By travisintigriti
December 14, 2022
Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by InsiderPhD. Every week, she keeps us up to date with a comprehensive list of write-ups, tools, tutorials and resources.
This issue covers the weeks from December 5th until December 11th.
Intigriti News
From my notebook
While ChatGPT released at the tail end of last week, we really saw the hacking community embrace it this week and start to experiment what can be done with the new chatbot. From its ability to generate code, to bypassing the security filters, so here are my top 5 of ChatGPT resources. If you want to play with it, if you haven’t yet it’s free you need an account and phone number, http://chat.openai.com.
Can AI create a flyhack in Minecraft? – LiveOverflow did a stream where he explored using ChatGPT to write a flyhack mod for Minecraft, this is a cut down video with the highlights, he experiments with creating a flyhack and bypassing the server’s anti-cheat protection. He also argues with it which is actually very funny.
Exploring Prompt Injection Attacks – This post on NCC’s blog looks at the ability to bypass content filters using a ‘malicious’ prompt, these prompts are often something like “ignore the above and…”, and work on a variety of LLMs (large language models)
Temporary policy: ChatGPT is banned – StackOverflow has decided to ban the use of ChatGPT for answering code questions, this is primarily due to the bot’s habit of being confidently incorrect as well as to reduce low effort contributions on the website.
ChatGPT bid for bogus bug bounty is thwarted – Sneaky bug hunters are trying to use ChatGPT to find security flaws, it did not go well! But as a positive at least the person triaging noticed they were arguing with a bot fairly quickly.
Attacking Artificial Intelligence: AI’s Security Vulnerability and What Policymakers Can Do About It – This blog post from 2019 covers a short introduction to AI security bugs, if you’re interested in learning more about AI security it’s a fantastic place to start.
Other Amazing Things
HackTheBox UniCTF 2022 Talk – Variable is what you make of It
Interview with Guy Podjarny | Snyk, problems in cybersecurity,
Ethical Hacking in 15 Hours – 2023 Edition – Learn to Hack! (Part 1)
EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security
The Problem With Kernel-Mode Anti-Cheat Software [ML B-Side]
173 – Remotely Controlling Hyundai and a League of Legends XSS
301: AI chatbot or the start of Skynet? Eufy privacy, and hot desks
Upgrading Your XSS Bugs from Medium to Critical: Techniques and Examples
GraphQL Exploitation Techniques | Fintech Bug Bounty — Part 2
[BAC/IDOR] How my father credit card help me to find this access control issue
Coming across C++ BOF (Buffer Overflow) Vulnerabilities Within Libraries (part 2) EXTENSION
[WRITE-UP] Irremovable comments on the FB Lite app (Bounty: 500 USD) | by Shubham Bhamare
Facebook page admin disclosure by “Create doc” button (Bounty: 5000 USD)
[WRITE-UP] Facebook page admin disclosure by “Message Seller” button (Bounty: 1500 USD)
SQL Injection Extracts Online Users status , completed registrations, net overall posts l Database
Account takeover without user interaction via the mail server
CORS Misconfig on Out of scope domain Bug Bounty Writeup (300 USD Reward )
Privilege Escalation to remove the owner from the organization
Vertical Privilege Escalation: The user can takeover an admin account via response manipulation
Scoring $$$ for a very simple bug : You don’t always need proxy tools
Automate Cross-Site Scripting (XSS) exploitation with unusal events and Burp Intruder
Block 1M+ users from accessing their accounts by taking over third-party service
How “I hacked the Dutch government and got the lousy t-shirt”
Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass
The most underrated injection of all time — CYPHER INJECTION.
10 Practical Recon & vulnerability Scanners for bug hunters (part one)
Klyda – Highly Configurable Script For Dictionary/Spray Attacks Against Online Web Applications
Frida-Mobile-Scripts – Collection of useful FRIDA Mobile Scripts