Philippe Arteau

418 posts

Philippe Arteau banner
Philippe Arteau

Philippe Arteau

@h3xstream

Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.

Montréal, Canada Beigetreten Eylül 2011
215 Folgt2.5K Follower
Philippe Arteau retweetet
James Kettle
James Kettle@albinowax·
We’re finally live! You can now watch “Listen to the whispers: web timing attacks that actually work” on YouTube: youtube.com/watch?v=zOPjz-…
YouTube video
YouTube
English
4
94
316
27.8K
Philippe Arteau retweetet
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Did you know that the CPU vuln "Zenbleed" 🩸 (CVE-2023-20593) was found through fuzzing? I was able to talk to @taviso and learned about his novel approach 🤯 it is so clever!!
English
10
133
690
82.6K
Philippe Arteau retweetet
GoSecure
GoSecure@GoSecure_Inc·
🎯 "After some research; [...] we had to conclude that this was unknown to the public and that it could potentially be an unintentional bug in MSSQL." Read our latest blog ⬇ bit.ly/3PoAnJM #cybersecurity #AWS #Amazon #EthicalHacking
GoSecure tweet media
English
1
13
26
8.4K
Philippe Arteau retweetet
Tristan Gosselin-Hane
Tristan Gosselin-Hane@eltdude·
Achieved first blood jackpotting the ATM at @NorthSec_io #nsec2023 CTF this weekend! The most insane and thrilling hack I've pulled off at a CTF so far, it certainly caught the eyes of everyone in the room and the event organizers, describing it "straight out of a movie"!
English
10
37
239
23.3K
Philippe Arteau retweetet
Masato Kinugawa
Masato Kinugawa@kinugawamasato·
Today, I learned that Express returns a Refer*r*er header via `req.get('referer')` code: #L77-L80" target="_blank" rel="nofollow noopener">github.com/expressjs/expr…
Masato Kinugawa tweet media
English
4
26
182
38.1K
Philippe Arteau retweetet
Alvaro Muñoz
Alvaro Muñoz@pwntester·
Had some fun with OGNL sandboxes last year. Read how I bypassed Atlassian Confluence and Struts ones in my latest blog post github.blog/2023-01-27-byp…
English
1
90
199
40K
Philippe Arteau retweetet
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
Chrome has removed the path property from events in version 109. We've updated our article about bypassing CSP with AngularJS to reflect this. The workaround is to use the composedPath() function. portswigger.net/research/angul…
English
0
22
65
17.3K
Philippe Arteau retweetet
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
Nominations are now open for the Top 10 web hacking techniques of 2022! You can view the current nomination list and submit your favourite new techniques here: portswigger.net/research/top-1…
English
0
80
186
29.7K
Philippe Arteau retweetet
sudi
sudi@sudhanshur705·
I just published Exploring the World of ESI Injection Feedbacks are appreciated , let me know if you liked it or not :) Special thanks to @nytr0gen_ link.medium.com/0WFFFk7n9vb
English
23
179
515
99.1K
Olivier Bilodeau
Olivier Bilodeau@obilodeau·
Stumbled upon my original proposal document to host a Hacker Jeopardy at HackUS 2 in 2011. Still doing it 10+ years later at @NorthSec_io!
Olivier Bilodeau tweet media
English
2
1
22
0
Philippe Arteau retweetet
mc_0wn
mc_0wn@mc_0wn·
Over a month ago Apache Struts submitted fixes for CVE-2021-31805. Not sure everyone noticed, but there were multiple RCEs fixed in this. Here was another: mc0wn.blogspot.com/2022/05/2nd-rc…
English
1
58
151
0
Philippe Arteau retweetet
Synacktiv
Synacktiv@Synacktiv·
If you see two guys wearing Synacktiv t-shirts with big antennas, you should turn around with your @Tesla! 0-click RCE demonstration on a real vehicle, with CAN messages sent to switch on headlights, wipers and trunk 😎 #Pwn2Own
English
6
122
418
0
Philippe Arteau
Philippe Arteau@h3xstream·
I wrote an article about small privacy leaks prevalent in web applications. These are not the most critical vulnerability patterns, but it was still a lot of fun to document.
GoSecure@GoSecure_Inc

Are you aware of these common pitfalls that can compromise #applicationsecurity and leak private user information? Our latest blog illustrates 6 hard to find but important #privacy risks for developers to consider. gosecure.net/blog/2022/03/1… #appsec

English
0
0
4
0