Authentication Bypass Using Root Array
Lots of #bugbountytips get posted on twitter, but some of them are ... weird. Let's explore the technical details of one tweet to understand where this tip came from, why this tip was wrong, and eventually learn about the real underlaying vulnerability. This is a surprising turn of events! advertisement: Get my handwritten font https://shop.liveoverflow.com Checkout our courses on https://hextree.io Authentication Bypass Due to Empty Where Clause and SQL Injection in CodeIgniter https://liveoverflow.com/authenticati... Thank you Eslam for sharing the details with us! Follow Eslam on Twitter: / eslam3kll The #bugbountytips tweet: / 1526795822687346688 Eslam's old post: https://infosecwriteups.com/authentic... Eslam's new blog: https://eslam3kl.gitbook.io/blog/bug-.... Day[0] Podcast: https://dayzerosec.com/vulns/2022/03/... Chapters: 00:00 - Intro 00:41 - The bugbountytips Tweet 01:21 - The Original Blog 02:43 - Talking to Eslam about the Happy Accident 04:36 - Digging Deeper 05:39 - Researching Login Code with Codeigniter 06:54 - Example Vulnerable Login Code 08:08 - Improving the Writeup 09:18 - Surprise SQL Injection! 11:37 - Conclusion 12:31 - hextree =[ ❤️ Support ]= → per Video: / liveoverflow → per Month: / @liveoverflow 2nd Channel: / liveunderflow =[ 🐕 Social ]= → Twitter: / liveoverflow → Streaming: https://twitch.tvLiveOverflow/ → TikTok: / liveoverflow_ → Instagram: / liveoverflow → Blog: https://liveoverflow.com/ → Subreddit: / liveoverflow → Facebook: / liveoverflow

Local Root Exploit in HospitalRun Software

The Circle of Unfixable Security Issues

7 Authentication Concepts Every Developer Should Know

Trying to Find a Bug in WordPress

The Art of Authentication Bypass

My theory on how the webp 0day was discovered (BLASTPASS)

Every Level of Reverse Engineering Explained

How To Protect Your Linux Server From Hackers!

Google CTF - Authentication Bypass

Missing HTTP Security Headers - Bug Bounty Tips

#NahamCon2024: OAuth Secret | @BugBountyReportsExplained

Something is jamming GPS over Europe. Here's what we found

START YOUR TUESDAY WITH FAITH | TODAY GOD IS GIVING YOU UNEXPECTED OPPORTUNITIES | FATHER FREDDY ...

I Found The $200,000 Missing Lego

Do you know this common Go vulnerability?

Passkeys Explained: Are They Actually Better Than Passwords?

Inside Anthropic, the $965 Billion AI Juggernaut | The Circuit

How to Crack any Software

What is a Server? (Deepdive)

