Sign in

modzero

@modzero.bsky.social
158 followers 99 following 39 posts

Breaking stuff since 2011

PostsRepliesMedia
modzero @modzero.bsky.social · 03/06/2026
And here is the detailed report on our PSA from last week: "Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free" modzero.com/en/blog/plea...
modzero.com
Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free
011
modzero @modzero.bsky.social · 28/05/2026
🎶 PSA: Multiple Denial of Service vulnerabilities in TeamSpeak. Find our colleague Michael Imfelds advisory here modzero.com/en/advisorie...
modzero.com
[MZ-26-01] TeamSpeak
012
modzero @modzero.bsky.social · 12/03/2026
We're Hiring! We are currently looking for a Penetration Tester and a Senior Red Teamer. Check out our open positions and reach out if you think you’d be a great fit. Here: modzero.com/en/jobs/
modzero.com
Jobs
034
Reposted by modzero
netzpolitik.org @netzpolitik.org · 07/01/2026
Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und praktischen Lösungen will sich Nikonole einer zusammenbrechenden Welt entgegenstellen.
netzpolitik.org
Hacken & Kunst: „Kunst allein reicht nicht aus“
Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und ...
625078
Reposted by modzero
Drew Harwell @drewharwell.com · 07/01/2026
X basically industrialized the creation of fake porn of women who don't consent. Others did it first, but Grok made it normalized and centralized: publicly visible, instantly creatable by anyone, regardless of who's being targeted and dehumanized. Only question now is will X suffer any consequences
20748561272
Reposted by modzero
Stadt Wien-Büchereien @buechereienwien.bsky.social · 07/01/2026
Sollen wir Büchertische zum Thema Fitness und Fasten machen oder gleich die Oster-Backbücher rausstellen?
1519114
modzero @modzero.bsky.social · 10/11/2025
No Leak, No Problem - Remember our PSA about updating your INSTAR cameras? Here’s the reason in detail, worked out and noted by our teammate Michael Imfeld: modzero.com/en/blog/no-l...
modzero.com
No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE
031
modzero @modzero.bsky.social · 06/11/2025
Does anyone here have a working way to contact archive.org? It's about a security issue...
000
modzero @modzero.bsky.social · 28/09/2025
catch a glimpse of us holding our annual “state of the zero” meetup - to wrap our heads around all of IT and us. we also took a boat trip, ate too many sweets, touched some grass, saved the world, had a barbecue and a drink or two…💓 #modzero #infosec #itsecurity #captainitswednesday
061
modzero @modzero.bsky.social · 03/09/2025
quantität vs qualität. aber naja, was weiss ich schon.
010
modzero @modzero.bsky.social · 14/08/2025
PSA update your INSTAR cameras. Our teammate Michael Imfeld identified a critical RCE (CVE-2025-8760) on 2k+ and 4K devices. Find the advisory here: modzero.com/en/advisorie...
modzero.com
[MZ-25-03] INSTAR 2K+ and 4K Series
094
modzero @modzero.bsky.social · 29/06/2025
This blog post contains the full technical walk-through and discovery of the vulnerability, its impact, and our experience during the responsible disclosure process with Synology.
030
modzero @modzero.bsky.social · 29/06/2025
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...
modzero.com
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
12214
modzero @modzero.bsky.social · 25/06/2025
donate! www.thetinychefshow.com/fan-club-log...
thetinychefshow.com
SUPPORT CHEF — The Tiny Chef Show
010
modzero @modzero.bsky.social · 25/06/2025
nooooooooooo... 💔
110
modzero @modzero.bsky.social · 14/05/2025
🧙
000
modzero @modzero.bsky.social · 24/04/2025
*rülps
000
modzero @modzero.bsky.social · 02/04/2025
nice!
000
modzero @modzero.bsky.social · 31/03/2025
"kick off" passt ganz gut. wenn auch noch ein wenig zu höflich
120
modzero @modzero.bsky.social · 31/03/2025
vielleicht mal ein argument für bildungsgeld, das auch neolibs verstehen?
030
modzero @modzero.bsky.social · 11/02/2025
ja!
010
modzero @modzero.bsky.social · 07/02/2025
Dive into the process of reverse engineering, gadget hunting, and crafting a working exploit.
020
modzero @modzero.bsky.social · 07/02/2025
Via Return-Oriented Programming chain small code snippets, or gadgets, already present in a program’s memory can be leveraged By chaining these gadgets together, they can execute arbitrary code without injecting anything new
110
modzero @modzero.bsky.social · 07/02/2025
ROPing our way to “Yay, RCE” - and a lesson in the importance of a good nights sleep! Follow our Colleague Michaels journey of developing an ARM ROP chain to exploit a buffer overflow in uc-http modzero.com/en/blog/ropi...
modzero.com
ROPing our way to RCE
274
Reposted by modzero
abgeordnetenwatch @abgeordnetenwatch.de · 03/02/2025
🔔 Unser #kandidierendencheck ist online: 18 Thesen beantworten - und ihr erfahrt, welche Kandidierenden in eurem Wahlkreis so denken wie ihr. 👇 www.kandidierendencheck.de/bundestag
kandidierendencheck.de
kandidierendencheck Bundestagswahl 2025 | Wahlhilfe für deine Erststimme
