We have confirmed the successful demonstration from @artsploit used a previously reported bug. This counts as a partial win, but does earn him 12.5 Master of Pwn points. #P2OMiami#S4x20
Up next and making his #Pwn2Own debut, Michael Stepankin (@artsploit) of Veracode will be targeting a remote code execution with continuation against the Inductive Automation Ignition in the Control Server category. #P2OMiami#S4x20
Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :) spaceraccoon.dev/remote-code-ex…
Our guy, @SecurityMB, had a presentation at OWASP Poland Day about exploiting prototype pollution to RCE on the example of Kibana, by abusing environmental variables in node. The slides are here:
slides.com/securitymb/pro…
We will also release a writeup soon so stay in touch!
Apache Solr research is completed and I'm happy to present some ways to RCE in this innocent looking search engine. See you @ #defcon27@defcondefcon.org/html/defcon-27… …
In our latest blog post we show you various ways how to attack RMI based JMX services. We also release our fork of sJET, which is called MJET (obviously). mogwailabs.de/blog/2019/04/a…
Blog post about attacking Java RMI services, a extension to the talk from Hans-Martin Münch at this years Bsides Munich mogwailabs.de/blog/2019/03/a…. You can also find the slides/material on our GitHub account #BSidesMUC19
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
0 Followers 173 FollowingRecruiti ng webshell e ngineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/DxhrzTFVyE
217 Followers 4K FollowingMy name is Christopher John Mahoney,I'm from Weymouth Massachusetts,i work with the department of defense,i'm the assistant commandant of the US Marines
407 Followers 372 FollowingBreaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJ
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
27K Followers 630 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
43K Followers 897 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
407 Followers 372 FollowingBreaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJ
67K Followers 403 Following➡️Hacker - Helper - Human ⬅️ . . . Also Author. Speaker & Scientific Hooligan! A bona fide teachable moment for hire! he/him
50K Followers 2K FollowingSecure Coding Trainer, Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her 🌻
34K Followers 821 FollowingBe Inspired, Be Amazed, Be Here.
Immerse in world-class culture, sport & iconic architecture. 🎤
Stunning parklands & great food in the heart of east London. 🌲
1.1M Followers 515 FollowingWe are the lead UK government department for immigration & passports, crime & policing, homeland security and protecting vulnerable people.
452K Followers 396 FollowingConservative Party Shadow Foreign Secretary and Member of Parliament for Witham. Promoted by Priti Patel of WCCA, Essex House, 21 Eastways, Witham, CM8 3YQ
2K Followers 179 FollowingSPAC musings, watch lists, viz, polls, and other nuggets. Evening and weekend warrior. Definitely NOT a financial advisor so don’t listen to me.
24K Followers 0 FollowingA global organization advocating the decriminalization of hacking through policy reform. Privacy and security hacktivism. Hack, ergo sum.
#HackingIsNotACrime
10K Followers 255 Followingsecurity enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish.
infosec at @google. opinions are mine.
106K Followers 7 Followinghttps://t.co/fgXNGNt7gm
Abandoned this site in 2022 but hopeful for the future of social media. Consider migrating to DEFCON.socal
2K Followers 403 FollowingEmbedded Firmware Fuzzing at https://t.co/h3RnGfm20g. Ph.D. student. Working on advancing embedded systems software security.
4K Followers 284 FollowingPreviously Red team @ Salesforce, SpecterOps & Big4 | Interested in security, puns, and mountains | Opinions my own
@[email protected]