Ansar Uddin

436 posts

Ansar Uddin

Ansar Uddin

@Ansar0047

Love to pwn system ! https://t.co/sLtQ7Yd5Pt

Bangladesh 🇧🇩 Katılım Aralık 2020
624 Takip Edilen1.9K Takipçiler
Ansar Uddin retweetledi
watchTowr
watchTowr@watchtowrcyber·
Today, we’re releasing watchTowr Labs’ @chudyPB’s BlackHat .NET research, owning Barracuda, Ivanti and more solutions. Enjoy the read as Piotr explains a new .NET Framework primitive, used to achieve pre- and post-auth RCE on numerous enterprise appliances. labs.watchtowr.com/soapwn-pwning-…
English
3
110
372
87.9K
Ansar Uddin retweetledi
James Kettle
James Kettle@albinowax·
This is your last chance to nominate research for the top ten web hacking techniques of 2025! Nominations close at 0800 UTC tomorrow. Form linked below.
James Kettle tweet media
English
3
19
66
13.6K
Ansar Uddin retweetledi
watchTowr
watchTowr@watchtowrcyber·
Oracle has patched two new critical CVEs (CVE-2025-53072 & CVE-2025-62481) in the Marketing Administration component of Oracle E-Business Suite. Given the recent Cl0p activity, exploitation is likely. Patch ASAP. Need help assessing exposure? watchTowr.com
watchTowr tweet media
English
0
17
64
6.6K
Ansar Uddin retweetledi
watchTowr
watchTowr@watchtowrcyber·
The watchTowr team has broken down the Oracle EBS unauth RCE exploit chain (tagged as CVE-2025-61882). Important to note: it is not one vulnerability, but multiple chained together. As always, we'll share more soon.
watchTowr tweet media
English
6
84
334
31.9K
Ansar Uddin retweetledi
shubs
shubs@infosec_au·
My favourite finding from @SLCyberSec's Security Research team in 2025 so far is a secondary context path traversal in Omnissa Workspace One UEM (CVE-2025-25231). Really interesting bug, and fun kill chain to RCE. slcyber.io/assetnote-secu…
English
3
48
196
14.3K
Ansar Uddin retweetledi
spaceraccoon | Eugene Lim
spaceraccoon | Eugene Lim@spaceraccoonsec·
At @defcon, I presented my research on client-side deanonymization attacks in @Google's Privacy Sandbox! Privacy research doesn't get as much attention, but ad-tech is increasingly embedded in everything - it's all about your attention and data. spaceraccoon.dev/client-side-de…
English
7
59
250
34.1K
Ansar Uddin retweetledi
James Kettle
James Kettle@albinowax·
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
English
19
241
753
86.2K
Ansar Uddin retweetledi
Assetnote
Assetnote@assetnote·
Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher @hash_kitten has written up a blog post about a novel technique for SQL Injection in PDO’s prepared statements: slcyber.io/assetnote-secu…
English
1
76
286
12.3K
Ansar Uddin retweetledi
Sam Curry
Sam Curry@samwcyo·
New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: samcurry.net/hacking-subaru
English
47
312
1K
118.1K
Ansar Uddin retweetledi
Jorian
Jorian@J0R1AN·
During @x3ctf, I discovered an unintended solution that turned out to be a pretty cool generic technique. It allows you to detect the result of a selector during CSS Injection, bypassing any CSP restricting external requests! Check out the writeup below: jorianwoltjer.com/blog/p/ctf/x3c…
English
2
48
202
12.9K
Ansar Uddin retweetledi
d4d
d4d@zakfedotkin·
Introducing the Cookie Sandwich, a tasty technique to steal HttpOnly cookies using legacy RFC features: portswigger.net/research/steal…
English
2
92
266
29.6K
Ansar Uddin retweetledi
Sonar Research
Sonar Research@Sonar_Research·
From HTTP request to ROP chain in Node.js! 🔥 Our latest blog post explains how to turn a file write vulnerability in a Node.js application into RCE – even though the target's file system is read-only: sonarsource.com/blog/why-code-…
Sonar Research tweet media
English
4
153
480
70.1K
Ansar Uddin retweetledi
Tom Stacey
Tom Stacey@t0xodile·
Excited to release my latest research today. Exploiting CORS can be a tricky in modern web apps, but there are still critical cases out there if you know what to look for. If you want to learn more about CORS exploitation, the research is available at outpost24.com/blog/exploitin…
English
2
61
175
15.5K
Ansar Uddin retweetledi
James Kettle
James Kettle@albinowax·
Love a good client-side exploit chain! This crazy cross-product chain targeting Google by @rebane2001 is a great example of the type of exploit that gets easier the longer you spend targeting a single company lyra.horse/blog/2024/09/u…
English
1
104
401
41.7K
Ansar Uddin retweetledi
PortSwigger
PortSwigger@PortSwigger·
Couldn't make @garethheyes Splitting the Email Atom event earlier this week? We'll be sharing the recording on our Discord next week. 👀 Make sure you've joined the official PortSwigger Discord 👉 discord.com/invite/portswi…
English
0
4
18
2.5K