Check out my article on Bash: bypassing command restrictions with obfuscated commands in the latest issue of PagedOut, and all the other cool articles while you are at it.
I'm very excited to finally share the first part of the research I did into Ghostscript. This post details the exploitation of CVE-2024-29510, a classic format string bug, which we abuse to bypass the SAFER sandbox and gain RCE.
https://t.co/gym3XltBpe
The most common mobile app attack vectors include: Rooted or jailbroken devices; Network attacks; & Malicious apps. This & more takeaways from our recent webinar w/ @Riscure's @AnisBoss_ and Zimperium's Tim Hartog & @bdogd: https://t.co/QUSAI3JSrh #WeSecureMobile#MobileSecurity
Glad to share with you my recently discovered CVE in zone minder product (CVE-2023-26039).
The vulnerability has been discovered during pb ctf 2023, thanks to @Unblvr1 for the great challenge.
Link: https://t.co/dN5aYjPnKN
Last year, @krvalk and I uncovered a series of vulnerabilities in Feathers.js, Sequelize and SocketIO that lead to critical issues for our client. Now that everything is fixed, here's our write-up of this journey into Javascript madness.
https://t.co/1cLCvAIghj
The slides for the @offensive_con talk “Bug Hunting S21's 10ADAB1E FW” of @ffmenarini and myself can be found here: https://t.co/ZvuU0SFZts Enjoy! We are still around at the conference so stop by and say hi.
#3kCTF-21 exploits to echo and klibrary, two kernel challenges that I created for this CTF:
https://t.co/qaxtvXrtFZ
and here exploits for the user-land challenges iterrun - stdout and masterc :
https://t.co/yEfYnOoX02
#3kCTF-2021 is over, Thank you for playing !
Final scoreboard:
1- Never Stop Exploiting
2- Black Bauhinia - @BlackB6a
3- zer0pts - @zer0pts
4- greunion - @greunion_ctf
5- zh3r0