[WSS] Security Labs
~/blog ~/consulting ~/huntdb ~/github
Blog Consulting HuntDB GitHub
How I made more than $30K with Jolokia CVEs

How I made more than $30K with Jolokia CVEs

Dear Readers – it’s been a while. First and foremost: This blog post is mostly inspired by the Gotham Security : jolokia-vulnerabilities-rce-xss write-up. None of what you are about to read is really new; I just found it difficult to find a complete write-up which describes the most common misconfigurations, so

June 16, 2020 β€’ 14 min read min read
Visual Recon - A beginners guide
bug bounty

Visual Recon - A beginners guide

May 05, 2018 β€’ 5 min read min read
The Stony Path of Android πŸ€– Bug Bounty - Bypassing Certificate Pinning

The Stony Path of Android πŸ€– Bug Bounty - Bypassing Certificate Pinning

October 21, 2017 β€’ 9 min read min read
Messaging Queues in the IoT under pressure - Stress Testing the Mosquitto MQTT Broker

Messaging Queues in the IoT under pressure - Stress Testing the Mosquitto MQTT Broker

October 05, 2017 β€’ min read
Decoding a $😱,000.00 htpasswd bounty
BugBounty

Decoding a $😱,000.00 htpasswd bounty

September 08, 2016 β€’ 3 min read min read
Sleeping stored Google XSS Awakens a $5000 Bounty
5k

Sleeping stored Google XSS Awakens a $5000 Bounty

May 17, 2016 β€’ 3 min read min read
Page 1 of 5 Older Posts →

Stay Updated

Get the latest security research and insights directly in your inbox.

Get in Touch

Have a security concern? Let's discuss how we can help.

patrik@wss.sh LinkedIn @patrikfehrenbach
WSS Security Labs

Professional security research and technical insights about penetration testing and cloud security.

GitHub Twitter

Products

  • HuntDB
  • WSS Consulting

Security Services

  • Penetration Testing
  • Security Consulting
  • Code Review