Positive Security

32 posts

Positive Security banner
Positive Security

Positive Security

@positive_sec

Holistic IT security research & consulting

Berlin Katılım Aralık 2020
0 Takip Edilen1.6K Takipçiler
Positive Security
Positive Security@positive_sec·
We looked at the internals of JavaScript/TypeScript's most popular utility libraries and found interesting issues. The post contains hacking challenges/live demos. We recommend checking it out if you work with the affected libraries. positive.security/blog/lodash-ra…
English
1
1
2
237
Positive Security
Positive Security@positive_sec·
The company operating this system has threatened us with lawsuits and (now publicly) denies the risk
English
0
0
0
125
Positive Security
Positive Security@positive_sec·
The system is also used for street lamp control, allowing for a scaled-up “Project #Blinkenlights” art installation that transforms an entire city into a screen (for astronauts)
English
1
1
2
215
Positive Security
Positive Security@positive_sec·
The Auto-GPT team has now also published GitHub security advisories and reserved CVE numbers: - github.com/Significant-Gr… - CVE-2023-37273, CVE-2023-37274, CVE-2023-37275
English
0
0
0
466
Positive Security
Positive Security@positive_sec·
We leverage indirect prompt injection to trick Auto-GPT (GPT-4) into executing arbitrary code and discovered vulnerabilities that allow escaping its sandboxed execution environment. positive.security/blog/auto-gpt-…
English
2
12
23
3K
Positive Security
Positive Security@positive_sec·
@rchase Yes, we ended that experiment after 5 days (as a tracking alert should have been triggered within that time frame) and then published the blog post
English
1
0
1
17
Reilly Chase
Reilly Chase@rchase·
@positive_sec Great research thanks for sharing! I don't think you mentioned why it stopped working after 5 days - did you just end the experiment, did it run out of power, did it run out of public keys etc?
English
1
0
0
11
Positive Security
Positive Security@positive_sec·
The popular Ruby library "Ransack" can be abused to exfiltrate sensitive data via character by character brute-force. We compromised multiple applications this way and found hundreds more that could be vulnerable. positive.security/blog/ransack-d…
English
0
8
18
2.8K
Positive Security
Positive Security@positive_sec·
@aroly Did you try Xubuntu 20.04? That's where we had successfully tested the auto-mount (in default config). Also make sure to have anonymous access enabled for the NFS share/server to be able to use the nfs:// URL as shown in the thumbnail without username/password.
English
0
0
0
196
Positive Security
Positive Security@positive_sec·
The latest @make magazine features an article of ours on "DIY #AirTags". It contains: - Brief explanation of the Find My protocol - Introduction of @seemoolab's OpenHaystack - Summary of our research (Send My & Find You) - Example use cases for such (enhanced) DIY trackers
Positive Security tweet media
English
1
5
27
0
Positive Security
Positive Security@positive_sec·
urlscan.io leaks API keys, shared documents, password reset links, team invites, and other sensitive data. We identified one culprit to be other security tools that accidentally make their scans public and put their users at risk. positive.security/blog/urlscan-d…
English
2
85
280
0