Soroush Dalili

@irsdl

Another ethical web appsec guy - breaker 〉builder - very limited BB hunter - delimiter characters fan - RT/LK can be an accident or not "'›|&;${3-1}\

World of Sec! 0xC0000005 Err
Beigetreten August 2009

Tweets

Du hast @irsdl blockiert

Bist du sicher, dass du diese Tweets sehen willst? Das Ansehen von Tweets wird @irsdl nicht entblocken.

  1. Angehefteter Tweet
    25. Apr.

    With the release of my ViewState plugin for , here is my blog post on Exploiting Deserialisation in ASPNET via ViewState:

    Diesen Thread anzeigen
    Rückgängig machen
  2. hat retweetet
    31. Okt.

    Did you know you can use the Connection header to delete other headers? Interesting research lead by :

    Diesen Thread anzeigen
    Rückgängig machen
  3. 31. Okt.

    Perhaps also join in even if you are a fan ;)

    Rückgängig machen
  4. 31. Okt.

    Probably the last time I am doing this with this laptop - research continues! I am going to miss my stickers

    Rückgängig machen
  5. hat retweetet
    27. Okt.

    Oh shit there is a video that backs up the ‘don’t congratulate Obama’ .. Can’t wait for the announcement..

    Rückgängig machen
  6. hat retweetet
    25. Okt.

    As I'm currently missing and so can't troll in person here's a blog about the recent changes to my .NET Remoting Exploit tool to bypass Low Type Filtering .

    Rückgängig machen
  7. hat retweetet
    25. Okt.

    Advisory: OneDrive/SharePoint File Picker Access Token Hijacking - by Adam Roberts

    Rückgängig machen
  8. hat retweetet
    24. Okt.

    I know DoS attacks are deeply unsexy, and I'm still somewhat in shock that I ever wrote an entire post about them. The core aim of this post is to illustrate how in the right circumstances they can be fun, high-impact and profitable

    Diesen Thread anzeigen
    Rückgängig machen
  9. hat retweetet
    21. Okt.

    While not officially confirmed yet, this is very likely to be true. Also it’s worth remembering that some of the attacks results never see the light of public news because targets prefer to remain silent either for intel obervations or simply avoid empowering attackers by an ack.

    Rückgängig machen
  10. hat retweetet
    5. Okt.

    Can’t stress enough the importance of patching affected VPN products. We’re seeing multiple groups exploiting these vulnerabilities.

    Rückgängig machen
  11. hat retweetet
    17. Okt.
    Rückgängig machen
  12. 16. Okt.
    Rückgängig machen
  13. hat retweetet
    14. Okt.

    OWASP Birmingham is pleased to announce it's hosting a Capture the Flag meetup in November supported by Kainos and Secure Code Warrior

    Rückgängig machen
  14. hat retweetet
    14. Okt.

    This is so insane. This was a straight-forward solution for Buggy .Net from

    Diesen Thread anzeigen
    Rückgängig machen
  15. hat retweetet
    12. Okt.

    HITCON CTF 2019 Quals is ongoing now! and I designed an XSS challenge this time and there are two solutions at least, could you find that? :D http://3.114.5.202/

    Rückgängig machen
  16. hat retweetet
    11. Okt.
    Antwort an

    Can't we have the old school instant (bit broken) render AND the new shiny render button, if we need it?

    Rückgängig machen
  17. 10. Okt.
    Rückgängig machen
  18. hat retweetet
    7. Okt.

    Updated my tool to exploit .NET remoting services to use a new (unpatched) technique to bypass Low Type Filter to get full serialization exploitation. Abuses the lease feature present on all MBR objects. . Don't use .NET remoting in production code!

    Rückgängig machen
  19. hat retweetet
    6. Okt.
    Antwort an
    Rückgängig machen
  20. 3. Okt.

    This is the command to activate all the bots from 3 years ago: WAKE UP AGAIN AND JOIN THE COLLECTIVE NOW! He should really be proud of himself to type these words correctly!

    Rückgängig machen
  21. 3. Okt.

    Just a friendly reminder that is still mine! 🤓 😇

    Rückgängig machen

Das Laden scheint etwas zu dauern.

Twitter ist möglicherweise überlastet oder hat einen vorübergehenden Schluckauf. Probiere es erneut oder besuche Twitter Status für weitere Informationen.

    Vielleicht gefällt dir auch

    ·