Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
As an engineer, I ❤️ clever engineering.
Ruby on Rails relies on signed sessions (AES GCM). They are secure, but there is a catch: you cannot invalidate them early. You have to wait for expiry. Workarounds exist, like caching sessions you want to kill, but nothing universal.
@vitorpy@dhh I put together a bit of an “Omadora” build based on Omarchy recently. It’s really just for my own personal use but you might find it a good base to build from with your own tooling.
https://t.co/joEkMo8Eb6
The Fetch API supports Blob objects as request bodies, not just strings!
Blobs can omit a type, enabling cross-site POST requests without a Content-Type header.
Even with non-empty bodies, the Blob's data becomes the request body!
(credit: @lukejahnke)
https://t.co/xI316Irhsu - Where reporting the vulnerabilities is left as an exercise for the reader
Want to provide feedback on upcoming posts before they’re published? Drop me a DM!