Doyensec · @doyensec
24 followers · 14 posts · Server infosec.exchange

In our latest blog post, learn how Szymon Drosdzol found a trivial SSRF bypass in 's `request` library (18M weekly downloads). Learn how to patch it and get the details on how other widely used libraries handle the same vector.

blog.doyensec.com/2023/03/16/s

#nodejs #doyensec #appsec

Last updated 1 year ago

Doyensec · @doyensec
22 followers · 13 posts · Server infosec.exchange

Congratulations 🎉 to our team member Adrian Denkiewicz for finding a nice 🐛Windows Installer - Elevation of Privilege Vulnerability (CVE-2023-21800) ! Keep an eye out for his upcoming blog post, detailing how he elevated to SYSTEM 🤯.

msrc.microsoft.com/update-guid

#doyensec #appsec #penetrationtesting

Last updated 2 years ago

Swissky :verified: · @swissky
908 followers · 308 posts · Server infosec.exchange

RT @doyensec
In our latest blog post, our chefs from 🇮🇹 and 🇫🇷 have collaborated to bring you a culinary masterpiece! Learn @lorenzostella and @maxenceschmitt's recipe for a tasty arbitrary file write to RCE via abusing files. Bon appétit!

blog.doyensec.com/2023/02/28/n

#uwsgi #doyensec #appsec

Last updated 2 years ago

Doyensec · @doyensec
18 followers · 12 posts · Server infosec.exchange

In our latest blog post, our chefs from 🇮🇹 and 🇫🇷 have collaborated to bring you a culinary masterpiece! Learn Lorenzo Stella and Maxence Schmitt's recipe for a tasty arbitrary file write to RCE via abusing files. Bon appétit!

blog.doyensec.com/2023/02/28/n

#uwsgi #doyensec #appsec #appsecurity #penetrationtesting

Last updated 2 years ago

Doyensec · @doyensec
15 followers · 11 posts · Server infosec.exchange

PESD Exporter templates!

Currently matches OAuth2/OpenID/SAML flows

Diagrams are enriched with frames surrounding the standard flow + custom flags

Ctrl+f to see core flags & discover custom implementations at a glance

Example: SAML response double spending after the frame

Release blog post: blog.doyensec.com/2023/02/14/p
Code: github.com/doyensec/PESD-Expor

#appsec #doyensec #appsecurity #penetrationtesting

Last updated 2 years ago

Doyensec · @doyensec
15 followers · 11 posts · Server infosec.exchange

Check out our new PESD Burp Suite extension. It converts proxy history to interactive diagrams!

Easily document findings or convey complicated logical application flows in seconds!

Blog: blog.doyensec.com/2023/02/14/p

Code: github.com/doyensec/PESD-Expor

#doyensec #appsec #pentesting

Last updated 2 years ago

Doyensec · @doyensec
15 followers · 11 posts · Server infosec.exchange

PESD's Mask Rand can map strings / UUIDs to variables & reshape diagrams for more clarity.

Eliminate time wasted searching for the same UUID in multiple API calls and make reports even better!

Plus Burp Suite comments can be notes in the sequence diagram.

#appsec #doyensec

Last updated 2 years ago

Doyensec · @doyensec
15 followers · 11 posts · Server infosec.exchange

Congrats @felix on "Hacking the cloud with SAML" making PortSwigger's Top 10 Web Hacking Techniques! To celebrate, is releasing our tool to generate exploitation PoCs for one of the issues he found. Enjoy!

github.com/doyensec/CVE-2022-3

portswigger.net/research/top-1

#doyensec #appsec #devsecops #secdevops

Last updated 2 years ago

Doyensec · @doyensec
12 followers · 6 posts · Server infosec.exchange

Need help securing against the arbitrary file read described in CVE-2022-44268? The pictured policy change can mitigate it for you.

For more recommendations on hardening your security policies check out our free tool at:
imagemagick-secevaluator.doyen

#imagemagick #doyensec #appsec #secdevops #securityresearch

Last updated 2 years ago

Doyensec · @doyensec
11 followers · 5 posts · Server infosec.exchange

Teleport just published the report from our latest round of auditing their Microsoft RDP Desktop Access tool. Read it today to see the findings & our approach to clients' product security

doyensec.com/research.html#96

#doyensec #appsec #security #devsecops #secdevops

Last updated 2 years ago

Doyensec · @doyensec
11 followers · 4 posts · Server infosec.exchange

A sneak peek at some of the swag we give our team for finding critical vulnerabilities for our clients! As a company of researchers from the top down, we like to celebrate cool bugs!

#doyensec #appsec

Last updated 2 years ago

Doyensec · @doyensec
11 followers · 3 posts · Server infosec.exchange

The second edition of 's "CloudSec Tidbits" has just been published! Learn all about Cognito User Attributes tampering and experiment with it in our free lab. Check it out today!

blog.doyensec.com/2023/01/24/t

#doyensec #aws #cloudsecurity #appsec #devsecops

Last updated 2 years ago

Doyensec · @doyensec
9 followers · 1 posts · Server infosec.exchange

It's been six wild years since first opened for business! We appreciate all the clients and team members (past and present) who have contributed to our success. The next six will be even more amazing!

#doyensec

Last updated 2 years ago

Doyensec · @doyensec
11 followers · 2 posts · Server infosec.exchange

It's been six wild years since first opened for business! We appreciate all the clients and team members (past and present) who have contributed to our success. The next six will be even more amazing!

#doyensec

Last updated 2 years ago

buherator · @buherator
590 followers · 453 posts · Server infosec.exchange

RT @Doyensec@twitter.com

Announcing the release of `safeurl` - a library to help devs "Build with Security"! This module provides tested & versatile protection against Server Side Request Forgery (SSRF)! Hurry and check it out!

blog.doyensec.com/2022/12/13/s
github.com/doyensec/safeurl

🐦🔗: twitter.com/Doyensec/status/16

#golang #doyensec #appsec

Last updated 2 years ago