Soroush Dalili

@irsdl

Another ethical web appsec guy - breaker 〉builder - very limited BB hunter - delimiter characters fan - RT/LK can be an accident or not "'›|&;${3-1}\

World of Sec! 0xC0000005 Err
Participa desde agosto de 2009

Tweets

Você bloqueou @irsdl

Tem certeza de que deseja ver estes Tweets? Visualizar os Tweets não desbloqueará @irsdl

  1. Tweet Fixado
    25 de abr

    With the release of my ViewState plugin for , here is my blog post on Exploiting Deserialisation in ASPNET via ViewState:

    Mostrar esta sequência
    Desfazer
  2. retweetou
    31 de out

    Did you know you can use the Connection header to delete other headers? Interesting research lead by :

    Mostrar esta sequência
    Desfazer
  3. 31 de out

    Perhaps also join in even if you are a fan ;)

    Desfazer
  4. 31 de out

    Probably the last time I am doing this with this laptop - research continues! I am going to miss my stickers

    Desfazer
  5. retweetou
    27 de out

    Oh shit there is a video that backs up the ‘don’t congratulate Obama’ .. Can’t wait for the announcement..

    Desfazer
  6. retweetou
    25 de out

    As I'm currently missing and so can't troll in person here's a blog about the recent changes to my .NET Remoting Exploit tool to bypass Low Type Filtering .

    Desfazer
  7. retweetou
    25 de out

    Advisory: OneDrive/SharePoint File Picker Access Token Hijacking - by Adam Roberts

    Desfazer
  8. retweetou
    24 de out

    I know DoS attacks are deeply unsexy, and I'm still somewhat in shock that I ever wrote an entire post about them. The core aim of this post is to illustrate how in the right circumstances they can be fun, high-impact and profitable

    Mostrar esta sequência
    Desfazer
  9. retweetou
    21 de out

    While not officially confirmed yet, this is very likely to be true. Also it’s worth remembering that some of the attacks results never see the light of public news because targets prefer to remain silent either for intel obervations or simply avoid empowering attackers by an ack.

    Desfazer
  10. retweetou
    5 de out

    Can’t stress enough the importance of patching affected VPN products. We’re seeing multiple groups exploiting these vulnerabilities.

    Desfazer
  11. retweetou
    17 de out
    Desfazer
  12. 16 de out
    Desfazer
  13. retweetou
    14 de out

    OWASP Birmingham is pleased to announce it's hosting a Capture the Flag meetup in November supported by Kainos and Secure Code Warrior

    Desfazer
  14. retweetou
    14 de out

    This is so insane. This was a straight-forward solution for Buggy .Net from

    Mostrar esta sequência
    Desfazer
  15. retweetou
    12 de out

    HITCON CTF 2019 Quals is ongoing now! and I designed an XSS challenge this time and there are two solutions at least, could you find that? :D http://3.114.5.202/

    Desfazer
  16. retweetou
    11 de out
    Em resposta a

    Can't we have the old school instant (bit broken) render AND the new shiny render button, if we need it?

    Desfazer
  17. 10 de out
    Desfazer
  18. retweetou
    7 de out

    Updated my tool to exploit .NET remoting services to use a new (unpatched) technique to bypass Low Type Filter to get full serialization exploitation. Abuses the lease feature present on all MBR objects. . Don't use .NET remoting in production code!

    Desfazer
  19. retweetou
    6 de out
    Em resposta a
    Desfazer
  20. 3 de out

    This is the command to activate all the bots from 3 years ago: WAKE UP AGAIN AND JOIN THE COLLECTIVE NOW! He should really be proud of himself to type these words correctly!

    Desfazer
  21. 3 de out

    Just a friendly reminder that is still mine! 🤓 😇

    Desfazer

O carregamento parece estar demorando.

O Twitter deve estar sobrecarregado ou passando por algum problema momentâneo. Tente novamente ou acesse o Status do Twitterpara obter mais informações.

    Você também pode gostar

    ·