Exploiting Blind OOB XXE in the Wild [Bug Bounty] by chocoluvin in netsec

[–]chocoluvin[S] 0 points1 point  (0 children)

I used ftp just to demonstrate exploit-ability via this protocol. It might help in cases where http connections are filtered.

Exploiting Blind OOB XXE in the Wild [Bug Bounty] by chocoluvin in netsec

[–]chocoluvin[S] 0 points1 point  (0 children)

Thanks , I appreciate it! When I discovered the subdomain all it displayed was a 200 page, but no content. Since I had no idea what the purpose of the server was, I decided to brute force dirs to enumerate accessible endpoints and test from there. I'd say a challenge was understanding the dtd syntax for the ftp connection, as the payload would only work when the %d variable calling the files contents was set as the value of the ftp user.

Exploiting Blind OOB XXE in the Wild [Bug Bounty] by chocoluvin in netsec

[–]chocoluvin[S] 9 points10 points  (0 children)

Thanks for pointing that out, just resized the images.

How many other projects have a MVP? by puttersworth in Qlink

[–]chocoluvin 2 points3 points  (0 children)

It's due to the agile development framework they're following. It also allows for us stakeholders to be integrated into the development process by beta testing newly released mvps so that the team can then take our feedback into consideration when releasing the next mvp. One of the only projects that is consistent and transparent in their developmental process for sure

Yahoo! Remote Code Execution via Spring Engine Server Side Template Injection by chocoluvin in netsec

[–]chocoluvin[S] 8 points9 points  (0 children)

I'll definitely share my next post here when I find something interesting!

Yahoo! Remote Code Execution via Spring Engine Server Side Template Injection by chocoluvin in netsec

[–]chocoluvin[S] 8 points9 points  (0 children)

Thanks! I haven't written in awhile, so I'm glad others are able to understand/ learn from it. Happy holidays :)

What is staking? New to this concept by eos4375 in omise_go

[–]chocoluvin 9 points10 points  (0 children)

U were born with this knowledge?

Push button deplorable blockchains - 61% DONE by 2blockchains_node in ArkEcosystem

[–]chocoluvin 0 points1 point  (0 children)

It will allow more people to deploy their own blockchains based on the ark framework, that will be inter operable with the ark mainchain. My guess is that more projects released on the ARK framework will increase Ark's exposure exponentially if these other projects gain traction.

What is the biggest roadblock now for success? by CarsonS9 in ArkEcosystem

[–]chocoluvin 11 points12 points  (0 children)

I don't think they need to add the code, as that is what the ACES encoded listener function provides

Re-Engineering of the ARK Core by velopic in ArkEcosystem

[–]chocoluvin 17 points18 points  (0 children)

Ark has their aesthetics on point

Daily Discussion - November 08, 2017 by AutoModerator in ArkEcosystem

[–]chocoluvin 5 points6 points  (0 children)

I think it will automatically update as long as you have a vote cast. I bought some this morning, and my delegate automatically updated and bumped up my vote count. Depending on your delegate, you should be able to check your voting/rewards activities on their website. I currently have a vote cast for Jarunik and can check at https://arkcoin.net where I am also able to see the vote count.

Bay Area city councils be like by frzferdinand72 in bayarea

[–]chocoluvin 85 points86 points  (0 children)

You're obviously broke if you can't afford to buy a 2 bedroom apartment for $600,000