Turns out my #PHRACK article is live! 🔥
> The Art of PHP — My CTF Journey and Untold Stories!
Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the @Phrack crew for keeping it real! 🎉
https://t.co/BMCLlHti7q
A 12,600$ Bounty and a Software Supply Chain Attack that could have impacted millions 🤯
Let me share you those 2 stories in this article ! 🤟
Link in the thread 🧵
Kill your AV/EDR product by getting the exact location it exists on disk (with the defrag API) and corrupting it. Bitlocker will boot on the drive but won’t be able to decrypt the data correctly.
https://t.co/FbMLQ3VIL1
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
Worried about attackers sneakily spying on your optical fibers ? Learn with @r3n1k how they operate, and how you can defeat them - for cheaper than a flagship smartphone !
https://t.co/j6u0Icapip
1/ A world first reverse engineering analysis of AWS Session Tokens.
Prior to our research these tokens were a complete black box. Today, we are making it more of a glass box, by sharing code and tools to analyze and modify AWS Session Tokens.
https://t.co/a1d4iznkSs
This HTML parsing behavior is absolutely wtf...
It can be abused to completely bypass any server-side HTML sanitizer when a second user input is present earlier in the document within a script string...
This feature of @github has to be one of the biggest operational security risks.
Why when you're searching to add people do a repo does it search the entire corpus of users?!
Show me the people in my org first!
At @assetnote, we published our research on Magento's pre-authentication XXE (CVE-2024-34102). @hash_kitten and I reproduced this issue together. It is a brilliant vulnerability originally found by Sergey Temnikov. You can read our research here: https://t.co/wENjzVSAYh
Have you heard of ORM Leak vulnerabilities? @elttam just published a super interesting deep dive into them, with tons of potential for further research
https://t.co/riiMfjsKh2
We found a Remote Code Execution (RCE) vulnerability in @Ollama - one of the most popular AI inference projects on GitHub. Here is everything you need to know about #Probllama (CVE-2024-37032) 🧵👇
git add -p
(this is bonus comic #4 for "How Git Works" https://t.co/7dO6Y4NFXN, covering some topics that I didn't have space for in the zine)
permalink: https://t.co/PNgrwuypxQ