Sign in

Luke Jahnke

@nastystereo.com
421 followers 126 following 14 posts

Blogging at nastystereo.com

PostsRepliesMedia
Luke Jahnke @nastystereo.com · 14/08/2026
www.elttam.com/blog/ruby-4-...
elttam.com
Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam
This post releases a new universal chain that turns a single Marshal.load into command execution on Ruby, built with new gadgets from untapped sources as well as old gadgets put to new use.
010
Reposted by Luke Jahnke
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
Reposted by Luke Jahnke
Patrick Gray @patrick.risky.biz · 04/02/2026
ICYMI: This week's show is up! @metlstorm.risky.biz and I were joined by our new podcast host @jameswilson.io to talk all about the Notepad++ supply chain compromise and the security angle on the Clawdbot/Moltbook fiasco: VIDEO: www.youtube.com/watch?v=W5hx... AUDIO: risky.biz/RB823
youtube.com
Risky Business Weekly (823): Humans impersonate clawdbots impersonating humans
YouTube video by Risky Business Media
194
Luke Jahnke @nastystereo.com · 29/12/2025
nastystereo.com/security/rub...
nastystereo.com
Ruby Array Pack Bleed / nastystereo.com
021
Luke Jahnke @nastystereo.com · 29/10/2025
Found an interesting ruby bug, time to see if it impacts rails. Anyone want to collab?
211
Reposted by Luke Jahnke
Ken Shirriff @righto.com · 31/03/2025
The Pentium's microcode ROM holds 414,720 bits in total: 4608 micro-instructions. For more photos of the Pentium's microcode circuitry along with a detailed explanation, see my latest blog post: www.righto.com/2025/03/pent...
righto.com
Notes on the Pentium's microcode circuitry
Most people think of machine instructions as the fundamental steps that a computer performs. However, many processors have another layer of ...
0283
Luke Jahnke @nastystereo.com · 10/12/2024
My latest blog post is live! Check your Ruby on Rails applications for the use of params[:_json] nastystereo.com/security/rai...
13314
Reposted by Luke Jahnke
James Kettle @jameskettle.com · 05/12/2024
Ten years ago, I realised I needed to rewrite ActiveScan++ in Java. After putting it off for so long that artificial intelligence was literally able to do 90% of the work for me, I've done it! It's now available in the BApp store. Report issues and feature requests here -> github.com/albinowax/Ac...
github.com
GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin
ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.
04010
Reposted by Luke Jahnke
Catalin Cimpanu @campuscodi.risky.biz · 05/12/2024
Security researcher Luke Jahnke has published an escape for SafeMarshal, a new Ruby security gem that can be used to block deserialization attacks nastystereo.com/security/rub...
042
Luke Jahnke @nastystereo.com · 04/12/2024
My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation! nastystereo.com/security/rub...
1198
Reposted by Luke Jahnke
James Kettle @jameskettle.com · 03/12/2024
I've just rewritten ActiveScan++ in Java to lay the foundation for some major enhancements. It's not in the BApp store yet but if you'd like to take it for a spin you can grab it here: github.com/albinowax/Ac...
github.com
GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin
ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.
24616
Reposted by Luke Jahnke
PentesterLab @pentesterlab.com · 02/12/2024
🚨 CORS vulnerabilities in Go 🚨 Misusing strings.HasSuffix, Contains, or HasPrefix? You might be leaving the door wide open! 🔓 Learn how these patterns lead to bypasses 🐛👇 👉 pentesterlab.com/blog/golang-...
pentesterlab.com
PentesterLab Blog: CORS Vulnerabilities in Go: Vulnerable Patterns and Lessons
Dive into common CORS vulnerabilities found in Go codebases, with real-world examples of flawed origin validation. Understand how these mistakes occur and why Go developers need robust solutions to se...
21710
Luke Jahnke @nastystereo.com · 02/12/2024
New blog post is up! Shiny Vulnerabilities in R's Most Popular Web Framework nastystereo.com/security/r-s... Turns out the programming language R is used for more than statistics, including web apps!
2122
Reposted by Luke Jahnke
Koto @kkotowicz.bsky.social · 27/11/2024
Not sure how I missed that, but we now actually have Ken Thompson's C compiler backdoor code from the classic "Reflections on Trusting Trust". An excellent writeup by @swtch.com - research.swtch.com/nih.
research.swtch.com
research!rsc: Running the “Reflections on Trusting Trust” Compiler
0103
Reposted by Luke Jahnke
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Luke Jahnke @nastystereo.com · 25/11/2024
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, @ulldma.bsky.social and @vakzz.bsky.social nastystereo.com/security/rub...
0155