Posts

Interview with West London charity DanceWest

Image
 Interview with West London charity DanceWest https://photojournalismhub.org/2021/01/14/wondering-about-west-london-issue4/ Twitter: @journothinker Instagram @journothinker

Interview with Carlos, Owner of Plumbing and Gas Boiler Services

Image
https://photojournalismhub.org/wondering-about-west-london/  

Interview with Sarah Kleio - Dance Studio Business Owner, Richmond

Image
https://photojournalismhub.org/wondering-about-west-london-issue2/  

Interview with Paola - Professional Dance Teacher, Choreographer, Actor and Events Organiser

Image
https://photojournalismhub.org/wondering-about-west-london/  

Security researcher earns $15000 biggest bug bounty for Russian internet company giant Mail.Ru

Image
Security researcher Ramazan (r0hack) discovered a Bind (time-based) SQL injection in https://city-mobil.ru website due to the unsafe usage of the GET parameter for which he was awarded $15000 So far, this is the largest awarded vulnerability disclosed in Mail.ru and the second biggest bounty awarded on the bug bounty platform Hackerone after just one bug bounty award of $20000 Time-based SQL Injection is an SQL Injection technique that relies on sending an SQL query to the database which forces the database to wait for a specified amount of time (in seconds) before responding. The response time will indicate to the attacker whether the result of the query is TRUE or FALSE which will allow the attacker to figure out if the payload used true or false Full details of the vulnerability have not been yet polished by the researcher and more information can be found at https://hackerone.com/reports/868436 Mail.Ru is a major Russian internet company whose sites reach approxima...

Slack vulnerability in the "Create snippet" feature can trick users to execute malicious filetypes

Image
Slack’s snippet feature allows users to quickly and easily share pieces of code, configuration files, or log files within their workspace. Researcher Kevin McSheehan discovered the bug in the snippet feature and reported it in the Slack’s bug bounty program. "They need to click on the file, so let's trick Slack into making it look benign. CSV should work" he said. Slack will also show the user that a .CSV file is being downloaded when it is actually a .BAT executable. The issue, present in both the mobile and desktop versions of the app, allowed a malicious actor to disguise dangerous files as benign, due to a flaw in the create snippet feature. The researcher discovered that by including a long file name and certain ASCII characters in the snipped content, an attacker could trick Slack into showing that a .CSV file was being downloaded when it was actually a .BAT executable. Full details of the vulnerability can be found here - https://hack...

Cape Town locals help the homeless during the lockdown despite opposition

Image
Peter Wagenaar, a real estate agent, and his wife have been cooking for the homeless people in Sea Point during the lockdown which has stirred up tension in the affluent suburb of Mouille Point. Peter had been using his car to distribute food to homeless people in Sea Point, which caused anger among some residents. In the early hours of 6th May, his car was set ablaze and nothing but charred metal was left after the fire. Picture by  @MarvinCharles17 Wagenaar has had confrontations with police officers since he started feeding the homeless. A video went viral in which a police officer threatened to arrest him for feeding the homeless despite Wagenaar having a permit. Wagenaar wakes up every day at 4am to start cooking. Breakfast is given to the homeless people from 7am to 9am on Beach Road and Fritz Sonnenberg Road. Wagenaar feeds breakfast and dinner to around 80 to 100 homeless people get which he buys from his own pocket. Alt...