Sign in

Cristian Cantos

@kriware.bsky.social
129 followers 181 following 148 posts

Security Analyst at Layakk
Permanent student
Kriware Security Feed: Feed of technical blogs about cybersecurity. -> Telegram Channel: t.me/kriwarefeed
YouTuber: kriware
RootedCON co-organizer

PostsRepliesMedia
Reposted by Cristian Cantos
Cristian Cantos @kriware.bsky.social · 06/12/2024
Are you still not part of the EXCLUSIVE hacker community that receives a DAILY TECHNICAL article about hacking? Every day, practical and advanced knowledge delivered straight to you. Join now! 👇
021
Cristian Cantos @kriware.bsky.social · 20/07/2025
Chaining Directory Traversal & CSV Parser Abuse for RCE in Django Combines unsanitized username path traversal with pandas CSV to_csv() quirks to overwrite wsgi.py and gain RCE. jineeshak.github.io/posts/Chaining-… #django
000
Cristian Cantos @kriware.bsky.social · 19/07/2025
Solo: A Pixel 6 Pro Story Researcher adapts a Mali GPU integer overflow (CVE‑2023‑48409) to root Pixel 6 Pro by adding memory-spraying and SELinux bypasses—all from a single bug. starlabs.sg/blog/2025/06-solo-a-pix… #Android
000
Cristian Cantos @kriware.bsky.social · 18/07/2025
TapTrap: Invisible Animation‑Driven Tapjacking on Android A malicious app with zero permissions uses transparent animations to hide real system prompts (e.g., camera, location, admin) and trick users into tapping them unknowingly. taptrap.click #Tapjacking #AndroidAttack
000
Cristian Cantos @kriware.bsky.social · 17/07/2025
GPUHammer: Rowhammer Attack on NVIDIA GDDR6 GPUs GPUHammer is the first practical Rowhammer attack on GDDR6 VRAM (e.g., RTX A6000), flipping bits via CUDA and silently corrupting AI models, plummeting accuracy from ~80% to under 1%. gpuhammer.com #Rowhammer #GPUAttacks
000
Cristian Cantos @kriware.bsky.social · 16/07/2025
DreamWalkers: Reflective Shellcode Loader with Clean Call Stacks A loader that achieves believable call stacks in reflectively loaded modules by parsing PE and registering unwind data via RtlAddFunctionTable. maxdcb.github.io/DreamWalkers #ShellcodeLoader #CallStackSpoofing
000
Cristian Cantos @kriware.bsky.social · 15/07/2025
Windows Kernel Pool Internals Explains kernel pool allocation, PoolTags, segment heap (kLFH, VS, Large), and building a no‑admin tool to enumerate tags. r0keb.github.io/posts/Windows-Kerne… #Kernel #Heap #windows
011
Cristian Cantos @kriware.bsky.social · 14/07/2025
Exploiting WRMSR in Vulnerable Drivers Detailed guide on abusing unsecured WRMSR IOCTLs to overwrite LSTAR MSR, build ROP chains bypassing SMEP/SMAP/KPTI, and gain kernel execution. idafchev.github.io/blog/wrmsr #Kernel #windows
000
Cristian Cantos @kriware.bsky.social · 13/07/2025
Hexagon Fuzz: Full-System Emulated Fuzzing of Qualcomm Basebands SRLabs released the first open-source emulator-based fuzzing toolchain for Qualcomm Hexagon baseband firmware www.srlabs.de/blog-post/hexagon-fuz… #Baseband #Fuzzing
000
Cristian Cantos @kriware.bsky.social · 12/07/2025
Rediscovered an 11‑Year‑Old libpng Vulnerability A beginner in secure code review reintroduced CVE‑2014‑9495 by fuzzing width * bit-depth overflow blog.himanshuanand.com/posts/discov… #libpng #IntegerOverflow
000
Cristian Cantos @kriware.bsky.social · 11/07/2025
Resurrecting a Dead Torrent Tracker and Finding 3M Peers Revived an expired .si tracker domain, launched Opentracker on VPS, and attracted ~1.7M torrents with 3.1M unique peers in just one hour. kianbradley.com/2025/06/15/resurrec… #TorrentTracker
000
Cristian Cantos @kriware.bsky.social · 10/07/2025
