date | slug | tags | title | author | type |
---|---|---|---|---|---|
2014-08-19 17:04:34 GMT |
Avoid-Command-Injection-Node.js |
security, node.js, injection |
Avoiding Command Injection in Node.js |
Adam Baldwin |
text |
--[[--------------- | |
LuaBit v0.4 | |
------------------- | |
a bitwise operation lib for lua. | |
http://luaforge.net/projects/bit/ | |
How to use: | |
------------------- | |
bit.bnot(n) -- bitwise not (~n) |
{ | |
"a": 8.167, | |
"b": 1.492, | |
"c": 2.782, | |
"d": 4.253, | |
"e": 12.702, | |
"f": 2.228, | |
"g": 2.015, | |
"h": 6.094, | |
"i": 6.966, |
wget -q http://s3.amazonaws.com/alexa-static/top-1m.csv.zip;unzip top-1m.csv.zip; awk -F ',' '{print $2}' top-1m.csv|head -1000 > top-1000.txt; rm top-1m.csv* |
. | |
.. | |
........ | |
@ | |
* | |
*.* | |
*.*.* | |
🎠|
URLs people tried (so far): https://gist.github.com/evilpacket/6651547a3d3e39bef75eee35f321f25f | |
Flag 1: | |
1. @jstash | |
2. @cnelson | |
3. @JF0LKINS | |
Flag 2: | |
1. |
(Swedish) Girl with a dragon tattoo | |
Hackers | |
WarGames | |
Antitrust | |
Swordfish | |
TRON | |
Sneakers | |
Joe Dante's Explorers (1985) | |
The imitation game | |
The KGB, the computer, and me |
date | slug | tags | title | author | type |
---|---|---|---|---|---|
Wed Jan 14 17:30:08 PST 2015 |
the-dangers-of-square-bracket-notation |
security, node.js, javascript, hapi, RCE, square bracket notation, io.js |
The Dangers of Square Bracket Notation |
Jon Lamendola |
text |
We are going to be looking at some peculiar and potentially dangerous implications of Javascript's square bracket notation in this post: where you shouldn't use this style of object access and why, as well how to use it safely when needed.
date | slug | tags | title | author | type |
---|---|---|---|---|---|
2013-09-07 17:03:10 GMT |
bypass-connect-csrf-protection-by-abusing |
CSRF, connect, methodOverride, middleware |
Bypass Connect CSRF protection by abusing methodOverride Middleware |
Node Security Team |
text |
Since our platform isn't setup for advisories that are not specific to a particular module version, but rather a use / configuration of a certain module, we will announce this issue here and get it into the database at a later date.
date | slug | tags | title | author | type |
---|---|---|---|---|---|
Mon Nov 03 8:00:00 PDT 2014 |
regular-expression-dos-and-node.js |
security, node.js, redos |
Regular Expression DoS and Node.js |
Adam Baldwin |
text |
Imagine you are trying to buy a ticket to your favorite JavaScript conference, and instead of getting the ticket page, you instead get 500 Internal Server Error
. For some reason the site is down. You can't do the thing that you want to do most and the conference is losing out on your purchase, all because the application is unavailable.