Skip to content

Latest commit

 

History

History
93 lines (47 loc) · 7.46 KB

2014.md

File metadata and controls

93 lines (47 loc) · 7.46 KB

Web Hacking Techniques 2014

Heartbleed

TweetDeck XSS

OpenSSL CVE-2014-0224

Rosetta Flash

Unauthenticated Backup and Password Disclosure In HandsomeWeb SOS Webpages cve-2014-3445

CTA: The weaknesses in client side xss filtering targeting Chrome's XSS Auditor

Advanced Exploitation of Mozilla Firefox Use-After-Free Vulnerability (Pwn2Own 2014) CVE-2014-1512

Facebook hosted DDOS with notes app

The Web Never Forgets: Persistent Tracking Mechanisms in the Wild

Remote File Upload Vulnerability in WordPress MailPoet Plugin (wysija-newsletters)

The PayPal 2FA Bypass

AIR Flash RCE from PWN2OWN

PXSS on long length videos to DOS

MSIE Flash 0day targeting french aerospace

Linskys E420 Authentication Bypass Disclosure

Paypal Manager Account Hijack

Covert Redirect Vulnerability Related to OAuth 2.0 and OpenID

How I hacked Instagram to see your private photos

How I hacked GitHub again

ShellShock

Poodle

Residential Gateway "Misfortune Cookie"

Recursive DNS Resolver (DOS)

Belkin Buffer Overflow via Web

Google User De-Anonymization

Soaksoak WordPress Malware

Hacking PayPal Accounts with 1 Click

Same Origin Bypass in Adobe Reader CVE-2014-8453

RevSlider

HikaShop Object Injection

Covert Timing Channels based on HTTP Cache Headers

NODE.JS CONNECT CSRF BYPASS ABUSING METHODOVERRIDE MIDDLEWARE

Bypassing NoCAPTHCA

Delta Boarding Pass Spoofing

Cryptophp Backdoor

Microsoft SChannel Vulnerability

Google Two-Factor Authentication Bypass

Drupal 7 Core SQLi

Apache Struts ClassLoader Manipulation Remote Code Execution and Blog Post

Reflected File Download

Misfortune Cookie -- TR-069 ACS Vulnerabilities in residential gateway routers

Hostile Subdomain Takeover using Heroku/Github/Desk + moreExample 1 and Example 2

File Name Enumeration in Rails

FlashFlood

Canadian Beacon

setTimeout Clickjacking