CloudRip Fast Cloudflare bypass scanner
Find real server IPs behind Cloudflare by scanning subdomains. Multi-threaded for speed, skips Cloudflare-owned IPs, supports custom or built-in wordlists, and exports results. Built-in rate limiting to avoid getting blocked
REPO ⤵️
I have seen lot of stupid things lately concerning CS, EDR's and Windows drivers. I wrote a, not so bad I guess, long blog post explaining how to build a windows driver, why EDR's need them, and how EDR's work, might be helpful 🤪 blog.whiteflag.io/blog/from-wind…
I am thrilled to share my first two CVE assignments CVE-2023-50694 and CVE-2023-50693 for discovering HTTP request smuggling vulnerabilities in HTTPbeast and Jester, both written in Nim language.
tenable.com/cve/CVE-2023-5…tenable.com/cve/CVE-2023-5…
I published a new blog post about how I chained two vulnerabilities I found in Huawei NetEngine AR617VW to achieve post-auth RCE
wr3nchsr.github.io/huawei-netengi…
new ctf tactic for pwners: a flexible arbitrary write -> rce primitive that doesn't rely on the linker, io objects, or malloc.
it's in how your program chooses between SSE or AVX when doing a memcpy!
@pepsipu/SyqPbk94a" target="_blank" rel="nofollow noopener">hackmd.io/@pepsipu/SyqPb…
Like many others, I'm very excited for #37C3. It does however seem like there will be no #CTF this time. We did some brainstorming in the CTF Discord and came up with the idea of a "CCC Potluck CTF". Please read about it and potentially contribute: forms.gle/FaPGE492s9rPzC…