Skip to main content

Questions tagged [websites]

Applications or informational pages, distributed via HTTP or HTTPS, using a web server. Pages are typically interconnected by hyperlinks and may contain forms or even entire applications.

0 votes
0 answers
24 views

I'm working on a web application and came across a scenario where a remember_token cookie is used by itself to authenticate a user on subsequent visits, completely bypassing the need for a password or ...
Abdelkafi Habbeddine's user avatar
1 vote
1 answer
190 views

What are the risks of publishing a company's IBAN account number on a public website, as long as the security measures for website maintenance have been taken by the IT supplier that hosts this ...
Fatih Danis's user avatar
0 votes
1 answer
444 views

The Guardian says: Many tech experts also argue that apps are generally more secure than websites and allow banks and others to carry out sophisticated ID verification using face, voice and ...
User65535's user avatar
  • 447
3 votes
1 answer
407 views

I am testing a deep packet inspection based application to block certain undesirable websites in a corporate network, eg gambling - williamhill.es . We do this by matching ServerName (HTTPS) or Host (...
Panda142308's user avatar
0 votes
1 answer
12k views

I was quite an imbecile for opening this website. It seemed to be some kind of prank, and it was "you are an idiot" song playing. However after looking it up on Reddit, some users said it ...
Arjun's user avatar
  • 109
3 votes
3 answers
2k views

I know that sites can share some information between each other by sharing cookies amongst themselves. They have to be in some kind of agreement with each other I assume? Or can any random site read ...
HullBreaker's user avatar
0 votes
1 answer
69 views

As most people know, it is very easy to modify a webpage’s local cached content (HTML, JS) through Inspect Element or various other means. This could be probably be stopped through something like ...
security_paranoid's user avatar
2 votes
0 answers
56 views

Url requested: https://site.azurewebsites.net/fky_7143_tczf_ohced.aspx?group=CON&branch=A&[email protected]&page=stocks/Bep_EQ32_agepbb_abfgjc_ctkdcem.aspx?veBjt=09983&...
JeffBusterCase's user avatar
2 votes
2 answers
203 views

I was watching Sun Knudsen's videos and in one of them, he talks about GPG. Specifically, he said that he has 3 locations where he provides fingerprints of his signatures. YouTube, Github and his ...
Xoteric's user avatar
  • 95
4 votes
1 answer
318 views

I was happily learning ReactJS when I accidentally clicked the URL for www.someurl.com. After all the redirects, the final page prevented me from leaving using CTRL+W, Windows key, Escape, Opening the ...
Jake's user avatar
  • 143
0 votes
1 answer
855 views

Polyfill.io is malicious: https://dev.to/snyk/polyfill-supply-chain-attack-embeds-malware-in-javascript-cdn-assets-55d6 https://www.sonatype.com/blog/polyfill.io-supply-chain-attack-hits-100000-...
telion's user avatar
  • 111
1 vote
1 answer
53 views

Consider a situation such as: private LAN <-> firewall A <-> DMZ <-> firewall B <-> internet (https://forum.huawei.com/enterprise/en/dmz-and-reverse-proxy/thread/...
PanCho's user avatar
  • 11
-1 votes
1 answer
148 views

There are plenty of questions on this site about how to report a vulnerability (such as SQLi or XSS,) but none of them really answer my question of who to. I understand for a big corporation (although ...
security_paranoid's user avatar
0 votes
1 answer
174 views

I have access to companies internal files through SSRF and Path traversal both but want to leverage it further to website takeover. Thus I can increase the impact and get more bounty then what they ...
oo7hacker's user avatar
2 votes
1 answer
873 views

I use a password manager and have a browser plugin installed for it to simplify entering passwords into websites. I recently encountered a website (enterprise SaaS solution I use at work), which ...
Aleks G's user avatar
  • 281

15 30 50 per page
1
2 3 4 5
19