xchym

68 posts

xchym banner
xchym

xchym

@xchym

g4mm4 is my h3r0

Katılım Mayıs 2010
483 Takip Edilen780 Takipçiler
xchym retweetledi
TrendAI Zero Day Initiative
Confirmed! Verichains Cyber Force chained two unique bugs - including an auth bypass - to exploit the Synology DS925+ and run code as root. Their work earns them $20,000 and 4 Master of Pwn points. #Pwn2Own
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
1
9
63
10.4K
xchym retweetledi
TrendAI Zero Day Initiative
📦 Storage unlocked! Le Trong Phuc & Cao Ngoc Quy of Verichains Cyber Force just cracked the @Synology DS925+ at #Pwn2Own. A brief DNS issues delayed them, but they couldn't be stopped. They're off to the disclosure room to explain what they did. #P2OIreland
English
0
4
12
3.6K
xchym retweetledi
Verichains
Verichains@Verichains·
Verichains is glad to have helped unveil the root cause behind the largest Web3 hack—$1.4 billion on @Bybit_Official’s Multisig @Safe Wallet! This hack is a strong wake-up call as Web3 security isn’t just about on-chain transactions or smart contracts — it also relies on traditional Web2 components like private keys, frontends, backends, oracle data, etc — which are prone to exploitation & manipulation.
Ben Zhou@benbybit

Bybit Hack Forensics Report As promised, here are the preliminary reports of the hack conducted by @sygnia_labs and @Verichains Screenshotted the conclusion and here is the link to the full report: docsend.com/view/s/rmdi832…

English
6
9
49
11.3K
xchym retweetledi
Verichains
Verichains@Verichains·
Verichains has released a new security advisory VSA-2022-120, exposing a key extraction vulnerability in Multichain's fastMPC. Kudos to @MultichainOrg for the swift response and bug bounty. Keep an eye out for upcoming advisories on critical attacks targeting popular MPC implementations. blog.verichains.io/p/vsa-2022-120…
English
0
15
26
8.6K
xchym retweetledi
VNG Security Response Center
VNG Security Response Center@vngsecresponse·
We're really happy to share our improvements and some experiments for the CookieMonster tool. Weaponizing Monster for Cookies Attacks: vsrc.vng.com.vn/blog/weaponizi… Also include burp-extender plugin for burp suite. Hope you guys enjoy it. ~Cheers, VSRC
VNG Security Response Center tweet media
English
0
13
29
0
xchym
xchym@xchym·
@snyff use-after-free =]]
English
0
0
1
0
Louis Nyffenegger
Louis Nyffenegger@snyff·
You’re on a first date with someone, and they tell you the name of their favorite security bug. You immediately leave. What’s the security bug?
English
41
6
62
0
xchym
xchym@xchym·
#OWASP subdomain Web Cache Poisoning Attacks lead to stored XSS :) youtu.be/pkCOsO9o-L4 This site is now closed ?!?
YouTube video
YouTube
English
1
3
10
0
xchym
xchym@xchym·
@disclosedh1 @Black2Fan I guess this issue is "web cache poisoning attacks", not a "cache deception attacks" :)
English
0
0
1
0
xchym
xchym@xchym·
Suddenly, I remembered my old shool hacking trick… maybe it is related to Server-Side RPO ;) #IIS5.x #Over15yearsBug #SSRPO
xchym tweet mediaxchym tweet mediaxchym tweet mediaxchym tweet media
English
2
3
13
0
xchym
xchym@xchym·
@mazen160 If you report to DoD, I guess all of them will be marked “dupllicated” =]]
English
1
0
0
0