Miroslav Stampar
3.6K posts

Miroslav Stampar
@stamparm
PhD, author of @sqlmap & @maltrail, CTF w/ @SuperGuesser, chess lover, problem solver
Zagreb, Croatia Katılım Nisan 2011
349 Takip Edilen8.3K Takipçiler
Miroslav Stampar retweetledi

We are elated to share that Author & maintainer of @sqlmap, Miroslav Stampar (@stamparm) will be providing a training on "SQLmap for the masses & Unveiling the art of database exploitation" in Bug Bounty village @seasides_conf 2023
Register here : forms.gle/3uNzXUar7KwKPH…
#SQLmap

English
Miroslav Stampar retweetledi
Miroslav Stampar retweetledi

Miroslav Stampar retweetledi

@osiryszzz @DangerEnd3 oh man, i couldn't. i played nice, but the code was not looking good
English

@DangerEnd3 if you read down to the end of the article you can see they added the tamper scripts to sqlmap repo, however @stamparm reverted the commit as apparently he was disgusted by how they were coded lol.
English

How I missed this beautiful piece of research I have no idea, I’m sure I might not be the only one.
TL;DR they had a “universal” WAF bypass for SQLi. claroty.com/team82/researc…
English

@ricardo_iramar @albinowax @simps0n did a quick look into the code. author indeed did a "derivative" work, but tbh, he rewrote the majority. there are no innovative ideas inside. instead, somebody spent tons of hours rewriting the sqlmap's internals. just a dummy comparison of code (1st pic sqlmap, 2nd pic ghauri)


English
Miroslav Stampar retweetledi

This #privacy audit looks like the first LeaveHomeSafe #pentest ever, way below commercial apps:
Broken SSL validation, SD Card Leaks, 2FA Logic bypass, Screenshot leaks, several Face Recognition artifacts, etc. 7asecurity.com/blog/2022/07/l…
Open Technology Fund@OpenTechFund
Serious vulnerabilities have been found in the Hong Kong government's LeaveHomeSafe COVID-19 app. @7aSecurity recently conducted a security audit that discovered numerous flaws that allow interception of the LeaveHomeSafe app and its backend servers. opentech.fund/news/7asecurit…
English

I rarely tweet, but FFS @ThePSF. Something badly happened in their course with 3.x. We are talking about a programming language, not some mobile OS or browser. Constant fear mongering with DeprecationWarnings, EOL, TypeErrors (due to ignored DeprecationWarnings), dependency hell

English
Miroslav Stampar retweetledi
Miroslav Stampar retweetledi
Miroslav Stampar retweetledi
Miroslav Stampar retweetledi

@anantshri Thank you. Title is really really long: "Expert system for recognition of malicious behaviour based on domain name resolution traffic analysis in real-time"
English




