Reliable System Call Interception Highlights using seccomp_user_notify with BPF for low‑overhead syscall interception, replacing slow ptrace—demoed via “copycat” tool for per‑syscall file redirection. blog.mggross.com/intercepting-sysca… #Seccomp #SyscallInterceptor
000
Cristian Cantos @kriware.bsky.social · 09/07/2025
VNC Honeypot Setup by James Woolley Details setting up a VNC honeypot on Ubuntu that logs sessions, records attacker interactions, and captures payloads for monitoring. ja.meswoolley.co.uk/vnc-honeypot #VNC #Honeypot
000
Cristian Cantos @kriware.bsky.social · 08/07/2025
The Hidden JTAG in Your Qualcomm/Snapdragon Device’s USB Port A built-in Embedded USB Debug (EUD) interface since ~2018 allows SWD/JTAG access via USB, enabling kernel/U-Boot debugging without external tools. www.linaro.org/blog/hidden-jtag-qua… #Snapdragon
000
Cristian Cantos @kriware.bsky.social · 07/07/2025
Implementing Fast TCP Fingerprinting with eBPF A Golang webserver uses eBPF (XDP + kernel hashmap) to capture TCP SYN options at kernel-level and fingerprint clients efficiently. halb.it/posts/ebpf-fingerprinting-1 #eBPF #TCPFingerprinting
020
Cristian Cantos @kriware.bsky.social · 06/07/2025
How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets Using GH Archive & GitHub Event API, Truffle’s tool scans zero‑commit force-pushes since 2020 to find leaked secrets. trufflesecurity.com/blog/guest-post… #git
000
Cristian Cantos @kriware.bsky.social · 05/07/2025
Alice’s Adventures in a Differentiable Wonderland A friendly primer on differentiable programming and neural nets—covering autodiff, CNNs, RNNs, transformers in PyTorch & JAX. arxiv.org/abs/2404.17625 #NeuralNetwork
000
Cristian Cantos @kriware.bsky.social · 01/07/2025
Essential C – Stanford CS Education Library Concise 45‑page guide covering C fundamentals: types, control flow, arrays, pointers, memory, struct, functions, and compilation. cslibrary.stanford.edu/101 #c #programming
000
Cristian Cantos @kriware.bsky.social · 30/06/2025
TPU Deep Dive Google’s TPUs use large systolic arrays, scratchpad memory, XLA AoT compilation, and 3D-torus interconnects to deliver exascale AI compute with efficiency. henryhmko.github.io/posts/tpu/tpu.h… #tpu #firmware
000
Cristian Cantos @kriware.bsky.social · 29/06/2025
Root Shell on Yomani Credit‑Card Terminal Reverse‑engineered Worldline Yomani XR: found exposed serial console with root shell, bypassed tamper protections via hardware debug port. stefan-gloor.ch/yomani-hack #terminal
000
Cristian Cantos @kriware.bsky.social · 28/06/2025
FileFix – A ClickFix Alternative Browser trick uses file upload to open File Explorer, copy malicious PowerShell path disguised as a doc, and auto-execute via address bar. mrd0x.com/filefix-clickfix-alternat… #Phishing
000
Cristian Cantos @kriware.bsky.social · 27/06/2025
Primitive Injection – Breaking the Status Quo Project creates reliable read/write/allocate primitives to evade telemetry by enabling custom injection flows and changing process IOCs. trickster0.github.io/posts/Primitiv… #injection #evasion
000
Cristian Cantos @kriware.bsky.social · 26/06/2025
PicoEMP – Low-Cost DIY EMFI Tool PicoEMP is a budget Electromagnetic Fault Injection (EMFI) device using Raspberry Pi Pico, ideal for hobbyist security research. github.com/newaetech/chipshouter-pi… #HardwareHacking
000
Cristian Cantos @kriware.bsky.social · 24/06/2025
Intercepting Traffic on Android with Mainline and Conscrypt NVISO explains how Conscrypt updates impacted HTTPS interception and how their AlwaysTrustUserCerts Magisk module now supports A7–A16. blog.nviso.eu/2025/06/05/intercepti… #android
