Sign in

Luke Jahnke

@nastystereo.com
421 followers 126 following 14 posts

Blogging at nastystereo.com

PostsRepliesMedia
Luke Jahnke @nastystereo.com · 10/12/2024
My latest blog post is live! Check your Ruby on Rails applications for the use of params[:_json] nastystereo.com/security/rai...
13314
Luke Jahnke @nastystereo.com · 04/12/2024
My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation! nastystereo.com/security/rub...
1198
Luke Jahnke @nastystereo.com · 02/12/2024
I hope to write a follow up post that covers the footguns I learnt about for R apps, especially jsonlite::fromJSON ;)
030
Luke Jahnke @nastystereo.com · 02/12/2024
New blog post is up! Shiny Vulnerabilities in R's Most Popular Web Framework nastystereo.com/security/r-s... Turns out the programming language R is used for more than statistics, including web apps!
2122
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Luke Jahnke @nastystereo.com · 25/11/2024
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, @ulldma.bsky.social and @vakzz.bsky.social nastystereo.com/security/rub...
0155