Denis Makrushin
  • Blog
  • Research
Denis Makrushin
  • Academynew
  • About
Blog

JavaScript prototype pollution: discovery and exploitation guide (Ru)

by Denis Makrushin March 19, 2021

https://habr.com/ru/company/huawei/blog/547178/

If you regularly monitor bug bounty reports, you’ve seen “JavaScript prototype pollution” titles. Nikita Stupin decided to dig deeper into the category of vulnerabilities, impacting JavaScript applications, and prepared the practical guide of its discovery and exploitation. Soon we will also prepare an English version of the paper, but currently, you have to manage by yourself to translate it.

March 19, 2021
TwitterLinkedinVKTelegram
Blog

“Web Application Bug Hunting” Workshop on #SINCON2020

by Denis Makrushin January 2, 2021

For everyone who wants to start new year productively and begin the journey in #AppSec, I'll introduce “Web App Bug Hunting: Fundamentals and Learning Path” workshop on #SINCON. Thanks to @dariaski and @Emil0xA for the opportunity. Workshop details: https://t.co/sEpB73RvTh https://t.co/nIoKt2JmCv

— Denis Makrushin (@makrushind) January 2, 2021

For everyone who wants to start the new year productively and begin the journey in application security, I will introduce “Web Applications Bug Hunting: Fundamentals and Learning Path” workshop on SINCON.

Continue Reading
January 2, 2021
TwitterLinkedinVKTelegram
Blog

Bug Hunting Hub: Telegram channel for Security Researchers

by Denis Makrushin November 14, 2020

https://t.me/bhhub

Once bug hunting becomes a race of known misconfigurations and CVE detection, automation is required:

  1. monitor daily #BugBountyTips and CVEs;
  2. filter results with trendy potential;
  3. get alerts on time (13:37 UTC +0).

“Bug Hunting Hub” is a Telegram channel with my notes and bot notifications.

November 14, 2020
TwitterLinkedinVKTelegram
Load More Posts

Join Telegram Channel

  • Twitter
  • Linkedin
  • Vk
  • Telegram

@ 2009. Denis Makrushin


Back To Top
Denis Makrushin
  • Blog
  • Research
Denis Makrushin
  • Academynew
  • About