RSSAmplifier

Blog

Sunshine After Rain

jdomeracki.github.ioRSS feed ↗3 posts

Latest posts

Hunting for Bucket Traversals in Google's Client Libraries

Table of Contents Preface Bucket Traversal 101 Case study TL;DR Overview Technical analysis PoC Attack scenario Diagram of a sample vulnerable application Summary Preface This writeup picks up pretty much where the last one ended, that is when I found an exploitable instance of a bucket traversal vulnerability and stumbled on an N-day in Go Cloud Storage client library . Intrigued by this finding,…

Sketchy Cheat Sheet - Story of a Cloud Architecture Diagramming Tool gone wrong

Table of Contents Preface Unplanned Bug Bounty hunt Backtracking from impact to attack scenario Hunting for the XSS Proving exploitability Attack scenario diagram #1 Digging into the share links feature Firebase (in)secure storage Firebase security rules Demo app repurposed Unauthorized access to 30k share links Surprising bypass PoC Attack scenario diagram #2 Poisoning predefined architectures…

GCP Professional Cloud Security Engineer

Preface Let me begin by stating that I want to keep it real by not inflating the meaning of earning this or any other certification. Having said that I do believe that the preparation for this exam can amplify the learning process and spare you the trial and error route. Passing this exam won’t automatically make you a great Cloud Security Engineer but it will help facilitate a common language and…