Mikhail Egorov

470 posts

Mikhail Egorov banner
Mikhail Egorov

Mikhail Egorov

@0ang3el

Security researcher & bug hunter

Katılım Mayıs 2016
472 Takip Edilen3.4K Takipçiler
Mikhail Egorov retweetledi
tincho 🪷
tincho 🪷@tinchoabbate·
The MOST vulnerable contracts in all DeFi just got upgraded! ⚙️ New testing env: Solidity 0.8 + Hardhat + Ethers 🌟 4 new levels 💥 New (broken) integrations with Uniswap v2, Gnosis Safe wallets, upgrades, timelocks, NFTs, and more! damnvulnerabledefi.xyz/v2-release.html
English
167
119
347
0
Mikhail Egorov retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Finally, here is the blog for the prototype pollution research we did. "A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild pwn.af/research/pp
s1r1us (mohan) tweet media
English
11
326
714
0
Mikhail Egorov retweetledi
Emil Lerner
Emil Lerner@emil_lerner·
Here're slides from my talk at ZeroNights X! A 0-day for GhostScript 9.50, RCE exploit chain for ImageMagick with the default settings from Ubuntu repos and several bug bounty stories inside slideshare.net/neexemil/hotpi…
English
8
127
359
0
Mikhail Egorov retweetledi
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
A New Attack Surface on Microsoft Exchange! The series covers most of my Black Hat USA and DEFCON talks (with slides and video inside). More articles and vulnerabilities are coming soon! blog.orange.tw/2021/08/proxyl…
English
8
515
1.3K
0
Mikhail Egorov retweetledi
PT SWARM
PT SWARM@ptswarm·
✍️We would like to share with the community some uncommon but not unique cases from our experience. Let us know if you like this format. ✅Stored XSS using .xbl files.
PT SWARM tweet media
English
3
107
261
0
Mikhail Egorov retweetledi
shubs
shubs@infosec_au·
My colleague @seanyeoh wrote up his security research on H2C smuggling and the various cloud providers he successfully exploited (Cloudflare, Azure). He also released a tool called h2csmuggler! Check it out at blog.assetnote.io/2021/03/18/h2c…
English
0
112
338
0
Mikhail Egorov retweetledi
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
I know there are lots of people waiting for the recent Microsoft Exchange pre-auth RCE on our side. This is a short advisory and detailed timeline. proxylogon.com #proxylogon
English
9
430
947
0
Mikhail Egorov retweetledi
PortSwigger
PortSwigger@PortSwigger·
Blog post: mapping out Burp Suite's crawler. This is a deep dive into the crawler, which is at the heart of Burp Suite's capabilities, and covers the crawler's origins, its current state and plans for the future. portswigger.net/blog/web-appli…
English
2
72
170
0
Mikhail Egorov retweetledi
Emil Lerner
Emil Lerner@emil_lerner·
I'm releasing my tool that detects HTTP Request Smuggling opportunities that arise during HTTP/2 -> HTTP/1.1 conversion by the "frontend" servers: github.com/neex/http2smugl. Comments & suggestions much appreciated. @albinowax what do you think about that?
English
2
158
422
0
Mikhail Egorov retweetledi
Jake Miller
Jake Miller@theBumbleSec·
Just when you thought JSON was the one thing you could trust. My latest research on JSON interoperability vulnerabilities highlights the risks of inconsistent parser behavior (40+ parsers) and attacks to bypass business logic in microservice architectures. labs.bishopfox.com/tech-blog/an-e…
English
17
509
1.1K
0
Mikhail Egorov retweetledi
Frans Rosén
Frans Rosén@fransrosen·
We did some fun tricks with nginx on bug bounties a while back, and made a post about out the configurations being vulnerable labs.detectify.com/2021/02/18/mid…
English
8
241
533
0