Exploiting slash/backslash mismatch to trigger cache poisoning.
This one-liner bug by @bassemsadaqah led to a CDN-wide DoS on Shopify and is a great example of how simple tricks can lead to impactful issues in mature organizations.
Full report here 👇
hackerone.com/reports/1695604
324 Followers 4K FollowingCrypto Enthusiast & Blockchain Researcher | Building the Future, One Block at a Time
Relentlessly Learning | Deep into Decentralization | Grinding 🗿❤️🥇
2K Followers 464 Following@immunefi Associates All Stars | Ranked on Immunefi’s all-time leaderboard | I enjoy finding bugs in smart contracts and blockchains 👾
56K Followers 628 FollowingImmunefi — One Platform. Unified Security Operations. Complete Onchain Protection. Over $180B of user funds protected across 650+ protocols.
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
132K Followers 57 FollowingProviding intel from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threats, Crypto & more. Follow X Bot: @DarkWebIntelBot. https://t.co/Fi7VW9lg94
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
241K Followers 202 FollowingBreaking cybersecurity and technology news, guides, and tutorials that help you get the most from your computer. DMs are open, so send us those tips!
326K Followers 3K FollowingThe only official HackerOne Twitter account.
A global leader in offensive security solutions. #HackForGood #togetherwehitharder
192K Followers 0 FollowingWe make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
38K Followers 132 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.