About a vulnerability in…
A year ago, on March 21, 2019, a very good bug report from maxarr came to the Mail.Ru bug bounty program on HackerOne. By injecting a null byte (ASCII 0) into the POST parameter of one of the email web API requests that returned an HTTP redirect, pieces of uninitialized memory appeared in the redirect data, often revealing fragments from GET parameters and headers of other requests to the same […]
