"The plural of regex is regrets"
Need to generate payloads that match or avoid multiple regex?
Check out regrets! https://t.co/ZiKblK4ZVv
Feedback is very welcome 😁
"Never Trust Your Victim: Weaponizing Vulnerabilities in Security Scanners" - missed that this research included @zaproxy - good to see no vulnerabilities found!
https://t.co/zpyjUX5YPp
Full PDF linked on that page.
Reasearch by @avalz_, Gabriele Costa, Alessandro Armando
Lookarounds are a great feature in PCRE regex. But what if you are using Go or Rust?
Here are a few tricks to simulate Negative Lookaheads in non-PCRE engines.
#regex#TIPS
https://t.co/IOR3GEiQJl
Today we (@antonio_ruggia, @_pox_, @dreamersball80, @_DarioNisi) disclose some vulnerabilities that we exploited to mount a novel phishing attack on @Android by abusing inotify.
Our research will be presented at @IEEEEUROSP 23
https://t.co/QAYowmxNco
Some comments below (1/n)
It's been a few years now, and WAF-A-MoLE is gaining momentum!🚀
Today it reached a great milestone, with a round number of stars!😁
\cc @zangobot#waf#Bypass#MachineLearning
On nuvola's repository README (https://t.co/GRinhlXgWm) you can find all links for the #RomHackCamp#slides and #demos that you saw during the "You Shall Not PassRole!" talk
Today we're releasing nuvola 🌩️(https://t.co/lNfzIISPDO) during #RomHack camp. nuvola is a new born open-source tool to dump and perform automatic and manual security analysis on AWS environments, especially useful to find privilege escalation paths! #aws#redteam#security
We love the elixir community! That's why we decided to contribute back and release prima_autho_ex: an easy-to-use elixir library to authenticate machine-to-machine communications through Auth0! https://t.co/zd2Jbtjy7V
Don't miss "You shall not PassRole!", a talk by @_notdodo_ @ RomHack (Sep 25th)!
He will show how privilege escalation issues proliferate in AWS environments, and how to automate the discovery process.
For more details: https://t.co/E0sv9OKKkJ
Interested in security? You should attend https://t.co/SPNYvdPAzc (@cybersaiyanIT) which will take place on September 23-24-25th 2022! Don't miss @_notdodo_ talk about AWS privilege escalations attacks and defenses!