Introduction Cross site scripting (XSS) is one of the most prevalent bugs in todays web applications. When doing a black…
How to hack a Google Firebase Database for easy wins
Use exposed log and configurations files to find credentials and other sensitive information.
Use Broken Link Hijacking to find stored XSS in web applications.
Injection malicious formulas into exported CSV files
Steal AWS credentials via Server Side Request Forgery(SSRF) attacks.
Use SVG images to gain stored XSS via uploading an SVG image.
Open S3 buckets can be used to find sensitive data. Dont forgot about google cloud storage though.
RCE exposed kubernetes API
RCE exposed docker API