Offensive #security goes #art at @ArsElectronica Festival 2020 😎 We will turn a whole building into a musical instrument by hacking into the access control system at @jkulinz campus
https://t.co/wlK2xk4KwI
Here is the write-up of the full exploit - explaining the XSS vulnerability, the CSP bypass with a JPEG/JS polyglot, stealing browser cookies, and finally exploiting an XXE in the admin panel to read arbitrary files from the victim server. (5/5) https://t.co/2mP1PL0hiU
Wie man alle OWASP Top 10 abkassiert! Heute haben wir auf der IKT-Sikon erste Details zu CVE-2023-3654/3655/3656 präsentiert. Kompletter Report https://t.co/YZqjsAg4vw tl;dr wir wurden unfreiwillig zu ehrenamtlichen Admins auf hundeten Registrierkassen in der Gastronomie.
While I'm strongly in favor of effective measures against child abuse and exploitation, client-side scanning and weakening of of end-to-end encryption in popular messengers can't be the solution. We explain our arguments in an open letter today: https://t.co/mJ1j3iddb1
My video "Cloning Credit Cards" (#research published in @usenix WOOT'13) is reason for @YouTube to suspend my channel due to "Content intending to sell certain illegal or regulated goods and services" ... WTF? Is this @Google understanding of support for the research community?
@TeamYouTube How long will it take for my channel & account to be back online? For now the channel is still inaccessible and the sign-in button redirects to an information that my account access to YouTube is still suspended.
(8/ ) Following @TeamYouTube suggestion to use the appeal form (again) resulted in the decision "We reviewed your channel carefully, and have confirmed that it violates our Community Guidelines." (AGAIN! and within 9 minutes after filing the appeal)
@rene_mobile @insjku@jkulinz@fhhgb@fhooe any ideas what we could do about this? Certainly we should avoid to use YouTube for preseting our research in future ...