A lot of folks asked @h2hconference to release the image used in the banner of the past edition of the magazine, so we did (high res in the link, low res in the tweet)! https://t.co/6jiiU0d2yu #H2HC2022
Landed a @metasploit module that exploit a Java deserialization vulnerability in JBOSS EAP/AS Remoting Unified Invoker interface for versions 6.1.0 and prior.
Credits: @joaomatosf
https://t.co/JTPOCJdJTz
#cybersecurity
@ILDannyMoore hey @ILDannyMoore , any idea when your book will be available in kindle format on https://t.co/nmKSftudyG ? I'm looking forward for this...
I did release a very small blogpost/exploit I wrote for a vulnerability found by @joaomatosf some years ago. Vulnerability details are on the slides (link on the post). https://t.co/JPACXTK04f
Time to leak this old (but gold) Pre-Auth RCE effecting some RedHat products. I had already leaked it some years ago at @AlligatorConBR and in the @h2hconference web training (with my friends @reefbr and @marcioalm). https://t.co/G7RAXeDK94
@cyb3rops hey buddy. Let's suppose that important people thought like you and decided to stop, for instance, selling food to places with "Russian language + timezone". Who do you think would be impacted with this "smart" decision? War Guys or Normal People? =]
@pwntester I agree. Changing the things to a non default state in order to make an app/framework/app_server vulnerable should not be considered a real vul also IMHO...
this is what happens when you entrust your company's security to self-titled "security XPTO" who spend all their time criticizing security researchers on twitter
When researchers said no more free bugs, they were serious. This includes red teams. If vendors fail to appropriately incentivize disclosure against prevailing market rates, somebody is gonna pay the bills.