Vergleichen Sie Ihre Meinung mit der Ihrer Kandidierenden über 18 Themen zur Wahl! Jetzt mitmachen!
11324151
modzero @modzero.bsky.social · 03/02/2025
uuuuh, nice.
020
modzero @modzero.bsky.social · 03/02/2025
hier! *wink
120
modzero @modzero.bsky.social · 29/01/2025
kluk 😐
000
Reposted by modzero
netzpolitik.org @netzpolitik.org · 29/01/2025
Seit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das Abstimmungsverhalten. netzpolitik.org/2025/real-o-...
netzpolitik.org
Real-O-Mat: Taten zählen mehr als Worte
Seit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das ...
18258124
modzero @modzero.bsky.social · 29/01/2025
"aus Verzweiflung rechtsradikal" wählen?
000
modzero @modzero.bsky.social · 27/01/2025
💓
010
modzero @modzero.bsky.social · 27/01/2025
ugh. 😷
000
modzero @modzero.bsky.social · 27/01/2025
kchkchkch. passt iwie auch immer. also, gern geschehen!
000
modzero @modzero.bsky.social · 27/01/2025
🎵 why don't you leave yor name and your number ... 🎶
100
modzero @modzero.bsky.social · 16/01/2025
learn all about it from our colleagues Pascal and Christoph at their 37c3 talk or from our published disclosure report: modzero.com/en/blog/mult...
modzero.com
Multiple Vulnerabilities in Poly VoIP Products
000
modzero @modzero.bsky.social · 16/01/2025
attackers could then listen in on conversations using the built-in microphones or could reroute incoming and outgoing calls ... and so on
100
modzero @modzero.bsky.social · 16/01/2025
we found several vulnerabilities in commonly used desk phones and smart conference speakers. combined, the issues can be used to take over a device through the local network or with physical access
100
modzero @modzero.bsky.social · 16/01/2025
was just listening to #DeLaSoul's classic #RingRingRing on the radio and thought about the time we broke a phone. or: how some coupled minor pinches can become a proper headache colleagues @yonk42.bsky.social and @parzel.bsky.social talked about it at #37c3 www.youtube.com/watch?v=K9mm...
youtube.com
37C3 - Finding Vulnerabilities in Internet-Connected Devices
YouTube video by media.ccc.de
220
Reposted by modzero
dunja hayali @dunjahayali.de · 13/01/2025
Wenn Sie sich die Unwörter der letzten 11 Jahre anschauen, was fällt Ihnen auf? • 2024 Biodeutsch • 2023 Remigration
2023: Remigration
2022: Klimaterroristen
2021: Pushback
2020: Corona-Diktatur und Rückführungspatenschaften
2019: Klimahysterie
2018: Anti-Abschiebe-Industrie
2017: Alternative Fakten
2016: Volksverräter
2015: Gutmensch
2014: Lügenpresse
2013: Sozialtourismus
1641642438
modzero @modzero.bsky.social · 10/01/2025
We were quite happy - at least for a minute - for there are probably easier ways to achieve the final result. So let us know if you have a better approach :) contact via link!
010
modzero @modzero.bsky.social · 10/01/2025
The post outlines the current state of SSTI on Spring Boot, explains where we got stuck with existing payloads and how to find your own exploitable libraries to bypass defenses.
110
modzero @modzero.bsky.social · 10/01/2025
We broke something: in a recent pentest on a hardened target, we were able to achieve unauthenticated Remote Code Execution (RCE) via Server-Side Template Injection (SSTI) in a Spring Boot application We wrote it down for you to try at home: modzero.com/en/blog/spri...
modzero.com
Exploiting SSTI in a Modern Spring Boot Application (3.3.4)
1195
Reposted by modzero
linuzifer @linuzifer.bsky.social · 29/12/2024
Der @ths.ch und ich haben uns beim #38C3 mal wieder mit Wahlsoftware beschäftigt. media.ccc.de/v/38c3-der-t...
media.ccc.de
Der Thüring-Test für Wahlsoftware
Wähle Dein Risiko! Vor der Bundestagswahl 2017 veröffentlichten wir unsere Analyse über haarsträubende Sicherheitslücken in einer weit v...
37917
modzero @modzero.bsky.social · 29/12/2024
it wasn't me. 🫶 #38c3
in handarbeit aus neon-klebeband gebasteltes modzero-logo an irgendeiner wand irgendwo auf dem 38c3
040
modzero @modzero.bsky.social · 18/12/2024
i am going on a trip and i am taking with me ... 💓 #38C3
cardboard box filled with different modzero and 38C3 -themed stickers
031
Reposted by modzero
Manuel 'HonkHase' Atug @honkhase.de · 03/12/2024
Wieder ein mega Programm! Der CCC hat zu seinem Chaos Communication Congress #38C3 den ersten Fahrplan veröffentlicht: Version Alpha-0.1 fahrplan.events.ccc.de/congress/202...
13816
Reposted by modzero
parzel @parzel.bsky.social · 27/11/2024
I can highly recommend Shazzer from @garethheyes.co.uk, such a great tool for XSS research!
youtube.com
Digging for XSS Gold: Unearthing Browser Quirks with Shazzer
YouTube video by PortSwigger
0224
modzero @modzero.bsky.social · 21/11/2024
Hello Bluesky 👋 We are an IT security company. Our team consists of like-minded hackers located in Germany and Switzerland. Our core areas of expertise are comprehensive technical security analyses, penetration tests and red teaming services. Want to learn more about us? Check: modzero.com/en/
modzero.com
In-depth IT Security
052