dls

61 posts

dls

dls

@putersarehard

dot dot slash enthusiast

Australia Katılım Haziran 2021
521 Takip Edilen70 Takipçiler
Sabitlenmiş Tweet
dls
dls@putersarehard·
My @securitytrails #reconmaster methodology/thoughts in a thread. I started somewhat late, many people already in the millions of hosts discovered. My first instinct was to automate the submission of Certstream data. 1/n
English
2
6
21
0
dls retweetledi
toasterpwn
toasterpwn@toasterpwn·
Team Oceania is seeking sponsors for the 2025 International Cybersecurity Challenge! Support top 🇦🇺🇳🇿 cyber talent and showcase your brand on the world stage. Learn more: oceaniacc.com or send me a message. #cybersecurity #ICSC2025 #infosec
English
2
14
22
5.7K
dls retweetledi
BSidesCanberra
BSidesCanberra@BSidesCbr·
We’re stoked to announce that @sk8boardingdog – Australia’s top CTF team – are writing and hosting the BSides Canberra 2025 CTF! 🐶🛹💻 They’ve won our CTF 3 years running, and now they’re bringing their skills to make this year’s comp unforgettable. cfp.bsidescbr.com.au/bsides-canberr…
English
0
6
22
3K
dls retweetledi
elttam
elttam@elttam·
New blog post: New Method to Leverage Unsafe Reflection and Deserialisation and gain RCE on Rails elttam.com/blog/rails-sql…
English
0
19
56
4.2K
dls retweetledi
Critical Thinking - Bug Bounty Podcast
The Fetch API supports Blob objects as request bodies, not just strings! Blobs can omit a type, enabling cross-site POST requests without a Content-Type header. Even with non-empty bodies, the Blob's data becomes the request body! (credit: @lukejahnke)
Critical Thinking - Bug Bounty Podcast tweet media
English
3
14
116
6.8K
dls retweetledi
shubs
shubs@infosec_au·
Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
shubs tweet media
English
15
218
789
73.2K
dls retweetledi
DownUnderCTF
DownUnderCTF@DownUnderCTF·
Australia's largest online CTF competition now welcomes New Zealand in July 2024! With 4200+ users and 2000+ teams as of 2023, it aims to up-skill the next generation of Cyber Security Professionals. Prize eligibility now includes Aussie and NZ students! #CTF #DownUnderCTF
English
7
9
28
3.9K
dls retweetledi
Luke Jahnke
Luke Jahnke@lukejahnke·
Blog is live, for now there is a quick puzzle to get to the posts nastystereo.com
English
1
4
11
5.4K
dls retweetledi
PT SWARM
PT SWARM@ptswarm·
🎁 Source Code Disclosure in IIS 10.0! Almost. There is a method to reveal the source code of some .NET apps. Here's how it works. 👉 swarm.ptsecurity.com/source-code-di…
PT SWARM tweet media
English
4
187
471
62.1K
dls retweetledi
elttam
elttam@elttam·
Today we're releasing a public beta of Talkback, a smart infosec resource aggregator to help you keep up with news and research. Please visit talkback.sh and give it a try! We'll be releasing new features and improvements over time.
English
3
27
42
12.1K
dls retweetledi
Lexfo
Lexfo@LexfoSecurite·
A few months ago, we reported a pre-auth Remote Code Execution #RCE vulnerability to @vBulletin. The exploitation of this unserialize() bug was tricky, as vBulletin classes are not deserialisable. Discover the exploitation in our latest blogpost: ambionics.io/blog/vbulletin…
English
2
85
200
49.9K
dls retweetledi
elttam
elttam@elttam·
Happy new year! We're excited to welcome dls / @putersarehard to the team today.
English
0
4
13
1.6K
dls retweetledi
Márcio Almeida
Márcio Almeida@marcioalm·
This is the technical writeup in how we found and exploited the CVE-2022-41343 (RCE via Phar Deserialisation in Dompdf <= v2.0.0). We presented this vulnerability at Ruxmon September and we are finally doing the public disclosure! I hope you like it ;-) tantosec.com/blog/cve-2022-…
English
2
70
184
0
dls retweetledi
Justin Elze
Justin Elze@HackingLZ·
One of the weirdest struggles in OffSec is teaching people to think like criminals and not like pentesters.
English
27
50
434
0