Sign in

adrian-rt.bsky.social

@adrian-rt.bsky.social
4 followers 74 following 2 posts
PostsRepliesMedia
adrian-rt.bsky.social @adrian-rt.bsky.social · 10/04/2025
Spoke at BlueHat IL and had an amazing time! I was able to deliver my talk, and I think it went really well, super excited to speak in front of such an incredible audience! Great seeing Alexander Georgiev again! Some pictures from the event below📸
100
Reposted by @adrian-rt.bsky.social
Mastering Burp Suite @mastering-burp.agarri.fr · 24/03/2025
A meme picture displaying the members of a gang. The caption says :
Fuck Turbo Intruder
All my homies use
Send group (parallel)
0103
Reposted by @adrian-rt.bsky.social
buherator @buherator.bsky.social · 26/03/2025
[RSS] Blasting Past Webp googleprojectzero.blogspot.com -> An analysis of the NSO BLASTPASS iMessage exploit Original->
011
Reposted by @adrian-rt.bsky.social
dmnk @dmnk.bsky.social · 10/03/2025
This is so cool: The LibAFL_QEMU ASan implementation was ported to rust github.com/AFLplusplus/... #LibAFL #QEMU #ASan #Rust
github.com
Librasan by WorksButNotTested · Pull Request #3023 · AFLplusplus/LibAFL
Implementation of ASAN target side components in rust. The implementation sits alongside the existing libqasan (although that could be withdrawn in future if we are happy with it). It is selected ...
0114
Reposted by @adrian-rt.bsky.social
buherator @buherator.bsky.social · 08/03/2025
Created a #CodeQL Cheat Sheet to document what I struggled with recently: scrapco.de -> Will push updates as they pop to my mind. Contributions/ideas are also most welcome! github.com -> Original->
031
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 07/03/2025
This article on Solr and its (in)security is really good 💎 And I strongly recommend to read @hacefresko.com previous article on Solr before diving in this one (I will share the link in my reply)
2144
Reposted by @adrian-rt.bsky.social
サイバーかいだ @cyberkaida.bsky.social · 08/03/2025
Quick fix for Ghidra's rust detection, if you are analyzing rust and your strings are not extracted correctly please try my patch! github.com/NationalSecu... #Ghidra #RustLang #Malware #ReverseEngineering
github.com
Detect more rust binaries by cyberkaida · Pull Request #7885 · NationalSecurityAgency/ghidra
Some rust binaries do not contain the rustc or RUST_BACKTRACE strings. Also detect RUST_MIN_STACK which is in these binaries. For example: baa676b671e771bf04b245e648f49516b338e1f49cbd9b4d237cc36d57...
052
Reposted by @adrian-rt.bsky.social
Gareth Heyes @garethheyes.co.uk · 20/02/2025
We've just released Shadow Repeater, for AI-enhanced manual testing. Simply use Burp Repeater as you normally would, and behind the scenes Shadow Repeater will learn from your attacks, try payload permutations, and report any discoveries via Organizer. portswigger.net/research/sha...
22112
Reposted by @adrian-rt.bsky.social
buherator @buherator.bsky.social · 07/03/2025
[RSS] Ungarble: Deobfuscating Golang with Binary Ninja invokere.com -> Original->
011
Reposted by @adrian-rt.bsky.social
TomNomNom @tomnomnom.com · 07/03/2025
Bluesky is the vaping of social media. It got me off the really bad stuff, and definitely tastes better, but it's probably still not great for my health.
1907
Reposted by @adrian-rt.bsky.social
Micah Lee @micahflee.com · 06/03/2025
It's live! Starting today, you can use @cyd.social to migrate your old tweets into Bluesky. Check it out! cyd.social/migrate-your...
cyd.social
Migrate your tweets to Bluesky with the latest version of Cyd
Starting today, Cyd can migrate your old tweets directly into Bluesky! This way you can delete everything from your X account but still have a place to reference your old posts. Here's how it works: ...
45423
Reposted by @adrian-rt.bsky.social
Brett Hawkins @h4wkst3r.bsky.social · 12/01/2025
You can find our @shmoocon.bsky.social presentation slides at the below GitHub repo. Thanks again to all that attended. Also, thank you to the conference organizers for putting on a great con and having us! #shmoocon github.com/h4wkst3r/Con...
github.com
11612
Reposted by @adrian-rt.bsky.social
Stephen Fewer @stephenfewer.bsky.social · 07/03/2025
A VM escape exploit chain, exploited in the wild as 0day ...well that's not something we see very often 👀
0114
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 07/03/2025
Here’s the first article: www.hacefresko.com/posts/unrest...
hacefresko.com
Accessing +700,000 users data and reading files on a Solr server
051
Reposted by @adrian-rt.bsky.social
Victor Fresk0 @hacefresko.com · 26/02/2025
Good news! I've uploaded a new post about the most complex and beautiful vulnerability I've ever found, involving patching and uploading deprecated .jar libraries to get RCE on a big target. It's a very technical post, but I hope you like it ! :) www.hacefresko.com/posts/rce-on...
hacefresko.com
A very fancy way to obtain RCE on a Solr server
12911
Reposted by @adrian-rt.bsky.social
FORTBRIDGE @fortbridge.bsky.social · 07/03/2025
We’re proud to announce that @adrian-rt.bsky.social will speak at BlueHat IL 2025 by @microsoft.com on April 8 in Tel Aviv! Our participation reinforces our position as a leader in pentesting and reflects our mission to enhance cybersecurity through cutting-edge research and real-world insights.
