Polymath. Getting to know the world a little bit better every day. Looking for a proper conversation. #Art & #Science & #FreeSoftware & #Encryption enthusiast
Yo hackers! I've built a small website that has some #XSS challenges.
🔗 https://t.co/EP3HnJBCvm
The main challenge for the week is `WW3`
All upcoming challenges will be hosted there, so stay tuned :)
Would love to know what you guys think. Have fun!
The types of bugs we continue to see from Palo Alto Networks in their products are disconcerting.
They are basic. They are identifiable through static analysis (format strings?!). And some products are built on risky foundations (Linux on MIPS lacks basic safety features).
??
Me volvieron a escribir ahora que lo hice publicop, pero ni a mi ni a todas las otras personas que lo reportaron les dieron bola. Por eso @CableFibertel dejen de mandarme DMs. Despues les paso mi informe... si me pinta. Saludos.
@oasace North Korea does similar things to media files on their operating system #RedStarOS. They seemed to be way ahead and started this in 2014 already. Just saying ... ;) https://t.co/FrweKEoBM9
@oasace@nixcraft I dug a little more, seems like facebook has been injecting the identifier recently.
I managed to hexdump some images I uploaded to Facebook
1. 2014 - https://t.co/mWwnNOyJJr (No Identifier)
2. 2017 - https://t.co/AJel2caSXL (Contains Identifier)
Whatsapp isn't injecting though
This 'Antivirus Oracle' technique potentially enables a whole bunch of different attacks far beyond exploiting blind SSRF. See the discussion at https://t.co/nuBBiGwLRx
Heads up @zoom_us:
The fix for the security vulnerability that impacts ~4 million of your users has regressed.
90-day public disclosure deadline was June 24th.
I'm going public tomorrow.
This is unacceptable.