Soroush Dalili

@irsdl

Another ethical web appsec guy - breaker 〉builder - very limited BB hunter - delimiter characters fan - RT/LK can be an accident or not "'›|&;${3-1}\

World of Sec! 0xC0000005 Err
S-a alăturat în august 2009

Tweeturi

Ai blocat pe @irsdl

Sigur vrei să vezi aceste Tweeturi? Vizualizarea Tweeturilor nu va debloca utilizatorul @irsdl

  1. Tweet fixat
    25 apr.

    With the release of my ViewState plugin for , here is my blog post on Exploiting Deserialisation in ASPNET via ViewState:

    Afișează acest fir
    Anulează acțiunea
  2. a redistribuit
    31 oct.

    Did you know you can use the Connection header to delete other headers? Interesting research lead by :

    Afișează acest fir
    Anulează acțiunea
  3. 31 oct.

    Perhaps also join in even if you are a fan ;)

    Anulează acțiunea
  4. 31 oct.

    Probably the last time I am doing this with this laptop - research continues! I am going to miss my stickers

    Anulează acțiunea
  5. a redistribuit
    27 oct.

    Oh shit there is a video that backs up the ‘don’t congratulate Obama’ .. Can’t wait for the announcement..

    Anulează acțiunea
  6. a redistribuit
    25 oct.

    As I'm currently missing and so can't troll in person here's a blog about the recent changes to my .NET Remoting Exploit tool to bypass Low Type Filtering .

    Anulează acțiunea
  7. a redistribuit
    25 oct.

    Advisory: OneDrive/SharePoint File Picker Access Token Hijacking - by Adam Roberts

    Anulează acțiunea
  8. a redistribuit
    24 oct.

    I know DoS attacks are deeply unsexy, and I'm still somewhat in shock that I ever wrote an entire post about them. The core aim of this post is to illustrate how in the right circumstances they can be fun, high-impact and profitable

    Afișează acest fir
    Anulează acțiunea
  9. a redistribuit
    21 oct.

    While not officially confirmed yet, this is very likely to be true. Also it’s worth remembering that some of the attacks results never see the light of public news because targets prefer to remain silent either for intel obervations or simply avoid empowering attackers by an ack.

    Anulează acțiunea
  10. a redistribuit
    5 oct.

    Can’t stress enough the importance of patching affected VPN products. We’re seeing multiple groups exploiting these vulnerabilities.

    Anulează acțiunea
  11. a redistribuit
    17 oct.
    Anulează acțiunea
  12. 16 oct.
    Anulează acțiunea
  13. a redistribuit
    14 oct.

    OWASP Birmingham is pleased to announce it's hosting a Capture the Flag meetup in November supported by Kainos and Secure Code Warrior

    Anulează acțiunea
  14. a redistribuit
    14 oct.

    This is so insane. This was a straight-forward solution for Buggy .Net from

    Afișează acest fir
    Anulează acțiunea
  15. a redistribuit
    12 oct.

    HITCON CTF 2019 Quals is ongoing now! and I designed an XSS challenge this time and there are two solutions at least, could you find that? :D http://3.114.5.202/

    Anulează acțiunea
  16. a redistribuit
    11 oct.
    Răspuns către

    Can't we have the old school instant (bit broken) render AND the new shiny render button, if we need it?

    Anulează acțiunea
  17. 10 oct.
    Anulează acțiunea
  18. a redistribuit
    7 oct.

    Updated my tool to exploit .NET remoting services to use a new (unpatched) technique to bypass Low Type Filter to get full serialization exploitation. Abuses the lease feature present on all MBR objects. . Don't use .NET remoting in production code!

    Anulează acțiunea
  19. a redistribuit
    6 oct.
    Răspuns către
    Anulează acțiunea
  20. 3 oct.

    This is the command to activate all the bots from 3 years ago: WAKE UP AGAIN AND JOIN THE COLLECTIVE NOW! He should really be proud of himself to type these words correctly!

    Anulează acțiunea
  21. 3 oct.

    Just a friendly reminder that is still mine! 🤓 😇

    Anulează acțiunea

Încărcarea pare că durează ceva timp.

Este posibil ca Twitter să fie suprasolicitat momentan sau să întâmpine mici probleme. Încearcă din nou sau vizitează Starea Twitter pentru mai multe informații.

    S-ar putea să-ți placă și

    ·