000
Cristian Cantos @kriware.bsky.social · 23/06/2025
Fault Injection – Follow the White Rabbit Demonstrates EMFI and voltage glitching on ESP32‑V3 to modify flash CRC32 and combine glitch for Secure Boot bypass via complex fault‑injection chain. security.humanativaspa.it/fault-inj… #EMFI #SecureBootBypass
000
Cristian Cantos @kriware.bsky.social · 22/06/2025
Make Self‑XSS Great Again Transforms stored self‑XSS into actual stored XSS using modern credentialless iframes plus CSRF to hijack victim sessions. blog.slonser.info/posts/make-self-x… #web #xss
000
Cristian Cantos @kriware.bsky.social · 21/06/2025
Funky Chunks: Abusing Chunk Line Terminators for Request Smuggling Investigates ambiguous chunk-line terminators enabling HTTP request smuggling via non-standard chunk parsing. w4ke.info/2025/06/18/funky-chunks.h… #RequestSmuggling #HTTPParsing
000
Cristian Cantos @kriware.bsky.social · 20/06/2025
MCP Security Tips – 5 Risks & Safeguards NCC Group highlights five MCP security risks: supply-chain, local/remote vulnerabilities, prompt injection, excessive capabilities, and offers practical mitigations. www.nccgroup.com/us/research-blog/5… #MCP #AI
000
Cristian Cantos @kriware.bsky.social · 19/06/2025
Emulating a Bike Sensor with ESP32 BLE Builds an ESP32-based BLE Cycling Speed & Cadence sensor using a single reed switch to emulate speed and cadence, leveraging the standard CSC BLE profile. eybisi.run/Emulating-a-Bike-Sensor #BLE #HardwareHacking
000
Cristian Cantos @kriware.bsky.social · 18/06/2025
PatchGuard Internals – Deep Kernel Protection Dive Explains PatchGuard’s initialization phases, secure-hypervisor activation paths, and context setup, revealing potential bypass points. r0keb.github.io/posts/PatchGuard-In… #PatchGuard #WindowsKernel
000
Cristian Cantos @kriware.bsky.social · 17/06/2025
Fuzzing WebSockets for Server‑Side Vulnerabilities Research reveals a technique using the Backslash Powered Scanner extension to fuzz WebSocket endpoints and find server‑side bugs. arete06.com/posts/fuzzing-ws #WebSocket #Fuzzing
000
Cristian Cantos @kriware.bsky.social · 16/06/2025
Brokering File System January 2025 Patch Analysis Microsoft patched two use‑after‑free bugs in bfs.sys via KB5050009 and KB5049984, fixing race‑condition flaws in PipeMappingTable and PolicyTable. ht3labs.com/Brokering-File-System-J… #WindowsKernel
000
Cristian Cantos @kriware.bsky.social · 15/06/2025
Reverse Camera Firmware Decryption Researchers figured out encrypted Hanwha firmware uses AES‑256‑CFB8 with key derived from “zeppelin” hash and model-based passphrases to decrypt .img files. brownfinesecurity.com/blog/hanwha-f… #IoT #Firmware
000
Cristian Cantos @kriware.bsky.social · 14/06/2025
Brute‑forcing Any Google User’s Phone Number IPv6 address rotation across no‑JS account recovery forms enables bruteforcing phone+display name combinations to discover full user numbers. brutecat.com/articles/leaking-googl… #AccountAbuse #PrivacyExploit
000
Cristian Cantos @kriware.bsky.social · 13/06/2025
000
Cristian Cantos @kriware.bsky.social · 13/06/2025
Covert Web-to-App Tracking via Localhost on Android JavaScript via Meta Pixel and Yandex Metrica transmits browser cookies to native Android apps via localhost sockets, linking web sessions to user IDs—bypassing incognito, permissions, and clearing cookies. localmess.github.io #privacy
000
Cristian Cantos @kriware.bsky.social · 12/06/2025
Camera & Microphone Spying via Chromium Flags Chromium’s --auto-accept-camera-and-microphone-capture flag lets attackers silently record webcam audio/video without user consent. mrd0x.com/spying-with-chromium-brow… #Chromium #PrivacyThreat
