π©βπ»IW Weekly #72: GraphQL Hacking, SSO Vulnerabilities, Race Condition Vulnerabilities, SQLMap & Server Side Request Forgery Tips, Sandwich Attack and many more..
Welcome to the #IWWeekly72 - the Monday newsletter that brings the best in Infosec straight to your inbox.
To help you out, we have 5 Articles, 4 Threads, 3 Videos, 2 Job Alerts and a Special Item π«’
Read, upskill yourself and spread love to the community π
Excited? Letβs jump in π
π 5 Infosec Articles
- @meispi_ found a race condition vulnerability on a GraphQL API endpoint and has written about his find.
- @rohitcoder goes over different vulnerability classes in SSO (Single Sign-On) implementations.
- Thorough reconnaissance could lead to treasure trove, read about different tricks that @armandjasharaj used to uncover PII data.
- Checkout @albinowaxβs latest research on web race conditions which is being presented at Blackhat, DEF CON, Nullcon, and more.
- Some of the top researchers at @SynackRedTeam teamed up and ended up finding multiple exploits resulting in multiple CVEs, find the details of exploits in the article.
π§΅4 Trending Tweets
- Elevate your SQLmap skills with this trick by @kuldeepdotexe, for faster issue reproduction in bug bounty triaging.
- Level up your SSRF skills with insightful tips from @Rhynorater in this thread.
- Unlock the secrets of enumerating UUIDs for IDORs with @Rhynorater.
- @Rhynorater shares some tips on how to look for XSS.
π½οΈ 3 Insightful Videos
- @NahamSec's latest video offers valuable insights on leveraging AI to enhance and supplement your hacking abilities.
- Discover the intriguing 'Sandwich Attack' by @0xLupin New to IoT and firmware hacking?
- Dive into firmware analysis in this informative video by @thecybermentor.
πΌ 2 Job Alerts
- IDFC FIRST Bank is looking to onboard a Security Engineer in Mumbai region.
- CloudSek is seeking a Cyber Security Analyst in Bengaluru.
π 1 Special Item
- Noir is a tool that maps attack surface using the source code, developed by @hahwul.
Thatβs all for this week. Hope you enjoyed these incredible finds and learned something new from todayβs newsletter. Meet you again next week hacker, until then keep pushing πͺ
This newsletter would not have been made possible without our amazing ambassadors.
Resource contribution by: Nikhil A Memane, Hardik Singh, Ayush Singh, Manikesh Singh, Bhavesh Harmalkar, Bimal Kumar Sahoo, Vinay Kumar, Shlok
Newsletter formatting by: Nikhil A Memane, Ayush Singh, Hardik Singh, Siddharth, Nithin R
Lots of love
Editorial team,
Infosec Writeups
π§
If you have questions, comments, or feedback reach out to us on Twitter @InfoSecComm or email [email protected]