Moritz Sanft

1.1K posts

Moritz Sanft banner
Moritz Sanft

Moritz Sanft

@stdoutput

security software engineer, ctf @fluxfingers @[email protected]

Germany Katılım Mart 2019
785 Takip Edilen1.3K Takipçiler
Thorsten Ball
Thorsten Ball@thorstenball·
@stdoutput moritz, don't worry, that's just the cleanshotx highlighting not matching our (better) border radius
English
1
0
1
103
Thorsten Ball
Thorsten Ball@thorstenball·
There are so many things like this where you know it will nail it. Why do it locally?
Thorsten Ball tweet media
English
8
0
37
7.3K
Arian van Putten
Arian van Putten@ProgrammerDude·
@HSVSphere I can guarantee you threat actors are very eager to backdoor nixpkgs and the fact that FOD hashes can cross-contaminate derivations it's easy to sneak in backdoors that look begnin
English
1
0
2
235
es3n1n
es3n1n@es3n1n·
tired
English
5
0
23
1.4K
Moritz Sanft retweetledi
pspaul
pspaul@pspaul95·
A fun gadget I found recently! The .NET JIT compiler makes sure there are no rwx pages by using a memfd, but that turns file writes into straight shellcode execution 🐚
Sonar Research@Sonar_Research

Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique: sonarsource.com/blog/jellyfin-… #appsec #security #vulnerability

English
0
11
81
10.6K
es3n1n
es3n1n@es3n1n·
i need to find a new obsession now that ctfs are deadge
English
22
7
181
11K
Moritz Sanft
Moritz Sanft@stdoutput·
@carste1n That one indeed is a gem. You’ve got good taste;)
English
0
0
1
100
Michal Melewski
Michal Melewski@carste1n·
Speaking about OffensiveCon - many good talks but one I really wanted to sink my teeth into (because I'm not looking for vulns in phones) was this one: offensivecon.org/speakers/2026/… by @stdoutput and Paul Gerste. Guys - any chance for the slides?
English
1
0
30
4.4K
Moritz Sanft
Moritz Sanft@stdoutput·
@ifsecure Any chance you could share the slides? Thanks for the great talk!
English
1
0
1
164
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
In my OffensiveCon talk on Site Isolation yesterday, a question was asked that I didn't quite get at the moment so my answer was probably irrelevant. My apologies, especially since the question, as I understand it now, totally makes sense. Answering it here:
English
3
3
60
15.3K
Moritz Sanft retweetledi
Nir Ohfeld
Nir Ohfeld@nirohfeld·
We @wiz_io just launched zeroday.cloud - a community for vuln researchers, by vuln researchers. Feat. writeups for PostgreSQL and MariaDB RCEs (@xint_official, @pspaul95 & @stdoutput) Stay tuned for the bug tracker and upcoming events. Big things coming soon 👀
English
1
18
103
7.9K
Moritz Sanft
Moritz Sanft@stdoutput·
Trying to get some new folks onto the AI for security research Discord server: discord.gg/sVy9ahuEv Feel free to share with your peers in the field!🤖🐛
English
0
0
1
258
Moritz Sanft
Moritz Sanft@stdoutput·
I‘m at @1ns0mn1h4ck today and tomorrow. Feel free to drop me a DM if anyone wants to meet :)
Moritz Sanft tweet media
English
0
0
1
173
Thorsten Ball
Thorsten Ball@thorstenball·
It's always like: how much do you squat? Never: how much do you curl? "wow you have strong legs" buddy, my bis are up here
English
5
0
60
7.7K