The Dark Side of JWT: Exploiting Token Vulnerabilities
Many modern applications use JSON Web Tokens (JWTs) to authenticate and authorize users in their functionalities. In this article, we will explore vulnerabilities in
Many modern applications use JSON Web Tokens (JWTs) to authenticate and authorize users in their functionalities. In this article, we will explore vulnerabilities in
Threat modeling is a cyclic process to avoid future problems. Just like brushing your teeth, that prevents decay, tartar or dental calculus, threat modeling
Key Findings * We analyzed over 590 million credentials from more than 20 million unique infected computers worldwide. * Brazil is one of the most affected
If you are a slightly above-average user – and you certainly are; otherwise, you wouldn't be reading this article =D – you'
File uploads have become essential for numerous web applications, ranging from social media platforms to cloud storage services. They enable users to easily share
In my recent research, I identified a critical vulnerability in osCommerce v4, specifically a Remote Code Execution (RCE) vulnerability enabled by bypassing file upload
Abstract On February 13th, 2024, during the patch Tuesday, Microsoft disclosed the CVE-2024-21338 based on the security report made by Jan Vojtěšek
In this article, we will discuss a case of SSRF in a GCP environment and how exploiting this vulnerability led to the idea and
Greetings to all, This article aims to provide insights and stories about vulnerabilities in web applications and their impacts. Throughout this text, I will