Sign in

0xacb

@0xacb.com
1.5K followers 101 following 412 posts

Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Co-founder @ethiack.com 0xacb.com

PostsRepliesMedia
0xacb @0xacb.com · 12h
Great research by @orange_8361 / Devcore
worst.fit
WorstFit!
000
0xacb @0xacb.com · 12h
Turns out those Unicode dashes are actually useful. Filter blocks "-"? Send full-width "-" instead. Windows converts it back to "-" inside curl.exe, injecting a -o argument that drops a webshell.
101
0xacb @0xacb.com · 29/09/2026
@garethheyes.co.uk eyes showed multiple ways this happens, super cool. Full blog 👇
portswigger.net
What's in a tag name? JavaScript, apparently
I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t
000
0xacb @0xacb.com · 29/09/2026
Have you looked at localName when testing an HTML filter? A tag name that looks useless as markup can come back from the browser as a transformed string. If an event handler reads that value, a payload the filter never saw as JavaScript may become code later.
100
0xacb @0xacb.com · 28/09/2026
Full writeup 👇
ethiack.com
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
000
0xacb @0xacb.com · 28/09/2026
HDF5 datasets can reference bytes in another file. When Rails generates a variant, bytes from a local path can come back as image pixels. This chain needs Active Storage with Vips, an untrusted upload path, and a libvips build with MAT support.
100
0xacb @0xacb.com · 28/09/2026
libvips then inspects the file itself. Our crafted file starts with `MATLAB 5.0`, which selects the MAT loader, but a separate version field tells libmatio to read it as MAT 7.3: an HDF5 file.
100
0xacb @0xacb.com · 28/09/2026
In our KindaRails2Shell research, a file labelled image/png can make Rails read /etc/passwd. The trick lies beneath the upload layer. On the direct-upload path, Active Storage can keep the client’s `image/png` label without checking the bytes.
100
0xacb @0xacb.com · 15/09/2026
Also worth checking the program policy first. Spraying IP ranges with a spoofed Host header hits hosts that aren't your target, and some programs may put origin IPs out of scope. Great tool by @hakluke 👇
github.com
GitHub - hakluke/hakoriginfinder: Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs! - hakluke/hakoriginfinder
000
0xacb @0xacb.com · 15/09/2026
One thing to keep in mind: a MATCH is a similarity score and not proof. Send something the gateway would block and see if the origin serves it. If it doesn't, the origin is filtering by gateway IP, using mTLS, or checking a header the gateway adds.
100
0xacb @0xacb.com · 15/09/2026
To check IP address spaces, you can use hakoriginfinder. It fetches the gateway first, then requests each IP with the Host header set, and scores the responses with Levenshtein distance. prips x.x.x.x/24 | hakoriginfinder -h
api.targetx.com
100
0xacb @0xacb.com · 15/09/2026
If that doesn't work, there's active recon. There are two ways to do this: via subdomains or via IP addresses with vhosts. To check subdomains, just do your usual subdomain enumeration and then check each subdomain to see if any of them respond the same as the gateway.
110
0xacb @0xacb.com · 15/09/2026
Then check records that may outlive the change: - DNS history (SecurityTrails, ViewDNS). If the gateway was put in front of an existing app, the old A record still points at the origin - Certificate Transparency (crt.sh) for hostnames they issued certs for but never linked - Shodan/Censys
210
0xacb @0xacb.com · 15/09/2026
First, try searching for it throughout the app. Some common places it pops up: - Error messages - JS source - CORS headers - Cloud storage
100
0xacb @0xacb.com · 15/09/2026
So how do we find the origin server? Let's say that the gateway is at api.targetx[.]com
100
0xacb @0xacb.com · 15/09/2026
Some security controls, such as auth checks, rate limiting, WAF rules, and IP allowlisting are often implemented with a gateway. If you're able to discover the origin host and it accepts requests directly, you can bypass all of that by sending your requests straight to the origin.
220
0xacb @0xacb.com · 14/09/2026
Tested on sequelize 6.37, mongoose 9.9, typeorm 1.1, knex 3.3, prisma 7.10, express 5.2
000
0xacb @0xacb.com · 14/09/2026
On the read path, findOne returns your own row whatever the order. The issue is on findAll/find, which returns both. Mongo operators like {"$in":[124]} can hit only the victim, but fail every middleware check I tested. Only reachable where the field isn't inspected.
