time-of-check-time-of-use

2 articles
sort: new top best
clear filter
0 7/10

A researcher discovered a Server-Side Request Forgery (SSRF) vulnerability using DNS rebinding to bypass IP-based access controls, escalating through AWS metadata enumeration and Monit admin interface exploitation to achieve instance shutdown and memory disclosure. The writeup details the methodology, tool creation, and real-world exploitation chain that combined multiple vulnerabilities.

CVE (buffer overread in Monit) AWS metadata service (169.254.169.254) Monit Admin interface Fireshell CTF 2019 Jan Masarik dnsFookup tool lock.cmpxchg8b.com/rebinder.html
geleta.eu · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details
0 7/10

Educational article explaining race condition vulnerabilities in web applications, particularly in financial systems, with real-world examples including the Starbucks gift card exploit where attackers could generate unlimited credit by sending concurrent transfer requests to bypass balance checks.

Egor Homakov Starbucks Vickie Li
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details