Hacking, AppSec, and Bug Bounty newsletter
2017-07-07 | Blind XXE, XSS triggered by CSP bypass, and How-to command injections
Friday, July 7
It’s PoC and How-to Friday. Enjoy!
Hunting in the Dark - Blind XXE by @ZephrFish
Making an XSS triggered by CSP bypass on Twitter by @tbmnull
How To: Command Injections by @jobertabma
You can see all the latest and greatest disclosures and bounties on www.hackerone.com/hacktivity
TWEET OF THE DAY
How about we create a /hackers.txt that says whether something is in scope or not of a vulnerability reward program and where to report it? - @sirdarckcat
OTHER ARTICLES WE’RE READING
Nuclear Facilities sustaining repeat malicious attacks says Homeland Security Dept. and F.B.I.
ABOUT ZERO DAILY
Zero Daily is a daily newsletter that highlights application security, bug bounty, and hacker focused topics. The content is curated with love by @luketucker and brought to you by HackerOne.
Friends don’t keep good things to themselves - forward this to your homies and co-workers. BTW, want to see who runs bug bounties?
Have a news tip / story to highlight? We’d love to hear about it. Email: firstname.lastname@example.org
Get this email forwarded to you? Click here to subscribe to the Zero Daily
Every day is still a school day and I'm always coming across things I've maybe seen before but in different implementations.