Skip to content

David Sopas – Security Researcher

I hack and I love it!

  • Home
  • About
  • Advisories
  • Contacts

Category: Advisories

  • Home
  • Advisories
  • Page 2

Workable Reflected File Download

  • Advisories
Posted on December 1, 2015December 1, 2015

For those who don’t know Workable.com… Workable is affordable, usable hiring software. It replaces email and spreadsheets with an applicant tracking system that your team […]

Read More

DepositFiles ZeroClipboard.swf XSS

  • Advisories
Posted on November 23, 2015

DepositFiles is a file storage website and one of the most popular ones. They’re online since 2005 and recently they start using dfiles.eu domain instead […]

Read More

Bytes that Rock voting manipulation

  • Advisories
Posted on November 20, 2015

Rocky Bytes is a company well known for its informative reviews and news on all the latest games and programs. Each year they promote Bytes […]

Read More

Edmodo XSS and HTML Injection

  • Advisories
Posted on November 6, 2015September 30, 2017

For those who don’t know Edmodo… The safest and easiest way for educators to connect and collaborate with students, parents, and each other. They count […]

Read More

SendGrid Reflected File Download

  • Advisories
  • Swag
Posted on October 28, 2015

For those who don’t know who SendGrid is… SendGrid provides unmatched deliverability, scalability, and reliability. We deliver email on behalf of happy customers such as: […]

Read More

Events Made Easy WordPress plugin CSRF + Persistent XSS

  • Advisories
Posted on October 15, 2015November 23, 2018

Plugin link: https://wordpress.org/plugins/events-made-easy/ Active Installs: 10,000+ Version tested: 1.5.49 CVE Reference: Waiting Events Made Easy is a full-featured event management solution for WordPress. Events Made […]

Read More

Komento Joomla! component Persistent XSS

  • Advisories
Posted on September 30, 2015

CVE Reference: CVE-2015-7324 Komento is a Joomla! comment extension for articles and blogs in K2, EasyBlog, ZOO, Flexicontent, VirtueMart and redShop. @http://stackideas.com/komento I found out […]

Read More

Shopify open to a RFD attack

  • Advisories
Posted on September 29, 2015September 29, 2015

Before Shopify having a bounty program on HackerOne I already sent [on 19 march] a security report about a Reflected Filename Download I found on […]

Read More

Acunetix got RFDed!

  • Advisories
Posted on September 23, 2015September 23, 2015

After publishing a report on a security software – OWASP ZAP – I found another vulnerability on a security company – Acunetix. Reminds the proverbial […]

Read More

OWASP ZAP XXE vulnerability

  • Advisories
Posted on September 22, 2015

I just noticed that this is my first full disclosure of a XXE vulnerability. I already found others but they were inside private bounty programs. […]

Read More

Posts navigation

Prev
Next

Recent Posts

  • I printed a 3D box for my bettercap arsenal and I liked it
  • Our DEF CON 28 day was a blast
  • DEF CON 28 here I go
  • A small gesture on this pandemic times
  • Checkmarx Security Research Team latest work

Recent Comments

  • David Sopas on BLE Driving 101
  • JIm K on BLE Driving 101
  • David Sopas on XSS on a input hidden field
  • shi on XSS on a input hidden field
  • David Sopas on Free online tools to help your #bugbounty

Archives

  • August 2020
  • July 2020
  • June 2020
  • March 2020
  • December 2019
  • August 2019
  • March 2019
  • February 2019
  • December 2018
  • November 2018
  • October 2018
  • August 2018
  • April 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • June 2017
  • April 2017
  • January 2017
  • November 2016
  • October 2016
  • August 2016
  • March 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015

Categories

  • Advisories
  • Bug Bounty
  • Challenge
  • Donations
  • Hardware
  • Inspiration
  • Interesting Readings
  • IoT
  • Life Style
  • Meetings
  • My Events
  • News
  • Papers
  • Swag
  • Tips and Tricks
  • Tools
  • Travel
  • Warning
Copyright © 2022 Biographyn by Theme Palace | Privacy Policy