Just build a simple tool to interact with web shells and command injection vulnerabilities. Hope it's as useful for you as it was for me :)
https://t.co/6QZRssCZox
#PenTest#pentestweb#pentesttool#webshell
A few days ago I spent a couple of weeks doing the #becodoexploit challenge of owning 30 machines. Reviewing my notes, I'll organize some interesting things to share... The first is some tips for solving problems when importing VMs:
https://t.co/nycQ89BGnr
#pentest#boot2root
Dias atrás passei umas duas semanas fazendo o desafio do #becodoexploit de ownar 30 máquinas. Revendo minhas notas, vou organizar algumas coisas interessantes para compartilhar... A primeira delas é algumas dicas para resolver problemas ao importar as VMs:
https://t.co/nycQ89BGnr
Dias atrás passei umas duas semanas fazendo o desafio do #becodoexploit de ownar 30 máquinas. Revendo minhas notas, vou organizar algumas coisas interessantes para compartilhar... A primeira delas é algumas dicas para resolver problemas ao importar as VMs:
https://t.co/nycQ89BGnr
That's a great post as usual. Also I love the "Defenders think in lists. Attackers think in graphs" post shared. Even though it seems obvious many defenders fail to reasoning like this.
https://t.co/RCIkSIGg8Q
"OpenSSH Backdoors" -- a few thoughts on supply-chain attacks against OpenSSH, and what we can learn from both historical and modern events. https://t.co/tIs9ahYwJj
Uma boa oportunidade para aprender sobre namespaces, interagir com netlink via libnl, reference counting e causar um OOPS através do seu código em C. Então confere nosso post, se inscreve no blog e não perca o próximo post da série.
https://t.co/zLLg5zGuHw
The time has come, and with it your reading material for the week.
Phrack #71 is officially released ONLINE! Let us know what you think!
https://t.co/BRnK9lnGjI
Está inscrito em nosso treinamento de exploração de vulnerabilidades no kernel do Linux? Ainda não, mas está interessado em fazer? Ou tem interesse em aprender mais sobre sistemas operacionais e exploração de vulnerabilidades?
I love RSS/Atom feeds. When I arrive on a website and like its content, I immediately look for its feed.
But not everyone cares about this and does not provide links for it. Here is what I've used for years to find RSS/Atom feeds from sites.
#rss#blogging
Quer entender cada detalhe dos códigos executados no vídeo? Quer ter a sensação de escrever um exploit que obtém uid == 0 explorando uma falha em um módulo no kernel do Linux e utilizando ROP?
Acesse nosso site para maiores informações:
https://t.co/6ds9rTdhGd
Está buscando desenvolver novas habilidades e dar um salto em sua carreira?
A sua oportunidade está aqui. Oferecemos em parceria com a GoHacking o curso de Linux Kernel Exploitation com abordagem dinâmica e didática, para você mergulhar no kernel do linux.
Nice tip by @jwworth .
It is great to put your mental model to test. Either you fix your mental model or find the issue.
Make a Prediction
https://t.co/kQgUfJGEBn
#debugging#bolhasec#bolhadev
Last days I was doing phoenix from https://t.co/2v4Rdn55xM. After exploiting them I like to read writeups to learn new tips. To my surprise people assumed some are unexploitable due to \n on address they need to write to. Here is a tip to pass:
#binaryexploitation#pwn
Always remember to take into account how the binary was built. I was trying to exploit a simple format string bug using positional parameters but this was not working, until @KampetL remember me this. GLIBC doesn´t care about this rule, while MUSL does.
Being who you are, while becoming better
https://t.co/Kwaj8qw1RV
Becoming better is my daily hunt, nonetheless we need to be smart on take advantages on who we really are.
#selfImprovement#performance
I really like to use `git log -L :function:file`.
It checks for modification on function() code through commit history. It is a pretty simple yet practical way to do that.
https://t.co/UPkOOOHecl
#codeaudit#codereview#git
Estarei participando de uma live na próxima terça-feira, dia 18/06/2024, às 21:00 (horário de Brasília), falando sobre carreira como pesquisador em segurança da informação e sobre o treinamento em exploração de vulnerabilidades no kernel do Linux que irei ministrar em parceria com a GoHacking. Na live abriremos as inscrições e no final sortearemos uma vaga. Se tem interesse em exploração de vulnerabilidades ou quer aprender sobre o kernel do Linux, não perca essa ótima oportunidade.
Introdução à Exploração do Kernel do Linux
https://t.co/oilgOgo366