Mikhail Firstov

1K posts

Mikhail Firstov banner
Mikhail Firstov

Mikhail Firstov

@cyberpunkych

Security Researcher

Москва, Россия Katılım Ekim 2014
718 Takip Edilen1.2K Takipçiler
Sabitlenmiş Tweet
Mikhail Firstov retweetledi
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
Turns out my #PHRACK article is live! 🔥 > The Art of PHP — My CTF Journey and Untold Stories! Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the @Phrack crew for keeping it real! 🎉 #article" target="_blank" rel="nofollow noopener">phrack.org/issues/72/5_md…
Orange Tsai  🍊 tweet media
English
20
221
902
64.7K
Mikhail Firstov retweetledi
ϻг_ϻε
ϻг_ϻε@steventseeley·
As it turns out, @orange_8361 and I have more in common than I had thought! If you love old school PHP quirks and CTF tricks I recommend you read our articles: #article" target="_blank" rel="nofollow noopener">phrack.org/issues/72/5_md… #article" target="_blank" rel="nofollow noopener">phrack.org/issues/72/6_md…
English
1
60
258
23.5K
Mikhail Firstov retweetledi
Sergey Bobrov
Sergey Bobrov@Black2Fan·
I have published a tool based on jadx that helps analyze Java applications. github.com/BlackFan/BFScan BFScan generates HTTP requests and OpenAPI specs based on config files and class/method annotations. It also searches strings that look like URIs, paths, or secrets.
English
6
121
443
24.2K
Mikhail Firstov retweetledi
Alisa Esage Шевченко
Alisa Esage Шевченко@alisaesage·
It took 3 years but finally I feel ready to release my Pwn2Own 2021 exploit code. 💖 Video talk covers my full research workflow, from attack surface modeling and reverse engineering, to vulnerability discovery and systematic exploit engineering, enjoy! #Pwn2Own
Zero Day Engineering@zerodayalpha

Release: VM Escape Exploit for Parallels Desktop Hypervisor (Pwn2Own 2021) zerodayengineering.com/research/pwn2o… A virtual machine escape exploit will typically require kernel privileges in the guest OS. In this exploit I chose to offload the reverse-engineered toolgate protocol implementation to a Python module, while keeping my low-level kernel code minimal, just enough to implement the attack interface - a nod to the principle of least privilege in systematic software engineering, which we miss a lot in non-trivial exploit development. -- @alisaesage

English
9
101
678
161.1K
Mikhail Firstov retweetledi
PT SWARM
PT SWARM@ptswarm·
🚨 New article: "WinRAR’s vulnerable trialware: when free software isn’t free" by our researcher @Psych0tr1a. In this article, we show how vulnerabilities in trialware could beсome a gate for hackers. swarm.ptsecurity.com/winrars-vulner…
PT SWARM tweet media
English
1
62
158
0
Mikhail Firstov retweetledi
FBK CyberSecurity
FBK CyberSecurity@fbk_cs·
Ущерб от киберпреступлений в 2021 году достигнет 6 трлн. долларов: Александр Черненко @fbk_cs и Роман Чаплыгин @ptsecurity на «Неделе МСФО и управленческого учета» conf.msfo1.ru рассказали о новом подходе в кибербезопасности, который может изменить прогнозы для бизнеса.
Русский
0
1
1
0
Mikhail Firstov retweetledi
PT SWARM
PT SWARM@ptswarm·
⚡️New DNS Out-of-Band vector for MSSQL Injections in SELECT statement! Can be used for completely blind #sqli. Use fn_trace_gettable and #Burp Collaborator👍. #ptswarmTechniques
PT SWARM tweet media
English
6
361
882
0
Mikhail Firstov retweetledi
Jake Miller
Jake Miller@theBumbleSec·
Excited to share my latest research! h2c smuggling: request smuggling via HTTP/2 cleartext. Leveraging TCP tunnels provided by HTTP/1.1 upgrades, we can initiate h2c connections directly with compatible back-end services, bypassing proxy access controls. labs.bishopfox.com/tech-blog/h2c-…
Jake Miller tweet media
English
12
313
700
0
Mikhail Firstov retweetledi
Sergey Bobrov
Sergey Bobrov@Black2Fan·
Did you know that browsers support multiple Content-Type in HTTP response header? Content-Type: text/plain; x=x, text/html, foobar More tricks in my content-type research github.com/BlackFan/conte…
English
10
240
654
0
Mikhail Firstov retweetledi
FBK CyberSecurity
FBK CyberSecurity@fbk_cs·
Очень давно от нас не было вестей, но мы вернулись с новой статьей в журнале "Хакер"! В этот раз будет описано подробное прохождение машины "Sunset: decoy" c сайта VulnHub. xakep.ru/2020/07/23/sun…
Русский
0
1
3
0
Mikhail Firstov retweetledi
Pavel Zhovner
Pavel Zhovner@zhovner·
Hey @stripe and @kickstarter Can someone please explain why our company verification documents are being rejected without any clear answer? We try all formats (PDF, JPG, PNG) and all possible resolutions. Support from both sides does not response for a several days!
Pavel Zhovner tweet media
English
26
23
208
0