How I Hacked Samsung’s Tizen OS & LG Electronics Private Project Management Instances

Using Jiraffe security tool to find low-hanging fruits


Usual Boring SSRF, Right?

Samsung’s Tizen OS Bug Tracking Dashboard

Proof of concept for XSS

<svg xmlns="" onload="alert(document.domain)"/>
$ pip install jiraffe


Dear PIYUSH RAJ,As we said, LG CNS is a separate company from us.
Thus, we don't also have a contact point.
We'll contact the relevant department.
Thank you.
Best Regards,

