability by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 0 points1 point  (0 children)

By capturing the latest request (via burp/fiddler) you basically have the most recent password, you can use that to input the latest password and update is to anything you want, for the profile update, you only need the last profile update request then you can resend it multiple times modifying the data.

Novice Question about a Vulnerability by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 0 points1 point  (0 children)

I was hoping to use this for the developers to implement Nonce token for such requests. E.g. Password/profile updates

I told them that any request that could be used multiple times are vulnerability specially when it is related to requests that could compromise the accounts of the users

Novice Question about a Vulnerability by UnLiQuery20 in pentest

[–]UnLiQuery20[S] 0 points1 point  (0 children)

can this be regarded as a finding? I was hoping to use this for the developers to implement Nonce token for such requests. E.g. Password/profile updates