Was the first to the drop, but the @ANDnXOR badge fairy delivered hard this drop. Special @k0grad for a sporting match of Rock Paper Scissors. Now off with them and @_dum8_k1d to start solving
Bumped the versions on everything for https://t.co/F36yxw3x6k, including fixing log4shell. Usually I don't post about the "boring" work like this, but strong recommend that if you're running this on sketchy libraries, it not be vulnerable to something so popular.
Hey, have you been spending a lot of time testing for potentially blind DNS recently for some reason? Check out this project from @symbolcrash1, just set up some alert domains and start spraying payloads (with legal consent).
If you want a self-hosted solution for DNS canary testing that's easy to deploy, @handled_sigint just added Slack webhook notification support to the madns server (already had email): https://t.co/LcFJlPYOpc
#Log4Shell#log4j
Reading through https://t.co/EPWsCjByLc, one of the unfortunate parts of that is you can't get source-level coverage guided fuzzing. To which my next question was, "how does coverage guided fuzzing actually work?" (thread)
Aaaaaaand, I'm already distracted. Did you know that you can get https://t.co/Hi675OSKPY entirely in offline mode? Everything is documented in https://t.co/mCkTqAvWJj, and all of the code explanations live as comments on the various files.