Burninator Sec

This blog is about the educational (and sometimes entertainment) value of simple hacks. For active vulnerabilities, real names are concealed.

Friday, July 19, 2019

Microsoft ID Open Redirect

›
Recently I submitted a Microsoft Bug Bounty report for an Open Redirect vulnerability in their Identity product. I found it by searching for...
Wednesday, July 3, 2019

Location-based Mobile Game Workaround

›
Here is a way to obtain items on-the-go while playing a popular location-based mobile game. Frequently I find that as a car passenger, I c...
Saturday, June 1, 2019

ctrl + s to Escape Chrome Kiosk

›
Consider a tablet at a store kiosk where the owner wants to display one particular web page to users. They don't want the user to have a...
1 comment:
Tuesday, May 28, 2019

Running Unicorn Payload Through Web Shell

›
This for escalating a low-privileged web shell to a Meterpreter shell. In this example, the Powershell execution policy was changed (using t...

Bypass Auth Lib

›
Recently I found a problem with an authentication library. The hyperlink the user clicks to access private content looks something like thi...
Friday, November 23, 2018

CVE-2020-15865 - Reporting C# Serialization: Remote Code Execution

›
The Stimulsoft Reports 2013.1.1600.0 library has code execution built in by design, and can be used to fully compromise the application serv...
Monday, August 13, 2018

Paywalls and Redirects

›
It is well known that paywalls can commonly be circumvented by editing the client side code so that the content is no longer hidden. But wha...
‹
›
Home
View web version
Powered by Blogger.