rekter0

57 posts

rekter0

rekter0

@rekter0

doing things @sundialxyz, CTF @water_paddler / BlueWater

เข้าร่วม Aralık 2019
580 กำลังติดตาม866 ผู้ติดตาม
rekter0 รีทวีตแล้ว
blasty
blasty@bl4sty·
can we please get the libxml2 and ffmpeg people some cold cash, lambo's and decent quality blow as a token of appreciation for all the ASAN splats we throw over the fence and want to have fixed pronto? I know one man's trash (CVE's) is another man's treasure, but we gotta respect and support these hardworking devs a bit more. how else do you expect to play back (x-rated) flicks that come in esoteric video container formats or correctly render SVG's containing vector depictions of your favorite animals in safari?
English
1
11
88
8.5K
rekter0
rekter0@rekter0·
@S1r1u5_ You guys should start using the same prettier conf
English
0
0
1
188
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
what does this man even cooking?
s1r1us (mohan) tweet media
English
3
0
27
7.1K
rekter0 รีทวีตแล้ว
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: portswigger.net/research/inlin…
Gareth Heyes \u2028 tweet media
English
13
86
362
26.3K
rekter0 รีทวีตแล้ว
Water Paddler
Water Paddler@Water_Paddler·
🥈 Thrilled to nab 2nd as Blue Water, teamed up with @perfect_blue at DEFCON CTF Final 33! 🙌 Congrats to @mmm_ctf_team for their 4th straight 1st 💪 We’re gunning for the crown next year! Join our crew to make it happen! DM us or drop us an email! 🚀 #DEFCON #CTF
English
2
9
42
9K
rekter0
rekter0@rekter0·
@blueminimal @sqrtrev Use sqlite atach database into css directory Or use sqli to update user_tables obj column to trigger elixir binary to term deserialise rce
English
0
0
1
78
Marco Squarcina
Marco Squarcina@blueminimal·
@sqrtrev Oh nice! Can you upload the exploit somewhere? I am curious to see how you got direct leakage without doing it via the blind sqli :)
English
1
0
0
111
sqrtrev
sqrtrev@sqrtrev·
Making a payload for AXIS challenge was so painful because of the web socket stuff
English
2
0
13
1.8K
rekter0 รีทวีตแล้ว
Tavis Ormandy
Tavis Ormandy@taviso·
I just learned that OSC8 (hyperlinks) in Windows Terminal uses ShellExecute(). Excellent trolling potential for README files 😆
Tavis Ormandy tweet media
English
14
87
476
55.6K
rekter0 รีทวีตแล้ว
Massimo
Massimo@Rainmaker1973·
Now you know why
English
47
409
4K
603.3K
rekter0 รีทวีตแล้ว
Sonar Research
Sonar Research@Sonar_Research·
🧵 [1/4] Here is our DOMPurify 3.2.1 bypass, using a namespace confusion technique where each element is initially in a “correct” namespace. When it was allowed, the ‘is’ attribute was not handled correctly, making the attribute content’s regex check obsolete. #mXSS #XSS
Sonar Research tweet media
English
2
40
146
17.1K
rekter0 รีทวีตแล้ว
Sundial
Sundial@sundialxyz·
Jesse Pollak showing the ease of onboarding with Onflow.
English
16
28
138
69.3K
rekter0 รีทวีตแล้ว
Sundial
Sundial@sundialxyz·
Trade onchain with counterparties, not addresses, privately. Finally, a small demo of the Onflow protocol, fully computed proof in zero-knowledge with no internet required. Going live on Base soon, and many other ecosystems. 1-click ZK-KYC, everywhere, imminent✨
English
8
10
71
13.8K
rekter0 รีทวีตแล้ว
Remedy
Remedy@xyz_remedy·
📝Another fantastic write-up about the Remedy Closed Beta Challenge. Dive into details r0.haxors.org/posts?id=43 Big kudos to @rekter0 for this comprehensive breakdown🙏 Curious about and want to give it a shot? Join us on Discord to explore and take part discord.gg/q5kZAH7kN5
English
1
4
19
1.3K
rekter0
rekter0@rekter0·
A twitter content spoofing issue being exploited by same recent Ledger hackers? you can put any username and as long as the tweet id is valid it will be redirected to the correct account. the scam pages drain using same ledger hack contract bytecode 🤔
rekter0 tweet media
English
0
1
6
2K
rekter0 รีทวีตแล้ว
Water Paddler
Water Paddler@Water_Paddler·
Thx for hosting such a great CTF. Great team work with @pb_ctf. Congraz to *0xA and MMM. See you guys in Final!
HITCON@HacksInTaiwan

#HITCONCTF2023 After 48 hours of fighting, the HITCON CTF 2023 Qualification has finally ended. Top 3 teams 🥇Blue Water 🥈*0xA 🥉MMM Top 1 Taiwanese team 🎖Flag Connoisseur We’re now reviewing the final results, the full finalists will be officially announced afterwards.

English
0
6
20
5.3K
rekter0 รีทวีตแล้ว
perfect blue
perfect blue@pb_ctf·
Blue Water places 2nd place in DEF CON CTF Finals! Blue Water is a merger of @pb_ctf + @Water_Paddler + Samsung Research + Tea Deliverers. Thank you to @Nautilus_CTF for the great CTF, and shoutout to all the other finalists! See you next year? 😉
perfect blue tweet media
English
4
16
83
13.5K
butt3rflyh4ck
butt3rflyh4ck@butt3rflyh4ck·
@rekter0 Hi guy, I want to reproduce this vuln and study but why I can not find processImage.php in impressCMS-1.4.1 or 1.4.2-rc2. tks.
English
1
0
0
0