My Publications

My Publications

Follow
homebadges

Hacking 6.5+ million websites => CVE-2022-29455 (Elementor)

Jun 12, 20227 min read

Please upgrade your Elementor websites · Announcing CVE-2022-29455 Actions you should take if you have Elementor installed: Scan yourself with this...

Hacking 6.5+ million websites => CVE-2022-29455 (Elementor)

SSRF in Open Distro for Elasticsearch

May 11, 20217 min read

CVE-2021-31828 · After an interesting adventure, it's now possible to announce a new CVE-2021-31828 which effects Open Distro for ElasticSearch (ODFE)...

SSRF in Open Distro for Elasticsearch

Developers, Please encode your URLs

Oct 26, 20205 min read

If you like it, put a # on it! · Uniform Resource Locators (URLs) are a funny thing. They seem so simple, but yet they have so many small complex rules...

Developers, Please encode your URLs

NGINX may be protecting your applications from traversal attacks without you even knowing

Sep 24, 20207 min read

By Danny Robinson and Rotem Bar · As a security team within a rapidly growing company, we encounter lots of different types of vulnerabilities. We have...

NGINX may be protecting your applications from traversal attacks without you even knowing