100
0xacb @0xacb.com · 14/09/2026
You always write to your own row too. [124] alone would hit only the victim, but the middleware rejects it because your ID isn't there. To get past the check you have to include yourself, and the ORM writes to everything in the list.
100
0xacb @0xacb.com · 14/09/2026
You don't need a JSON body either. Duplicate params gave me an array in every Express config I tried: user_id=124&user_id=123 -> ["124","123"] They arrive as strings, so includes(123) fails, but some(x => x == 123) still passes and Sequelize still fires: IN ('124','123')
100
0xacb @0xacb.com · 14/09/2026
Then it's up to the ORM: Sequelize -> IN (124,123), both rows written Mongoose -> implicit $in, both rows written TypeORM -> throws RangeError Knex -> throws on bind Prisma -> throws, Expected Int, provided (Int, Int)
100
0xacb @0xacb.com · 14/09/2026
One that surprised me, though it's already known: parseInt([123,124]) === 123 is true. The array becomes the string "123,124" and parseInt stops at the comma. So put your own ID first to get past a parseInt check.
100
0xacb @0xacb.com · 14/09/2026
This only works if the middleware checks whether your ID is in the array. These pass: [].concat(id).includes(123) [].concat(id).some(x => x == 123) Strict == and === both reject [124,123]. So does Number().
100
0xacb @0xacb.com · 14/09/2026
Been testing the IDOR trick where you wrap the identifier in an array, in Node JS. You are 123, victim is 124. {"user_id": [124, 123]} The ORM doesn't pick the first element. Sequelize and Mongoose turn it into WHERE id IN (124, 123) and can write both rows.
100
0xacb @0xacb.com · 11/09/2026
Watch the full talk:
youtube.com
Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents | Johann Rehberger | HackAICon 2025
Read the complete article:https://ethiack.com/news/blog/agentic-pr...
000
0xacb @0xacb.com · 11/09/2026
How to trick an AI into downloading and running malware, by @wunderwuzzi23:
120
0xacb @0xacb.com · 09/09/2026
Also: MySQL's default is utf8mb4_0900_ai_ci. The ai means accent insensitive, so 'admin' = 'ádmin' is true there. SQL Server defaults to _AS and returns false. Tested on SQL Server 2022 + 2025, MySQL 8.4/9.7/26.7, Postgres 18.6, default configs.
000
0xacb @0xacb.com · 09/09/2026
MySQL is case insensitive by default too, but its 8.0+ default doesn't pad: 'admin' = 'admin␣' is false. Older ones like utf8mb4_general_ci still do. Postgres does neither. App assumes one thing, DB does another. This can lead to some weird bugs and bypasses.
100
0xacb @0xacb.com · 09/09/2026
Other things I tested: Only the space char. Tab, newline and CR still count Leading spaces still count = and LIKE disagree: 'admin' = 'admin␣' is true, 'admin' LIKE 'admin␣' is false A UNIQUE index under CI rejects ADMIN as a duplicate of admin, so it's a lookup bug not a signup one
100
0xacb @0xacb.com · 09/09/2026
Now if someone fixes it like: username.ToLower() == "admin" stops ADMIN, but lets 'admin␣' through. Moving the column to a CS collation also stops ADMIN, and also lets 'admin␣' through. Two different fixes, same half of the bug left open.
100
0xacb @0xacb.com · 09/09/2026
So if an app blocks a username in app code: if (username == "admin") deny; <- checks case and spaces WHERE username = @username <- checks neither Send ADMIN, or 'admin␣'. The check doesn't fire and the DB still finds the admin row.
100
0xacb @0xacb.com · 09/09/2026
I tried CS, BIN, BIN2 and a UTF8 collation. They all pad the space away. Looks like only a VARBINARY cast sees the difference.
101
0xacb @0xacb.com · 09/09/2026
I was playing with SQL Server and noticed the default collation is case insensitive (SQL_Latin1_General_CP1_CI_AS). admin and ADMIN are the same string to the DB. That part is well known. Less talked about: = also ignores trailing spaces. 'admin' = 'admin␣' is true (␣ is an actual space char)
100
0xacb @0xacb.com · 07/09/2026
Watch the full talk:
youtube.com
Agentic ProbLLMs: Exploiting AI Computer-Use and Coding Agents | Johann Rehberger | HackAICon 2025
Read the complete article:https://ethiack.com/news/blog/agentic-pr...
