Soroush Dalili

@irsdl

Another ethical web appsec guy - breaker 〉builder - very limited BB hunter - delimiter characters fan - RT/LK can be an accident or not "'›|&;${3-1}\

World of Sec! 0xC0000005 Err
Geregistreerd in augustus 2009

Tweets

Je hebt @irsdl geblokkeerd

Weet je zeker dat je deze Tweets wilt bekijken? @irsdl wordt niet gedeblokkeerd door Tweets te bekijken.

  1. Vastgemaakte Tweet
    25 apr.

    With the release of my ViewState plugin for , here is my blog post on Exploiting Deserialisation in ASPNET via ViewState:

    Deze collectie tonen
    Ongedaan maken
  2. heeft geretweet
    31 okt.

    Did you know you can use the Connection header to delete other headers? Interesting research lead by :

    Deze collectie tonen
    Ongedaan maken
  3. 31 okt.

    Perhaps also join in even if you are a fan ;)

    Ongedaan maken
  4. 31 okt.

    Probably the last time I am doing this with this laptop - research continues! I am going to miss my stickers

    Ongedaan maken
  5. heeft geretweet
    27 okt.

    Oh shit there is a video that backs up the ‘don’t congratulate Obama’ .. Can’t wait for the announcement..

    Ongedaan maken
  6. heeft geretweet
    25 okt.

    As I'm currently missing and so can't troll in person here's a blog about the recent changes to my .NET Remoting Exploit tool to bypass Low Type Filtering .

    Ongedaan maken
  7. heeft geretweet

    Advisory: OneDrive/SharePoint File Picker Access Token Hijacking - by Adam Roberts

    Ongedaan maken
  8. heeft geretweet
    24 okt.

    I know DoS attacks are deeply unsexy, and I'm still somewhat in shock that I ever wrote an entire post about them. The core aim of this post is to illustrate how in the right circumstances they can be fun, high-impact and profitable

    Deze collectie tonen
    Ongedaan maken
  9. heeft geretweet
    21 okt.

    While not officially confirmed yet, this is very likely to be true. Also it’s worth remembering that some of the attacks results never see the light of public news because targets prefer to remain silent either for intel obervations or simply avoid empowering attackers by an ack.

    Ongedaan maken
  10. heeft geretweet
    5 okt.

    Can’t stress enough the importance of patching affected VPN products. We’re seeing multiple groups exploiting these vulnerabilities.

    Ongedaan maken
  11. heeft geretweet
    17 okt.
    Ongedaan maken
  12. 16 okt.
    Ongedaan maken
  13. heeft geretweet
    14 okt.

    OWASP Birmingham is pleased to announce it's hosting a Capture the Flag meetup in November supported by Kainos and Secure Code Warrior

    Ongedaan maken
  14. heeft geretweet
    14 okt.

    This is so insane. This was a straight-forward solution for Buggy .Net from

    Deze collectie tonen
    Ongedaan maken
  15. heeft geretweet
    12 okt.

    HITCON CTF 2019 Quals is ongoing now! and I designed an XSS challenge this time and there are two solutions at least, could you find that? :D http://3.114.5.202/

    Ongedaan maken
  16. heeft geretweet
    11 okt.
    Als antwoord op

    Can't we have the old school instant (bit broken) render AND the new shiny render button, if we need it?

    Ongedaan maken
  17. 10 okt.
    Ongedaan maken
  18. heeft geretweet
    7 okt.

    Updated my tool to exploit .NET remoting services to use a new (unpatched) technique to bypass Low Type Filter to get full serialization exploitation. Abuses the lease feature present on all MBR objects. . Don't use .NET remoting in production code!

    Ongedaan maken
  19. heeft geretweet
    6 okt.
    Als antwoord op
    Ongedaan maken
  20. 3 okt.

    This is the command to activate all the bots from 3 years ago: WAKE UP AGAIN AND JOIN THE COLLECTIVE NOW! He should really be proud of himself to type these words correctly!

    Ongedaan maken
  21. 3 okt.

    Just a friendly reminder that is still mine! 🤓 😇

    Ongedaan maken

Het laden lijkt wat langer te duren.

Twitter is mogelijk overbelast of ondervindt een tijdelijke onderbreking. Probeer het opnieuw of bekijk de Twitter-status voor meer informatie.

    Je bent misschien ook geïnteresseerd in

    ·