Jusepe

127 posts

Jusepe banner
Jusepe

Jusepe

@Jusepe_it

InTernet lover

Katılım Eylül 2020
299 Takip Edilen140 Takipçiler
Jusepe retweetledi
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
Stuck on a blind PHP file-read? @_remsio_ has just built on @hash_kitten's research using filter chains to trigger an OOM oracle and leak file contents. synacktiv.com/en/publication… twitter.com/PortSwiggerRes…
PortSwigger Research@PortSwiggerRes

Just learned you can exploit blind file-reads in PHP by combining the dechunk filter with the PHP memory limit. This crazy finding by @hash_kitten is a great reminder to pay attention to CTF writeups! github.com/DownUnderCTF/C…

English
0
23
86
15.5K
Jusepe
Jusepe@Jusepe_it·
However, libc is in fact the one that is in charge of that task (#L163" target="_blank" rel="nofollow noopener">elixir.bootlin.com/glibc/latest/s…) . Created a simple PoC to test how .init section is only loaded when is linked with libc. gist.github.com/itasahobby/11e…
English
0
0
0
0
Jusepe
Jusepe@Jusepe_it·
Interesting how Linux seems to delegate some of ELF specification compliance. According to the specs "When a program starts to run, the system executes the code in this section before calling the main program entry point" (refering to .init section).
English
1
0
2
0
Jusepe retweetledi
Flaggermeister
Flaggermeister@flaggermeister·
We won DEADFACE CTF 2022 by @CHacktics ! So nice CTF, we loved the way that the story and the challenges are related. Its sucha a pleasure to participate on CTFs like this.
Flaggermeister tweet media
English
1
10
30
0
Jusepe retweetledi
raptor
raptor@0xdea·
Another awesome #BGGP3 writeup (well, not exactly an entry for the context but close enough)! Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later xcellerator.github.io/posts/tetsuji/
English
0
6
12
0
Jusepe retweetledi
shubs
shubs@infosec_au·
Really well written post by @fransrosen on breaking OAuth implementations through postMessage gadgets that leak URLs. Awesome research, I loved following the journey. Totally worth the time it took you to do this. @avlidienbrunn is a great sounding board. labs.detectify.com/2022/07/06/acc…
English
2
62
234
0
Jusepe retweetledi
N0xi0us
N0xi0us@_N0xi0us_·
This year's @synackredteam recognition program is over and I was inducted into the acropolis due to my performance. acropolis.synack.com/inductees/n0xi… I would also like to congratulate all the srt colleagues who earned their spot as they did an amazing job throughout the year.
English
5
2
24
0
Jusepe
Jusepe@Jusepe_it·
W25Q512JV flash high level driver for rpk2 by @therealdreg , also used it to create a CTF challenge for @uad360. May come handy when developing your own driver or just to grasp how flash devices work. github.com/itasahobby/win…
English
2
1
9
0