#brokenaccesscontrol — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #brokenaccesscontrol, aggregated by home.social.
-
🕸️ Hoy Miércoles 15 de Julio a las 8:00 pm (UTC -05:00) iniciamos el Curso de Hacking Aplicaciones Web 2026 🕷️ 🚀 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🎯 De 8:00 pm a 11:00 pm (UTC -05:00) 👁🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #AppSec #OWASP #SQLInjection #XSS #SSRF #RCE #BrokenAccessControl -
🕸️ Hoy Miércoles 15 de Julio a las 8:00 pm (UTC -05:00) iniciamos el Curso de Hacking Aplicaciones Web 2026 🕷️ 🚀 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🎯 De 8:00 pm a 11:00 pm (UTC -05:00) 👁🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #AppSec #OWASP #SQLInjection #XSS #SSRF #RCE #BrokenAccessControl -
🕸️ Hoy Miércoles 15 de Julio a las 8:00 pm (UTC -05:00) iniciamos el Curso de Hacking Aplicaciones Web 2026 🕷️ 🚀 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🎯 De 8:00 pm a 11:00 pm (UTC -05:00) 👁🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #AppSec #OWASP #SQLInjection #XSS #SSRF #RCE #BrokenAccessControl -
🕸️ Hoy Miércoles 15 de Julio a las 8:00 pm (UTC -05:00) iniciamos el Curso de Hacking Aplicaciones Web 2026 🕷️ 🚀 Miércoles 15, Viernes 17, Miércoles 22 y Viernes 24 de Julio 🎯 De 8:00 pm a 11:00 pm (UTC -05:00) 👁🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Hacking_Aplicaciones_Web.pdf #AppSec #OWASP #SQLInjection #XSS #SSRF #RCE #BrokenAccessControl -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
-
Acer Rushes to Patch Zero-Days in Wave 7 Routers
Acer is urgently patching a critical vulnerability in its Wave 7 routers that allowed hackers to easily access sensitive login credentials, putting your entire network at risk. This flaw let attackers remotely tap into plaintext passwords stored in log archives, no authentication required.
#ZeroDay #Cve202649200 #Acer #Wave7Routers #BrokenAccessControl
-
Neuer Artikel im Blog:
TYPO3 Security Releases: Vier Sicherheitslücken in 14.0.2, 13.4.23 und 12.4.41 geschlossen
-
Neuer Artikel im Blog:
TYPO3 Security Releases: Vier Sicherheitslücken in 14.0.2, 13.4.23 und 12.4.41 geschlossen
-
Neuer Artikel im Blog:
TYPO3 Security Releases: Vier Sicherheitslücken in 14.0.2, 13.4.23 und 12.4.41 geschlossen
-
Neuer Artikel im Blog:
TYPO3 Security Releases: Vier Sicherheitslücken in 14.0.2, 13.4.23 und 12.4.41 geschlossen
-
Neuer Artikel im Blog:
TYPO3 Security Releases: Vier Sicherheitslücken in 14.0.2, 13.4.23 und 12.4.41 geschlossen
-
Lỗ hổng kiểm soát truy cập bị phá vỡ (BAC) là một trong những rủi ro hàng đầu trong bảo mật. Kỹ thuật leo thang đặc quyền, đánh cắp dữ liệu, và tấn công DDoS là những ví dụ điển hình.
Để phòng ngừa, cần kiểm thử bảo mật liên tục, cấu hình CORS, RBAC, và MAC.
#BAC #BrokenAccessControl #Security #BảoMật #OWASP #Cybersecurity #AnToanThongTin -
The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
🚨Security Risk: High
🧵👇More details
https://herolab.usd.de/en/security-advisories/usd-2023-0008/ -
The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
🚨Security Risk: High
🧵👇More details
https://herolab.usd.de/en/security-advisories/usd-2023-0008/ -
The #usdHeroLab analysts examined the open source application #WeKan while conducting their security analyses and found a #BrokenAccessControl vulnerability.
🚨Security Risk: High
🧵👇More details
https://herolab.usd.de/en/security-advisories/usd-2023-0008/