NCS-Competition
hackerone-reports
Our great sponsors
NCS-Competition | hackerone-reports | |
---|---|---|
1 | 2 | |
5 | 3,182 | |
- | - | |
0.0 | 6.4 | |
almost 3 years ago | about 1 month ago | |
Python | Python | |
- | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
NCS-Competition
-
Help with Decompiling Binary file
The correct decompilation for the binary's main() function and the bm01.zip file that contains the binary executable itself can both be found here: https://github.com/HHousen/NCS-Competition/tree/master/Binary/BM01. (The correct decompilation is in the readme.)
hackerone-reports
- GitHub - reddelexc/hackerone-reports: Top disclosed reports from HackerOne
-
XXE (XML External Entity) Attack & Prevention
There was an interesting case on Hackerone where the XMP metadata of a JPG file was getting parsed unsafely. There are many other interesting XXE bugs there as well if you want to take a look.
What are some alternatives?
XFFF - CTF servers using socket() and No-sql
reconftw - reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Ciphey - ⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
hackthebox - Notes Taken for HTB Machines & InfoSec Community.
CTF-Writeups - A collection of write-ups and scripts from various CTFs I've participated in
Exif-Maniac - Post Exploitation Framework via Exif Data in images
SpringShell - Spring4Shell - Spring Core RCE - CVE-2022-22965
OWASP-Xenotix-XSS-Exploit-Framework - OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework.
CVE-2021-40444 - CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
jira-mobile-ssrf-exploit - Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)
Egyscan - Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious threats. Let's delve into the tasks and functions that make Egyscan an indispensable tool in your security arsenal:
xsser - Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.