Excited to release my latest research today. Exploiting CORS can be a tricky in modern web apps, but there are still critical cases out there if you know what to look for. If you want to learn more about CORS exploitation, the research is available at https://t.co/qV5nr5T0xg
Blind file read to RCE in PHP - without access to files, we need to build reliable arbitrary read primitive from the ISO-2022-CN-EXT overflow (CVE-2024-2961) #CNEXT
the @CellebriteLabs French🇫🇷 team is recruiting! Don't miss the rare opportunity to join a team that specializes in breaking Android security boundaries (bootchain/trustzone/Secure Element/kernel and other goodies) for forensic purposes. ⤵️
1/5
Si vous gérez des serveurs #DNS (qu'ils soient résolveurs ou faisant autorité), lisez bien ce décret, vous avez plein de nouvelles obligations https://t.co/oKT0WrZJE3
Si vous utilisez des serveurs DNS (c'est a priori le cas 😀), réfléchissez à ceux que vous utilisez.
When you are fuzzing API Endpoints worth you add XMLHttpRequest headers, some frameworks filter requests that don't was called by Frontend Applications.
- "X-requested-with: XMLHttpRequest"
* Found in some PHP frameworks.
#BugBounty#BugBountyTips#Pentesting
🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!
I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz
Last night, I was targeted for a sophisticated phishing attack on my Apple ID.
This was a high effort concentrated attempt at me.
Other founders are being targeted by the same group/attack, so I’m sharing what happened for visibility.
🧵 Here’s how it went down:
Aux @restosducoeur, nous recherchons activement des modules SFP (Juniper, Cisco Fortigate), câblage fibre, DAC 10G et surtout des disques dur/SSD (idéalement SAS) pour notre infrastructure.
N'hésitez pas à me contacter. Merci par avance pour votre aide !🩷
Need more points on Root-Me?
To make up for it : 5 new Miscellaneous challenges are now available on the Root-Me and Root-Me Pro environments.
https://t.co/VTJfcgHHni
Many thanks to the authors: @Njord_____, @0xTRIKKSS, @Elweth_, #Mister7F and #S1m 👏 !
✅ NEW FREE-ACCESS CHALLENGE ✅This Network Challenge is now open access on Root-Me: 𝐀𝐑𝐏 𝐒𝐩𝐨𝐨𝐟𝐢𝐧𝐠 - 𝐄́𝐜𝐨𝐮𝐭𝐞 𝐚𝐜𝐭𝐢𝐯𝐞 👉 https://t.co/FQT5GhMTC6
Thanks to @voydstack for this creation 💪☠️ Enjoy !
Can't wait to see some new web server challenges? 4 new ones are now available! Thanks to the authors: @_Sanlokii#lolo42, #K4ndar3c 👏 ! https://t.co/yBGycCTMmk + 🥳 we've got a new contest just for you! 3 of you could win: 1 months' Premium subscription => be among the first 3 to flag the « Elixir-EEx » chall.🤞
Hello Twitter!
Petit post recrutement, notre équipe offensive recrute actuellement un ou deux profils afin de renforcer l'équipe technique sur Rennes ou Nantes
Idéalement, on recherche un profil disposant d'une double compétence [1/n]
A new Lab 🏰 is available on GOAD: NHA.
This time it is a challenge, 5 vms, you start with no account and try to get domain admin on the two domains.
https://t.co/ZDYBjb6AaL
Have fun !