1. 通过响应队列投毒将 HTTP 头注入升级为严重漏洞 研究 | 2022-09-26 14:26 | portswigger.net | 原文 ↗ | #bug-bounty | #web-security | #proxy
2. How I stole the identity of every Yahoo user 博客 | 2017-05-09 00:00 | samcurry.net | 原文 ↗ | #bug-bounty | #email-security | #spoofing