PinnedClaudio Salazar·Jan 20, 2025Introducing lorito, an HTTP security suiteYou’re participating in a bug bounty program and the target application accepts a user-controlled URL. How can you exploit that?A response icon1A response icon1
Claudio Salazar·Mar 25, 2021Pentester’s tricks: Local privilege escalation in OpenVASIt’s not a common scenario but if during a pentesting you get access to some machine with a user that has sudo rights to execute openvas…
InThe StartupbyClaudio Salazar·Mar 1, 2021Best Practices to Mitigate JSON Interoperability Vulnerabilities“An Exploration of JSON Interoperability Vulnerabilities” by Jake Miller was published last week. It’s an interesting research about…A response icon1A response icon1
InITNEXTbyClaudio Salazar·Feb 14, 2021Another variant to compromise frontend developers by malicious packagesSome days ago I was watching 10 Things I Regret About Node.js and the introduction to Deno started with this slide about security.
InThe StartupbyClaudio Salazar·Dec 1, 2020Don’t Scan My Website I: Exploiting an Old Version of WappalyzerDisclaimer: I discovered this vulnerability in February and it was fixed in May 2020 (version 5.10.2 and new branch 6.x) due to the change…
InalertotbyClaudio Salazar·Jul 15, 2019“Web scraping considered dangerous”: Leaking files from the spider’s hostThis is the next post of this serie called “Web scraping considered dangerous”. You can read the previous post here and as an update, my…
InalertotbyClaudio Salazar·May 14, 2019“Web scraping considered dangerous”: Exploiting the telnet service in scrapy < 1.5.2Disclaimer: scrapy 1.5.2 has been released on January 22th, to avoid being exploited you must disable telnet console (enabled by default)…A response icon1A response icon1
InspectbyClaudio Salazar·Apr 26, 2019Exploiting the scraperOriginally it was published here: https://spect.cl/blog/2014/08/exploiting-the-scraper/
InalertotbyClaudio Salazar·Apr 15, 2019Un buffer overflow para gobernar ChileEl año pasado hubo en Chile una charla titulada “Chile Exposed: un puerto para gobernarlos a todos” haciendo referencia al anillo del…A response icon2A response icon2
InalertotbyClaudio Salazar·Feb 6, 2019Un sigiloso ataque en SII.cl[This post is only available in Spanish because the target audience is in Chile]