Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

My first RCE: a tale of good ideas and good friends

Summary

Joseph Thacker recounts his first RCE and first critical: spraying SSRF parameter payloads with meg across 600,000+ public bug bounty hosts, catching callbacks on a bare python http.server, then isolating the vulnerable host and parameter with split and grep.
Published
Collected

original ↗

Related coverage

back