Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @yarlob
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @yarlob
-
Jaroslav Lobačevski proslijedio/la je Tweet
This weekend is your last chance to vote for the Top 10 (new) Web Hacking Techniques of 2019! Voting closes Monday.https://portswigger.net/polls/top-10-web-hacking-techniques-2019 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So this is what it was about... Glad I could help :)https://twitter.com/WPalant/status/1216651056995807232 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Just wrote a short blog post about a win32k info leak I found earlier this year:https://www.ragestorm.net/blogs/?p=458
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
So overhyped. https://gbhackers.com/chrome-zero-day/ … Not a single word in the article that is works on Win7 only (well until someone weaponized his sandbox escape). But if you look closer at the screenshot you see "Windows NT 6.1" check :)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
As I'm currently missing
#bluehatseattle and so can't troll@blowdart in person here's a blog about the recent changes to my .NET Remoting Exploit tool to bypass Low Type Filtering https://tyranidslair.blogspot.com/2019/10/bypassing-low-type-filter-in-net.html ….Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
We added AddressSanitizer (ASan) support to MSVC in the latest Visual Studio preview. So now you can not only use it for applications targeting Linux from VS, but Windows too, to find runtime memory issues fast:https://devblogs.microsoft.com/cppblog/addresssanitizer-asan-for-windows-with-msvc/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
So apparently NordVPN was compromised at some point. Their (expired) private keys have been leaked, meaning anyone can just set up a server with those keys...pic.twitter.com/TOap6NyvNy
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Our guy,
@SecurityMB, had a presentation at OWASP Poland Day about exploiting prototype pollution to RCE on the example of Kibana, by abusing environmental variables in node. The slides are here: https://slides.com/securitymb/prototype-pollution-in-kibana/#/ … We will also release a writeup soon so stay in touch!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Updated my tool to exploit .NET remoting services to use a new (unpatched) technique to bypass Low Type Filter to get full serialization exploitation. Abuses the lease feature present on all MBR objects. https://github.com/tyranid/ExploitRemotingService …. Don't use .NET remoting in production code!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
SecurityCodeScan is used by
@StackOverflow now. https://stackoverflow.blog/2019/10/08/adding-static-code-analysis-to-stack-overflow/ ….@kevinmontrose is a great contributor btw.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Windows Exploitation Tricks: Spoofing Named Pipe Client PID https://googleprojectzero.blogspot.com/2019/09/windows-exploitation-tricks-spoofing.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
It has come to my attention that it is not at all clear that
@spdevlin’s Cryptopals Set 8 is public, and has been for awhile: https://toadstyle.org/cryptopals/Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
A very deep dive into iOS Exploit chains found in the wild https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Yea, I've got 3 hours to kill here in this airport lounge waiting for the next leg of my flight, so let's discuss the "OSI Model". There's no such thing. What they taught you is a lie, and they knew it was a lie, and they didn't care, because they are jerks.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
In multiple recent disclosure discussions on Twitter, I had said I will write a longer blog post about my views. I finally found the time to jot them down. I expect almost every reader to disagree with something vehemently. Enjoy "Disclosure Rashomon": http://addxorrol.blogspot.com/2019/08/rashomon-of-disclosure.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Another great work from
@LucaBongiorni#USBSamurai — A Remotely Controlled Malicious#USB#HID Injecting Cable for less than 10$ https://securityaffairs.co/wordpress/89978/hacking/usbsamurai-usb-hid.html …#securityaffairs#hackingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
It turns out it was possible to reach across sessions and violate NT security boundaries for nearly twenty years, and nobody noticed.https://twitter.com/taviso/status/1161277080723529728 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
With Vegas over and done with for another year, it's time to go Twitter dark for a while. But one last blog before I go https://tyranidslair.blogspot.com/2019/08/windows-code-injection-bypassing-cig.html … for
@monoxgas and hat tip to@HexacornHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you have
@steam_games client installed on Windows, you are potentially running any program as NT AUTHORITY\SYSTEM. First they don't care they compromise your OS security model, then@Hacker0x01 tries to forbid the disclosure.https://twitter.com/enigma0x3/status/1159103239729471488 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jaroslav Lobačevski proslijedio/la je Tweet
Another opening in my AppSec team :https://www.linkedin.com/jobs/view/1391800927/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
research today, a major design flaw in Windows that's existed for almost *two decades*. I wrote a blog post on the story of the discovery all the way through to exploitation.