Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
infosecau
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Frontier class vulnerabilities: it gets worse before it (maybe) gets better
(shubs.io)
1 points
by
infosecau
2mo ago
|
0 comments
2.
▲
I found a WordPress RCEs with GPT5.6 and $25
(slcyber.io)
404 points
by
infosecau
2mo ago
|
227 comments
3.
▲
The down fall of bug bounties
(shubs.io)
2 points
by
infosecau
4mo ago
|
0 comments
4.
▲
High fidelity check for Next.js/RSC RCE (CVE-2025-55182 and CVE-2025-66478)
(slcyber.io)
3 points
by
infosecau
10mo ago
|
0 comments
5.
▲
Analyzing the Next.js Middleware Bypass (CVE-2025-29927)
(slcyber.io)
2 points
by
infosecau
2y ago
|
0 comments
6.
▲
by
infosecau
3y ago
Yes, as we were able to download the database for CoCCA's web application (from the box.com backups) for any of the ccTLDs managed by CoCCA, we could decrypt the admin hash and then login to the CoCCA administration panel and modify&#x
7.
▲
by
infosecau
3y ago
I prefer bashupload.com or transfer.sh for this. Both alternatives have worked well for me. Alternatively, you can check out magic wormhole (for a more secure transfer of files between two terminals): https://magic-wormhole.readt
8.
▲
So, you want to get into bug bounties?
(shubs.io)
2 points
by
infosecau
4y ago
|
0 comments
9.
▲
Exploiting Static Site Generators: When Static Is Not Static
(blog.assetnote.io)
21 points
by
infosecau
4y ago
|
0 comments
10.
▲
by
infosecau
4y ago
Assetnote | Backend Engineer | Remote Australia By joining our growing engineering team at Assetnote as a Backend Engineer, you will be responsible for extending the capabilities of our Continuous Security Platform through developing our se
11.
▲
Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135)
(blog.assetnote.io)
1 points
by
infosecau
4y ago
|
0 comments
12.
▲
Cloudflare Pages, part 1: The fellowship of the secret
(blog.assetnote.io)
28 points
by
infosecau
4y ago
|
2 comments
13.
▲
Hacking a Bank by Finding a 0day in DotCMS
(blog.assetnote.io)
3 points
by
infosecau
4y ago
|
0 comments
14.
▲
by
infosecau
5y ago
Assetnote | Site Reliability Engineer | Remote Australia By joining our growing engineering team at Assetnote as a Site Reliability Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform. In t
15.
▲
Eliminating Dangling Elastic IP Takeovers with Ghostbuster
(blog.assetnote.io)
2 points
by
infosecau
5y ago
|
0 comments
16.
▲
by
infosecau
5y ago
Assetnote | DevOps Engineer | Remote Australia By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform. In this role, you will b
17.
▲
by
infosecau
5y ago
# Assetnote - Continuous Security At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be bu
18.
▲
Turning Bad SSRF to Good SSRF: Websphere Portal
(blog.assetnote.io)
2 points
by
infosecau
5y ago
|
0 comments
19.
▲
by
infosecau
5y ago
# Assetnote - Continuous Security At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be bu
20.
▲
by
infosecau
5y ago
Assetnote | Frontend Engineer | Remote Australia At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform
21.
▲
Exploiting GraphQL
(blog.assetnote.io)
2 points
by
infosecau
5y ago
|
0 comments
22.
▲
by
infosecau
5y ago
There's not really much user interaction required. You just have to engage the victims cell phone when sending the OTP. The voicemail hack doesn't require any user interaction.
23.
▲
Taking over Uber accounts through voicemail
(blog.assetnote.io)
15 points
by
infosecau
5y ago
|
5 comments
24.
▲
Hacking IIS
(drive.google.com)
1 points
by
infosecau
6y ago
|
0 comments
25.
▲
by
infosecau
6y ago
Assetnote | Engineer (Backend & API) | Remote Australia At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, t
26.
▲
Attack of the clones: Git clients remote code execution
(blog.blazeinfosec.com)
5 points
by
infosecau
6y ago
|
0 comments
27.
▲
Finding Hidden Files and Folders on IIS Using BigQuery
(blog.assetnote.io)
1 points
by
infosecau
6y ago
|
0 comments
28.
▲
by
infosecau
6y ago
Paid in USD, worked remotely (conversion rates)
29.
▲
by
infosecau
6y ago
Author of the blog post here. I want to make it clear that I had multiple full-time jobs along the way that paid over 200k AUD/year and it required a lot of effort to do both bug hunting and work full time. I only did bug bounty huntin
30.
▲
Hacking on Bug Bounties for Four Years
(blog.assetnote.io)
89 points
by
infosecau
6y ago
|
10 comments
More ›