Shiro

89 posts

Shiro

Shiro

@ShiroPycatchown

Vulnerability researcher @Synacktiv, pwn and reverse enthusiast; doing some CTF on my freetime @ @RMUBYGG

Katılım Eylül 2014
166 Takip Edilen219 Takipçiler
Shiro retweetledi
Synacktiv
Synacktiv@Synacktiv·
For our first talk, Ambre presents her previous research about firmware images identification #SSTIC2025
Synacktiv tweet media
English
0
4
17
2.6K
Shiro retweetledi
Hell Diner
Hell Diner@DinerHell·
🔥Introducing Arion🔥 A high-performance C++ framework for emulating executable binaries. Based on Unicorn and inspired by Qiling, Arion offers an easy-to-use interface and super low execution times making it a great ally for fuzzing or other applications. github.com/h311d1n3r/Arion
Hell Diner tweet media
English
2
21
54
4.3K
Shiro retweetledi
Synacktiv
Synacktiv@Synacktiv·
The FastCGI library, mostly used in embedded equipment, was vulnerable for decades to an integer overflow over the IPC socket in 32-bits architecture. Check out how @ShiroPycatchown found it and exploited it for RCE! synacktiv.com/en/publication…
English
0
42
140
9.2K
Shiro
Shiro@ShiroPycatchown·
@und3ath1 Best of luck mate, hope to see you back and ready asap
English
0
0
1
94
und3ath
und3ath@und3ath1·
2nd pneumothorax in 2 months.. time for a painful surgery :/ .
English
2
0
1
362
Shiro retweetledi
Shiro retweetledi
RootMeUpBeforeYouGoGo
RootMeUpBeforeYouGoGo@RMUBYGG·
We had the chance to team up with some friends of @AperiKube and @navalgroup for this edition of #leHack CTF and managed to win the first place ! 🥳🤘 Thanks @_leHACK_ for the whole event and congratulations to the Capgemini alliance and @Synacktiv ! See u next year
RootMeUpBeforeYouGoGo tweet mediaRootMeUpBeforeYouGoGo tweet media
English
3
13
40
0
Shiro
Shiro@ShiroPycatchown·
@TheLaluka @podalirius_ 'don't want to sound mean though, I just disagree with the idea, I think it could be a good one for specific cases, but not for a generic shellcode
English
0
0
1
0
Laluka@OffenSkill
Laluka@OffenSkill@TheLaluka·
@ShiroPycatchown @podalirius_ Well, might be a bit longer to generate the shellcode, but once you have it, it can be replayed anywhere independently from the shell type, so "a bit more portable", given you have python.. But you're right, the problem is just moved away :p
English
2
0
0
0
Rémi GASCOU (Podalirius)
Rémi GASCOU (Podalirius)@podalirius_·
[thread] Isn't it annoying when you have a working shellcode, but the wrong rights in the spawned shell ? Newer versions of UNIX shells no longer transfer SUID rights by default. Here is the shells affected by this, as well as a new shellcode for tclsh: podalirius.net/en/articles/un…
English
1
10
26
0
Shiro
Shiro@ShiroPycatchown·
@TheLaluka @podalirius_ Well, portable... You got to have the right python path, the right version for the binary, and hope for it to be there. While when you have a shell, if you want it to be persistent, well, you have a shell, so just write the commands
English
0
0
1
0
Shiro
Shiro@ShiroPycatchown·
@TheLaluka @podalirius_ Honestly; that still sounds longer than just adding a setresuid call on the shellcode, or maybe I did not completely understand what you meant.
English
1
0
0
0
Laluka@OffenSkill
Laluka@OffenSkill@TheLaluka·
@podalirius_ Why copy it ? Just add the setuid bit on the main python instance, and then have a python snippet ready to spawn a clean shell and remove its own setuid bit ?
English
1
0
0
0
Shiro retweetledi
RootMeUpBeforeYouGoGo
RootMeUpBeforeYouGoGo@RMUBYGG·
We end up #2 of the Barbhack's CTF! Really proud of this result 🤘 Big GG to all the other teams, last hour was insane Thank you @_barbhack_ for this awesome event, we had a ton of fun meeting a lot of wonderful hackers and with the great confs/workshops. See u next year ❤️
Barbhack@_barbhack_

📣 Scoreboard #CTF #BarbHack21 👏 Bravo à toutes les #teams 💪 🏴‍☠️ A vos RT, Like et commentaires 🤓 Dites nous ce que vous avez pensé du #ctf 2021 #teamctf

English
0
6
21
0
Shiro retweetledi
Barbhack
Barbhack@_barbhack_·
📣 Gagnants #CTF BarbHack 2021 ! 🏅Synacktiv 🥈RootMeUpbeforeyouGoGo 🥉NavHack 👏 Félicitations à tous rdv en 2022!
Barbhack tweet mediaBarbhack tweet mediaBarbhack tweet media
Français
1
28
113
0