Sign in

Flomb

@fl0mb.bsky.social
91 followers 1K following 6 posts

blog.flomb.net x.com/flomb_

PostsRepliesMedia
Flomb @fl0mb.bsky.social · 05/02/2026
Incredibly excited to share that my research 'Playing with HTTP/2 CONNECT' made the final @portswigger.net Top 10 Web Hacking Techniques of 2025! A huge thank you to everyone who voted. It’s a privilege to be featured alongside such talented researchers. portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
050
Reposted by Flomb
codewhitesec.bsky.social @codewhitesec.bsky.social · 23/01/2026
You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 code-white.com/blog/2026-01...
code-white.com
CODE WHITE | Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive
NetSupport Manager is a remote control and support software that we find surprisingly often utilized in sensitive *Operational Technology (OT)* environments, such as production plant networks. Besides...
068
Flomb @fl0mb.bsky.social · 19/01/2026
Honored to be nominated for the @portswigger.net Top 10 Web Hacking Techniques 2025 with my research "Playing with HTTP/2 CONNECT". Make sure to check out the full list and cast your vote! portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
000
Flomb @fl0mb.bsky.social · 31/12/2025
blog.flomb.net/posts/autotls/
blog.flomb.net
TIL: SNI-Based Auto Certificate Generation Is a Thing
I recently stumbled upon a great writeup which explained how it is possible to get a SSRF from SNI to hit the Azure VM Instance Metadata Service(IMDS). Inspired, I started scanning for this behaviour ...
000
Flomb @fl0mb.bsky.social · 31/12/2025
blog.flomb.net/posts/tekton/
blog.flomb.net
Tekton Dashboard RCE and Kubernetes API Proxy
This is the story of how I found two vulnerabilities in the Tekton CI/CD Dashboard component that allow remote code execution and a potential node takeover if deployed in read/write mode as well as pr...
000
Flomb @fl0mb.bsky.social · 15/09/2025
blog.flomb.net/posts/http2c...
blog.flomb.net
Playing with HTTP/2 CONNECT
In HTTP/1, the CONNECT method instructs a proxy to establish a TCP tunnel to a requested target. Once the tunnel is up, the proxy blindly forwards raw traffic in both directions. This mechanism is mos...
000
Reposted by Flomb
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/08/2025
We always love a good challenge. That’s why we’re sponsoring the 10th FAUST CTF. Game on at 2025.faustctf.net
2025.faustctf.net
FAUST CTF 2025 | FAUST CTF 2025
FAUST CTF 2025 is an online attack-defense CTF competition run by FAUST, the CTF team of Friedrich-Alexander University Erlangen-Nürnberg
076
Reposted by Flomb
Jorian @jorianwoltjer.com · 05/06/2025
Just pushed a new frontend for my site, and a new post! This one's about an tricky file write vulnerability on Windows in OBS. By crafting an image with very specific pixels, we can plant a backdoor on your PC all from an attacker's site by misconfiguring: jorianwoltjer.com/blog/p/resea...
jorianwoltjer.com
OBS WebSocket to RCE | Jorian Woltjer
Disabling password authentication of your OBS WebSocket server can have devastating consequences. We'll attack from the browser to construct an RCE payload on Windows formed from the pixels of an imag...
152
Reposted by Flomb
mrbruz.bsky.social @mrbruz.bsky.social · 11/05/2025
One-Click RCE in ASUS’s Preinstalled Driver Software mrbruh.com/asusdriverhub/
mrbruh.com
MrBruh's Epic Blog
One-Click RCE in ASUS’s Preinstalled Driver Software Introduction This story begins with a conversation about new PC parts. After ignoring the advice from my friend, I bought a new ASUS motherboard fo...
064
Reposted by Flomb
codewhitesec.bsky.social @codewhitesec.bsky.social · 13/05/2025
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-...
code-white.com
CODE WHITE | Analyzing the Attack Surface of Ivanti's DSM
Ivanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized dis...
088
Reposted by Flomb
Frycos @frycos.bsky.social · 28/04/2025
My blog post on some vulns in GFI MailEssentials frycos.github.io/vulns4free/2...
frycos.github.io
GFI MailEssentials - Yet Another .NET Target
What is this product GFI MailEssentials all about? We’re living the future, right? So let’s ask the GFI AI.
077
Flomb @fl0mb.bsky.social · 31/03/2025
blog.flomb.net/posts/ingres...
blog.flomb.net
Exploiting IngressNightmare: A Deep Dive
Wiz recently discovered an unauthenticated remote code execution (RCE) vulnerability in the Ingress NGINX admission controller. I found the exploit chain particularly intriguing and decided to recreat...
043
Reposted by Flomb
codewhitesec.bsky.social @codewhitesec.bsky.social · 21/02/2025
Ever wondered how Kurts Maultaschenfabrikle got hacked in 2023? The full story, all technical details, out now ;-) apply-if-you-can.com/walkthrough/...
apply-if-you-can.com
Walkthrough 2023
0710