Menu

#PenTest

6 posts

Feed·
4 of 6 posts
Pentesting a private tracker: Nuxt.js, Cloudflare and 3 vulnerabilities found
🖼️
0

Pentesting a private tracker: Nuxt.js, Cloudflare and 3 vulnerabilities found

DEV Community·Odilon HUGONNOT·about 1 month ago
#sx1ShzTT

Hands-on report of an authorized web pentest on a private BitTorrent tracker: Nuxt.js SSR + Node.js behind Cloudflare WAF. 3 findings (CORS, unbounded chat history, NUXT_DATA), Playwright trick for WebSockets, and what Cloudflare doesn't protect against.

15s
Read More