000
0xacb @0xacb.com · 07/09/2026
This is how user data can be exposed via prompt injection, explained by @wunderwuzzi23:
110
0xacb @0xacb.com · 04/09/2026
Check out the full video on Ethiack’s channel:
youtube.com
Breaking the Chain: Advanced Offensive Strategies in Software Supply Chain | @Lupin @ HackAiCon
You're not just protecting your code. You're responsible for everyt...
000
0xacb @0xacb.com · 04/09/2026
Did you know you can actually steal a dev's GitHub account using their expired domain? Here's how @0xLupin did it. It's pretty cool:
120
0xacb @0xacb.com · 02/09/2026
Bug was in Azure Container Runtime, so AKS and Container Apps were also affected. Any SSRF that can reach the node's localhost = root on the node. 5 issues, 4 Microsoft products, $48k bounty. Cool research by Ori Lahav 👇
zerolabs.rubrik.com
Breaking the M365 Copilot Sandbox with ChatMate
ChatMate, the first documented instance of remote prompt execution, shows how a malicious document can lead to sandbox escape.
000
0xacb @0xacb.com · 02/09/2026
5. The node has internet but the sandbox doesn't. And that channel goes both ways: the attacker sends prompts down and Copilot answers, with the victim's identity and full M365 access.
100
0xacb @0xacb.com · 02/09/2026
How it works: 1. A Word doc with a hidden prompt injection gets uploaded to Copilot 2. Launder intent (using a gzip payload) to bypass safety filters 3. Escalate to root inside the sandbox 4. Execute a full container-to-host escape (CVE-2026-32193)
100
0xacb @0xacb.com · 02/09/2026
What happens when an attacker gets a live, interactive shell inside Microsoft 365 Copilot? @vbcrlf.bsky.social from Rubrik Zero Labs dropped ChatMate, the first publicly documented Remote Prompt Execution (RPE): an attacker manipulating a victim's assistant, prompt by prompt.
100
0xacb @0xacb.com · 01/09/2026
For more details about Hackian: 👇
ethiack.com
Introducing the Hackian - an AI agent that can hack | Ethiack — Autonomous Ethical Hacking for continuous security
Discover Hackian, an AI agent transforming cybersecurity by autonomously identifying vulnerabilities and enhancing ethical hacking practices for a safer internet.
100
0xacb @0xacb.com · 01/09/2026
How do we prevent Hackian (our hackbot) from performing destructive actions? Here’s how we do it: 👇
100
0xacb @0xacb.com · 31/08/2026
Check out the full video on Ethiack’s channel:
youtube.com
Hacking Gemini & the MCP Permission Problem | Ciarán Cotter (monke) @ HackAICon 2025
What happens when you give a fully-fledged LLM access to your opera...
000
0xacb @0xacb.com · 31/08/2026
IDOR to image-based data exfiltration on an AI chat agent. Here’s a clip from @monkehack’s talk, explaining how they did it.
120
0xacb @0xacb.com · 24/08/2026
Check out the full video on Ethiack’s channel:
youtube.com
Breaking the Chain: Advanced Offensive Strategies in Software Supply Chain | @Lupin @ HackAiCon
You're not just protecting your code. You're responsible for everyt...
010
0xacb @0xacb.com · 24/08/2026
This is how @0xLupin bypassed the supply chain security of major companies like Google, Salesforce, Netflix, and many others. Here’s the clip:
120
0xacb @0xacb.com · 14/08/2026
Check out the full video on Ethiack’s channel:
youtube.com
Breaking the Chain: Advanced Offensive Strategies in Software Supply Chain | @Lupin @ HackAiCon
You're not just protecting your code. You're responsible for everyt...
000
0xacb @0xacb.com · 14/08/2026
Using SHA collision to trick an AI for a $10k bounty. Really interesting technique by my buddy @0xLupin:
110
0xacb @0xacb.com · 13/08/2026
Full talk on Ethiack's channel 👇
youtube.com
Hacking Gemini & the MCP Permission Problem | Ciarán Cotter (monke) @ HackAICon 2025
What happens when you give a fully-fledged LLM access to your opera...
000