Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pentestercrab
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
91.
▲
Ask HN: Do you create digital art? let's see it
41 points
by
pentestercrab
6y ago
|
51 comments
92.
▲
A Journey Combining Web Hacking and Binary Exploitation in Real World
(blog.orange.tw)
1 points
by
pentestercrab
6y ago
|
0 comments
93.
▲
Sudoedit Heap Overflow
(blog.infosectcbr.com.au)
2 points
by
pentestercrab
6y ago
|
0 comments
94.
▲
Stop Using Libgcrypt 1.9.0
(lists.gnupg.org)
5 points
by
pentestercrab
6y ago
|
1 comments
95.
▲
Rysolv – Fix open source issues, get paid
(rysolv.com)
2 points
by
pentestercrab
6y ago
|
0 comments
96.
▲
The search for the “perfect” Advent Calendar (2018)
(blog.jgc.org)
1 points
by
pentestercrab
6y ago
|
0 comments
97.
▲
Tuya IoT and EZ Mode Pairing
(elttam.com)
1 points
by
pentestercrab
6y ago
|
0 comments
98.
▲
Cross-site leaks (XS-Leaks) Wiki
(xsleaks.dev)
4 points
by
pentestercrab
6y ago
|
0 comments
99.
▲
iOS 1-day hunting: uncovering and exploiting CVE-2020-27950 kernel memory leak
(synacktiv.com)
1 points
by
pentestercrab
6y ago
|
0 comments
100.
▲
Simple bugs with complex exploits – an analysis of a V8 vulnerability from P0
(elttam.com)
3 points
by
pentestercrab
6y ago
|
0 comments
101.
▲
Ghostscript Safer Sandbox Breakout (CVE-2020-15900)
(insomniasec.com)
1 points
by
pentestercrab
6y ago
|
0 comments
102.
▲
Lua SUID Shells – How to make SUID Lua scripts not drop privileges
(elttam.com)
2 points
by
pentestercrab
6y ago
|
0 comments
103.
▲
by
pentestercrab
6y ago
The second sentence of the blog post states: We were also unable to control the contents of a file on disk, and bruteforcing process identifiers (PIDs) and file descriptors found no interesting results, eliminating remote LD_PRELOAD ex
104.
▲
by
pentestercrab
6y ago
https://intelx.io/?did=25626760-7371-4872-be87-68c350f7baac
105.
▲
by
pentestercrab
6y ago
Sounds very interesting, thanks for sharing. Do you have any more information or perhaps a URL to a write-up for this? Or do you remember the challenge name?
106.
▲
by
pentestercrab
6y ago
It does not require opening a browser, it can cause a browser to open.
107.
▲
by
pentestercrab
6y ago
Yes, that works fine. The hard part is finding a suitable .so already on the system. The following (credit to Tavis Ormandy) creates /tmp/testing $ RUBYOPT="-r/usr/lib64/libpcprofile.so" PCPROFILE_OUTP
108.
▲
Hacking with environment variables
(elttam.com)
226 points
by
pentestercrab
6y ago
|
65 comments
109.
▲
Windows Telemetry service elevation of privilege
(secret.club)
2 points
by
pentestercrab
6y ago
|
0 comments
110.
▲
Hacking with Environment Variables
(elttam.com)
1 points
by
pentestercrab
6y ago
|
0 comments
111.
▲
Presentations of Diffie-Helman leave out how to find g
(blog.computationalcomplexity.org)
1 points
by
pentestercrab
6y ago
|
0 comments
112.
▲
Vulnerabilities allowing offering malicious firmware updates to Linux systems
(github.com)
1 points
by
pentestercrab
6y ago
|
0 comments
113.
▲
by
pentestercrab
6y ago
From TFA: These vulnerabilities would have allowed an attacker who claimed the S3 bucket to offer malicious firmware updates to Linux desktops and servers running legacy versions of fwupd. Some extra discussion can be found in a Twitter thr
114.
▲
Fwupd – S3 bucket takeover and CVE-2020-10759 signature verification bypass
(github.com)
2 points
by
pentestercrab
6y ago
|
1 comments
115.
▲
Cmd Hijack – a command/argument confusion with path traversal in cmd.exe
(hackingiscool.pl)
2 points
by
pentestercrab
6y ago
|
0 comments
116.
▲
by
pentestercrab
6y ago
Some extra details can be found in the relevant Twitter thread[0] relating to affected Linux distributions. [0] https://twitter.com/justinsteven/status/1270113960021209088
117.
▲
Fwupd – S3 bucket takeover and CVE-2020-10759 signature verification bypass
(github.com)
3 points
by
pentestercrab
6y ago
|
1 comments
118.
▲
Hobo Nickel
(en.wikipedia.org)
3 points
by
pentestercrab
6y ago
|
0 comments
119.
▲
by
pentestercrab
6y ago
http://geometrylearning.com/DeepFaceDrawing/ says "[Coming Soon]" for the code.
120.
▲
Surprising Certificate Authority validation gotcha
(twitter.com)
2 points
by
pentestercrab
6y ago
|
1 comments
More ›