021
Reposted by @adrian-rt.bsky.social
d4d @zakfedotkin.bsky.social · 06/02/2025
We've updated our URL validation bypass cheat sheet with this shiny Domain allow list bypass payload contributed by dyak0xdb!
1289
Reposted by @adrian-rt.bsky.social
buherator @buherator.bsky.social · 18/02/2025
Qualys Security Advisory CVE-2025-26465: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client CVE-2025-26466: DoS attack against OpenSSH's client and server www.openwall.com -> Original->
021
Reposted by @adrian-rt.bsky.social
James Kettle @jameskettle.com · 18/02/2025
Catch the inside story on the Top Ten Web Hacking Techniques in my interview with the Application Security Weekly podcast youtu.be/8XEK3NkbKOA
youtu.be
Top 10 Web Hacking Techniques of 2024 - James Kettle - ASW #318
YouTube video by Security Weekly - A CRA Resource
1124
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 18/02/2025
My bad, I forgot to post a link to last week's edition of AppSec Ezine 🤦 pathonproject.com/zb/?e8f4f080...
pathonproject.com
AppSec Ezine
1103
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 10/01/2025
OMG, Orange Tsai released his latest new research 🤯 💣 blog.orange.tw/posts/2025-0...
blog.orange.tw
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
33420
Reposted by @adrian-rt.bsky.social
PentesterLab @pentesterlab.com · 11/01/2025
Networking in InfoSec isn’t just about IP addresses and ports—it’s also about people! Discover how meetups, conferences, and volunteering can open big career doors in InfoSec. Read more: pentesterlab.com/blog/infosec...
pentesterlab.com
Networking but not TCP/IP - PentesterLab's Blog
Discover how building real-world connections in the InfoSec community can accelerate your journey into pentesting and cybersecurity. From local meetups and conferences to online communities, this guid...
0113
Reposted by @adrian-rt.bsky.social
Łukasz @maldr0id.bsky.social · 03/01/2025
If you haven't seen the Honey tech drama you absolutely have to, it's awesome! youtu.be/vc4yL3YTwWk
youtu.be
Exposing the Honey Influencer Scam
YouTube video by MegaLag
2204
Reposted by @adrian-rt.bsky.social
Ange @angealbertini.bsky.social · 02/01/2025
No polyglots or tricks, just the basics for now. This will be recorded and available publicly later. m.youtube.com/@corkami-alb...
m.youtube.com
Ange Albertini
Reverse engineering & visual documentations/presentations Free, technical, useful
053
Reposted by @adrian-rt.bsky.social
Scott Piper @scottpiper.bsky.social · 24/12/2024
AWS published CVEs on Christmas Eve. 🎅 Their Redshift library is vulnerable to SQL injection, but only one minor version that was released a month ago. aws.amazon.com/security/sec...
aws.amazon.com
Issue with RedShift JDBC Driver, Python Connector and ODBC Driver - (CVE-2024-12744, CVE-2024-12745, CVE-2024-12746)
076
Reposted by @adrian-rt.bsky.social
Louis Nyffenegger @snyff.pentesterlab.com · 24/12/2024
🎅 pentesterlab.com/gift/v5kegJq... (3-month) pentesterlab.com/gift/4VG6RYU... (3-month) pentesterlab.com/gift/lsgfEwJ... (3-month)
pentesterlab.com
Learn Web Penetration Testing: The Right Way
Learn Web Penetration Testing: The Right Way
293
Reposted by @adrian-rt.bsky.social
Daniel Cuthbert @dcuthbert.bsky.social · 22/12/2024
I just….
3152
Reposted by @adrian-rt.bsky.social
ϻг_ϻε @steven.srcincite.io · 22/12/2024
These are some really nice blog posts regarding algo confusion bugs in JWT by @pentesterlab.com pentesterlab.com/blog/jwt-alg... & pentesterlab.com/blog/another... nice one @snyff.pentesterlab.com!
pentesterlab.com
PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.
1205
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 20/12/2024
Just thinking… If there’s no chunked responses in HTTP/2, could HTTP/1 be more efficient for race conditions which don’t require perfect parallelism but instead very small intervals (à la phpinfo+LFI)? 🧐
031
Reposted by @adrian-rt.bsky.social
harisec @harisec.bsky.social · 20/12/2024
OpenAI o3 model just achieved unbelievable scores (75% and 87%) on ARC-AGI, the previous models made maximum 20% and humans make around 85%. arcprize.org/blog/oai-o3-...
arcprize.org
OpenAI o3 Breakthrough High Score on ARC-AGI-Pub
OpenAI o3 scores 75.7% on ARC-AGI public leaderboard.
031
Reposted by @adrian-rt.bsky.social
OWASP® Foundation @owasp.org · 04/12/2024
🚀 Exciting news! Showcase your skills at the 2025 #OWASP Global #AppSec EU conference in vibrant Barcelona! The Call for Trainers is officially OPEN! Don't let this chance slip away. Submit your proposal today to inspire fellow enthusiasts: sessionize.com/owasp... #cybersecurity #devsecops #AI
084
Reposted by @adrian-rt.bsky.social
Nicolas Grégoire @agarri.fr · 17/11/2024
In case you're a professional Burp Suite user, there's a few seats left for the Q1 2025 training sessions hackademy.agarri.fr/2025
1158