Sign in

maitai

@maitai.bsky.social
56 followers 226 following 4 posts

BSc Computer Science Engineering | 24 | Trying to find my way ~ 🍭 blig.one

PostsRepliesMedia
maitai @maitai.bsky.social · 30/03/2026
Here is the blog post about the Node.js permission escape: blig.one/2026/03/29/n... I would like to highlight once again that this is not considered a vulnerability per the Node.js threat model. The fix is now public on the Node.js repo
blig.one
021
Reposted by maitai
Iceman @iceman1001.bsky.social · 13/07/2025
🔥 The future of RFID hacking isn’t dead, its even more... At #WHY2025, Kirils and I are breaking down current RFID hacking situation No fluff. Just spilling the beans. 🗓️ 9th of August 13:00 at Andromeda 🔗 cfp.why2025.org/why2025/talk... RT if you’re ready.
cfp.why2025.org
Decoding RFID: A comprehensive overview of security, attacks, and the latest innovations WHY2025
RFID reverse engineering has seen significant advancements, yet a comprehensive overview of the field remains scattered across research and practitioner communities. Here the authors presents a struc...
067
Reposted by maitai
st98 @st98.bsky.social · 18/04/2025
月火で岡山旅行に行っていた 買ってきたきびだんごがおいしい
021
Reposted by maitai
Lorenzo Leonardini @pianka.it · 28/02/2025
Took me a while, but here is the full article! If you want to see some weird URL parsing behavior, here you can find a lot of them :) sec.leonardini.dev/blog/playing... Disclaimer: no exploits nor vulnerabilities in this post, just some broken code
sec.leonardini.dev
Playing with Bun's URL parser
During the latest SECCON CTF quals, I had the pleasure of reading the custom implementation of Bun's URL parser, and I found some... weird behaviors... Join me in this wonderful journey.
182
Reposted by maitai
Nicolas Grégoire @agarri.fr · 07/03/2025
This article on Solr and its (in)security is really good 💎 And I strongly recommend to read @hacefresko.com previous article on Solr before diving in this one (I will share the link in my reply)
2144
Reposted by maitai
Kévin Gervot (Mizu) @mizu.re · 02/03/2025
For this challenge, it was necessary to abuse a discrepancy between the DOM and the rendered page in Firefox's cache handling 💽 👉 bugzilla.mozilla.org/show_bug.cgi... This allows to shift iframe rendering from one to another leading to a sandbox bypass 🔥 👉 mizu.re/post/an-18-y...
091
maitai @maitai.bsky.social · 25/02/2025
@hextreeio.bsky.social 👀
000
Reposted by maitai
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/02/2025
Bro is writing malware but also a Mad Max supervillian
1415
Reposted by maitai
Quarkslab @quarkslab.bsky.social · 13/02/2025
AMD published Security Bulletin AMD-SB-7027 addressing CVE-2024-0179 and CVE-2024-21925, the two UEFI SMM vulnerabilities disclosed in our blog post. Data center, desktop, mobile and embedded processors products are affected: www.amd.com/en/resources...
amd.com
022
Reposted by maitai
GitHub Security Lab @securitylab.github.com · 14/02/2025
Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled Pixel 8" by Man yue Mo github.blog/security/vul...
github.blog
Gaining kernel code execution on an MTE-enabled Pixel 8
In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulne...
032
Reposted by maitai
David Buchanan @retr0.id · 07/10/2024
Can you get root with only a cigarette lighter? (Yes!) www.da.vidbuchanan.co.uk/blog/dram-em...
a laptop running memtest86+, showing two errors. a wire pokes out from the lower edge of the laptop, annotated as "antenna wire". an orange cigarette/barbecue lighter sits next to it, annotated as "elite hacking tool"
1539781
maitai @maitai.bsky.social · 05/02/2025
Hype!
010
Reposted by maitai
smaury @smaury.bsky.social · 30/11/2024
If you are interested in client-side hacking and browser quirks I strongly recommend going through this writeup by @maitai.bsky.social! It was also cool to collab w/ him on the second chall 🤜🏿🤛🏻 blig.one/2024/11/29/f...
blig.one
Flatt Security XSS Challenge - Writeup | maitai's blog
0137
Reposted by maitai
PortSwigger Research @portswiggerres.bsky.social · 04/02/2025
The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
26636