TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Airbnb Audit Results

50 pointsby remxabout 8 years ago

3 comments

zeliasabout 8 years ago
Anyone know of a good intro-to-web-app-security-best-practices resource? I don't have the resources to hire a security person and don't have the time to begin learning it all from scratch. I'm generally aware of what attack vectors look like (e.g. XSS, SQL injection, etc.) but am generally unfamiliar with solid low-cost, low-overhead ways of dealing with these problems. I don't have the time or the money (at-present) to set up a WAF -- but I know how important security can be. Where do I go to learn more?
评论 #13836704 未加载
评论 #13831071 未加载
评论 #13830876 未加载
tptacekabout 8 years ago
This appears to be a bad headline: it&#x27;s not the result of an audit on Airbnb, but instead a list of findings as part of a bug bounty.<p>Further: while this is good work, clever findings, and an excellent writeup, it&#x27;s a series of attacks on a single endpoint; sort of the XSS equivalent of a bug chain for a browser vulnerability. You could quibble over &quot;8 vulnerabilities&quot;, since they all add up to the same vulnerability in the same piece of code.<p>The best headline would be the article&#x27;s own, or, failing that:<p>Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor at Airbnb
评论 #13832370 未加载
robjanabout 8 years ago
Site is wobbling; Google cache version: <a href="https:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:l3pDsjc5p6gJ:https:&#x2F;&#x2F;buer.haus&#x2F;2017&#x2F;03&#x2F;08&#x2F;airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities&#x2F;+&amp;cd=1&amp;hl=en&amp;ct=clnk&amp;gl=us" rel="nofollow">https:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:l3pDsj...</a>
评论 #13830381 未加载