Moritz Sanft
1.1K posts

Moritz Sanft
@stdoutput
security software engineer, ctf @fluxfingers @[email protected]




Around 400 AUR packages compromised taken over and include NPM post install hooks. @lists.archlinux.org/thread/FGXPCB3ZVCJIV7FX323SBAX2JHYB7ZS4/" target="_blank" rel="nofollow noopener">lists.archlinux.org/archives/list/…

Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique: sonarsource.com/blog/jellyfin-… #appsec #security #vulnerability


SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud by @pspaul95 and @stdoutput







The secret's out.🤫 Introducing THE ZERODAY.CLOUD COMMUNITY 👾 Inside: • 0-day vuln deep dives from @xint_official, @stdoutput, @pspaul95 & more... • Access to events & a network of world-class hackers • CTFs with prizes Join now :)









