If you are hard at work scanning the internet for CVE-2021-41773 (apache 2.4.49 path traversal thing).. also try /icons instead of just /cgi-bin, enjoy the increased success rate. :-P
Cool Windows Internals trick I found over the weekend. If you name a folder "anything.{D2035EDF-75CB-4EF1-95A7-410D9EE17170}", Explorer will crash when you try to enter that folder.
Ever wondered which flags you should use for your C compiler to:
- detect the maximum number of bugs or potential security problems?
- enable security mitigations in binaries?
- enable runtime sanitizers?
We got you covered for GCC, Clang and MSVC!
airbus-seclab.github.io/c-compiler-sec…
Ever wanted to exploit Windows 10 with CVE-2021-31956? Obsessive about kernel memory layouts? research.nccgroup.com/2021/08/17/cve… is now up focusing on exploit reliability, stability and detection! #windows
Ever wanted to exploit Windows 10 with CVE-2021-31956? Obsessive about kernel memory layouts? research.nccgroup.com/2021/08/17/cve… is now up focusing on exploit reliability, stability and detection! #windows https://t.co/ymrqhlNwuM
Here is my PoC for exploiting the @Razer device driver installation LPE using a generic Android phone instead of a stock Razer device.
gist for the gadget setup: gist.github.com/tothi/3cdec3ac…
Original version using a Razer device was presented by @j0nh4t. Awesome finding, I like it.
curious how Android phones interact with embedded hardware (camera, sensors, etc) natively? libhardware tests show how it’s done. why does this matter? APTs persist (or re-exploit) as root and *not* as an individual app. it’s much harder to detect. android.googlesource.com/platform/hardw…
I wrote a 1day exploit for chrome CVE-2020-16040. It includes a typer hardening bypass. Works for chrome version <= 87.0.4280.88
github.com/r4j0x00/exploi…
Patch sudo. (Have backups prepped just in case you, you know, break everything)
wget sudo.ws/dist/sudo-1.9.…
tar xzvf sudo-1.9.5p2.tar.gz
cd sudo-1.9.5p2
./configure
make && sudo make install
bash -c "sudo --version"
Google's ReCAPTCHA will automatically fingerprint Burp Suite Proxy and raise the challenge difficulty to the maximum, making analysis of the app very irritating.
To fix this, go into your Burp Suite Project Configurations and activate TLS Passthrough for google.com
[UPDATE] AppSync Unified 90.0 — Massive rewrite of AppSync Unified that now fully supports all current iOS 14.x versions, while also improving the experience for all other iOS versions (even iOS 5/6!)
reddit.com/r/jailbreak/co…
do you want to know about?
integer overflow
integer underflow
Out of bound Read
Out of bound Write
Double Free
Use After Free
Memory leaks
here is the damn vulnerable c program i coded to explain AFL fuzzing in my videos:
github.com/hardik05/Damn_…
fuzz it using AFL and see :)
We've confirmed exploitability of Windows Pre-Auth RDP bug (CVE-2019-0708) patched yesterday by Microsoft. Exploit works remotely, without authentication, and provides SYSTEM privileges on Windows Srv 2008, Win 7, Win 2003, XP. Enabling NLA mitigates the bug. Patch now or GFY!
3 Followers 170 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/1zhiPhlHUe
148 Followers 367 FollowingI study Information Technology at Tampere University. In my spare time, I am a team member of Cutie Shell Project and Droidian GNU/Linux.
247 Followers 728 Following#Linux Hobbyist ⌘ | ☯#InfoSec Enthusiast & Professional ☠ | #HackingIsNotACrime | ♥ #Trance music ♬ | #INTJ | Opinion is of my own
201 Followers 828 FollowingUn passo a sinistra e cado.
Curioso con sete di conoscenza, quindi hacker.
Figlio del Sud e del Vesuvio.
Opinioni personali.
992 Followers 489 Following#RainbowHat | Ideology is killing the 🌍, only idealism might save it | 1+2+3+4 ... = -1/12 | #Covid-19 is the #newreligion and I still am gnostic.
48 Followers 886 FollowingHello, IT. Have you tried turning it off and on again?
I've been using Vim for about 2 years now, mostly because I can't figure out how to exit it.
11K Followers 7 FollowingCutting-edge security research by @SonarSource to educate the world about code security across all software.
We're also at @[email protected] 🦣
950 Followers 371 FollowingFounder https://t.co/xRe3RiqgRj / Security Consultant / Mobile & Web apps | My opinions are my own | @MobileHackingES organizer
2K Followers 521 FollowingOffensive Security Trainings and Services. OnDemand Mobile Security Courses - https://t.co/B8Q31o3o8q Follow us on Linkedin https://t.co/Td3Ww1uMgt
5K Followers 427 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
201 Followers 828 FollowingUn passo a sinistra e cado.
Curioso con sete di conoscenza, quindi hacker.
Figlio del Sud e del Vesuvio.
Opinioni personali.
37K Followers 496 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
992 Followers 489 Following#RainbowHat | Ideology is killing the 🌍, only idealism might save it | 1+2+3+4 ... = -1/12 | #Covid-19 is the #newreligion and I still am gnostic.
49K Followers 339 FollowingSecurity researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
26K Followers 2 FollowingOffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.