000
Cristian Cantos @kriware.bsky.social · 11/06/2025
High-Performance Network Fuzzing with LibAFL and libdesock Custom fuzzer using LibAFL and libdesock achieves 42x speedup over AFLNet via tokenized inputs and shared memory, uncovering new bugs. lolcads.github.io/posts/2025/05/hig… #Fuzzing #Network
000
Cristian Cantos @kriware.bsky.social · 10/06/2025
The Ultimate Guide to Windows Coercion Techniques in 2025 RedTeam Pentesting details modern Windows coercion methods, analyzing their effectiveness and bypasses for recent mitigations. blog.redteam-pentesting.de/2025/win… #Windows
000
Cristian Cantos @kriware.bsky.social · 09/06/2025
Tokenization Confusion Reseacher examines how simple prompt obfuscations, like hyphenation, can bypass LLM safety models due to tokenization quirks. blog.xpnsec.com/tokenization-confus… #LLM #PromptInjection
000
Cristian Cantos @kriware.bsky.social · 08/06/2025
Poison Everywhere: No Output from Your MCP Server Is Safe Attackers can manipulate outputs from Anthropic's MCP servers, complicating detection and response. www.cyberark.com/resources/threat-r… #MCP
110
Cristian Cantos @kriware.bsky.social · 04/06/2025
Offensive CTI Explores offensive cyber threat intelligence (CTI) techniques, focusing on leveraging adversary tactics for proactive defense strategies. blog.zsec.uk/offensive-cti #CTI #ThreatIntel
000
Cristian Cantos @kriware.bsky.social · 03/06/2025
Understanding Integer Overflow in Windows Kernel White Knight Labs explores how unchecked arithmetic in kernel drivers can cause heap corruption via integer overflows. whiteknightlabs.com/2025/05/27/unde… #Exploiting
000
Cristian Cantos @kriware.bsky.social · 02/06/2025
Red Team Gold: Extracting Credentials from MDT Shares TrustedSec reveals how misconfigured Microsoft Deployment Toolkit shares can expose plaintext domain credentials, aiding lateral movement. trustedsec.com/blog/red-team-gold-e… #MDT #RedTeam
000
Cristian Cantos @kriware.bsky.social · 01/06/2025
Abusing dMSA to Escalate Privileges in Active Directory Akamai reveals a flaw in Windows Server 2025's dMSA, allowing attackers with minimal permissions to escalate privileges in AD. www.akamai.com/blog/security-resear… #AD
000
Cristian Cantos @kriware.bsky.social · 31/05/2025
Decoding TCP SYN for Stronger Network Security Analysis unsolicited TCP SYN packets from honeypots, revealing patterns in TTL and header lengths without evidence of IP spoofing. www.netscout.com/blog/asert/decodin… #TCP #DDoS
000
Cristian Cantos @kriware.bsky.social · 30/05/2025
From Reverse Engineering to Cheat Development Step-by-step guide to building an external ESP and aimbot for AssaultCube adminions.ca/books/articles/page/pa… #GameHacking #RE
000
Cristian Cantos @kriware.bsky.social · 29/05/2025
How to use o3 to Find CVE-2025-37899 Researcher used OpenAI’s o3 model to discover CVE-2025-37899, a use-after-free bug in Linux. sean.heelan.io/2025/05/22/how-i-use… #Linux #SMB
000
Cristian Cantos @kriware.bsky.social · 28/05/2025
Attacking EDRs: Intro & Security Analysis of EDR Drivers InfoGuard examines EDR driver attack surfaces, focusing on low-privileged user access and potential vulnerabilities in Windows agents. labs.infoguard.ch/posts/edr_part1_i… #EDR #DriverAnalysis
000
Cristian Cantos @kriware.bsky.social · 27/05/2025
Bypassing kASLR via Cache Timing Explores a prefetch side-channel attack to bypass kASLR on Windows 11 by measuring cache access times to locate the kernel base address. r0keb.github.io/posts/Bypassing-kAS… #kASLR #SideChannel
000