Skip to content

Instantly share code, notes, and snippets.

@zionspike
zionspike / main.dart
Last active March 11, 2022 18:10
Flutter TLS Certificate Pinning (cannot bypass using SSLKillSwitch on iOS)
import 'dart:io';
import 'package:dio/adapter.dart';
import 'package:dio/dio.dart';
void main() async {
BaseOptions options = BaseOptions(
baseUrl: "https://httpbin.org",
connectTimeout: 3000,
receiveTimeout: 3000,
);

Session Fixation in BigTree CMS 4.2.23 and earlier (CVE-2018-18380)

Description

A Session Fixation issue was discovered in Bigtree 4.2.23 and earlier. The PHP session id has not been generated after loggin. File core/inc/bigtree/admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.

Additional Information