Get a Pentest and security assessment of your IT network.

News

0day writeup: XXE in uber.com

An interesting XXE in a popular product of Code42.com company, which could give access to backups of all users in a given company. The only option to break the service and get a bounty for pwning application was to find a 0day. Uber was using last version of product (5.2.0) of product, but not all customers have it installed. Since application was using Java, I knew I could read directories, and hence I immediately launched xxe-ftp server to extract data.”]

Source: https://httpsonly.blogspot.com/2017/01/0day-writeup-xxe-in-ubercom.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months