test2shells - A valid URL with a Command in its Shadow
A connectivity test panel in a bug bounty program took an SSH host, shrugged off thirty minutes of SSRF testing, and never expected a semicolon.
Electronics Engineer turned ethical hacker and bug bounty hunter. Fascinated by finding security vulnerabilities.
A connectivity test panel in a bug bounty program took an SSH host, shrugged off thirty minutes of SSRF testing, and never expected a semicolon.
This article explains how I found an XML External Entity (XXE) injection through a specially crafted PDF file.