During a penetration test, we came across a Siemens ICS (Industrial Control System) / BMS (Building Management System) device and decided to study its custom HTTP component
Two critical vulnerabilities were discovered and disclosed to Siemens ProductCERT
https://t.co/kTKuZXYoJp
The team is getting stronger with recent hires 💪
@m0kr4n3 is joining as a pentester intern 🥋
@t0m7r00z is joining as a reverser intern 👨🔬
@jeynthan is joining as a reverser 👨🔬
We proudly secured 6th place out of 1,128 teams in the @hackthebox_eu University CTF 2024: Binary Badlands, representing @EsiAlger! 💻
Huge shoutout to our incredible team for their efforts and dedication! 👏
Congrats to @HPI_NYC, @NUSGreyhats, and @esnabretagne! 🏆
#CTF#HTB
Let's give it up for October’s featured huntr Mokrane, aka @m0kr4n3, who hacked open-webui with a custom-crafted payload. 👏 Result? Total admin access. Read up on his story, get inspired, but don’t try this at home… or do. 🐰👇
https://t.co/nKzDkJLo1d
Excited to launch my first browser extension, DOMLogger++! Now available for both Firefox and Chromium! 🎉
DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations 🔥
Check it out 👇
https://t.co/D9OiEIKQp3
1/5
@kevin_mizu I saw many reports where @huntr_ai validates reports if they estimate that it’s a valid one, even though the repo maintainer doesn’t agree, so they validate it and give the bounty without issuing a CVE. I think it’s the case here xD
Bug squashing season was successful! 🐛 We’ve ironed out issues from SSE compatibility to security fixes. Shoutout to @ouxs11, @m0kr4n3, https://t.co/PUhF8ObJLb, @mudler_it for their wizardry. Our platform's smoother and more stable because of you.
Thread 3/9 🧵
Redirect/SSRF payload generator opened by @intigriti
This online tool will generate payloads for you to bypass filters to reach open redirect/SSRF vulnerability.
https://t.co/lFWP10AXF2
Just published a new article about Keccak/Sha3 (explains its steps in simple words, and explains how leaking the internal state can lead to unwanted consequences)
https://t.co/oZyvZuVJT4
Feedback is welcome (PS: I'm not a cryptographer)
The next Community voice is not-to-miss opportunity🤩
Have you ever wanted to make an impact; but you don't know how to start🤔?
Stay tuned for the "Open source week" where you will make the change from anywhere in the world 🌏
#GDG#WTM#CommunityVoice#learn#technology#share
With the end of the CTF competition, BSides is now officially over 🏴☠️
We would like to say thank you to all our participants, and congratulations to the winners 🔥
It was an honor having you, mates!
/* Where there is a shell, there is a way */
#shellmates#hack#ctf
GDG Algiers comes back with a brand new surprise 🎉
Curious to know what Brainy and the team have been up to?
Stay in the loop for more to come.
@googledevgroups#gdg#wtm
Dear community!
This year's edition is quite special, as we have prepared a selection of workshops that encompass several areas of cybersecurity.
Without further ado, here are the workshops that will be held in the D-day.
Stay tuned!
#hackini#ctf#cybersecurity