Sign in

pspaul

@pspaul95.bsky.social
76 followers 134 following 9 posts
PostsRepliesMedia
pspaul @pspaul95.bsky.social · 02/06/2026
A fun gadget I found recently! The .NET JIT compiler makes sure there are no rwx pages by using a memfd, but that turns file writes into straight shellcode execution 🐚
001
Reposted by pspaul
OffensiveCon @offensivecon.bsky.social · 29/05/2026
Offensivecon's talks are now available on our YouTube channel! 🔗 buff.ly/g63xgm5
youtube.com
OffensiveCon26
OffensiveCon 2026 Talks
053
Reposted by pspaul
OffensiveCon @offensivecon.bsky.social · 15/05/2026
SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud by @pspaul95.bsky.social and Moritz Sanft
032
pspaul @pspaul95.bsky.social · 24/04/2026
Pwning PostgreSQL was quite fun, excited to share our research at OffensiveCon! www.offensivecon.org/speakers/202...
15:15 - 16:15
SELECT shell FROM postgres: Digging up a 20-year-old bug for ZeroDay.Cloud
by Paul Gerste and Moritz Sanft
010
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 25/03/2026
📱 1-click RCE in the YTDLnis Android app! On Android, turning file writes into RCE is usually quite hard, but here the app had a nice gadget for us. Check out the details in our latest blog post: www.sonarsource.com/blog/ytdlnis... #appsec #security #vulnerability
sonarsource.com
From intent extra to RCE: Argument injection in YTDLnis
Discover a vulnerability our researchers found in the Android app YTDLnis, allowing attackers to execute code on victim devices.
021
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 09/12/2025
🧟 A fixed vulnerability that comes back to life? This could have happened in GitHub Actions until yesterday! Learn how attackers could have exploited seemingly fixed workflow vulnerabilities: www.sonarsource.com/blog/zombie-... #appsec #security #vulnerability
sonarsource.com
021
pspaul @pspaul95.bsky.social · 02/12/2025
My TROOPERS25 talk has been uploaded! If you ever wondered if "style-src: 'unsafe-line'" in your CSP is bad, this one is for you. Scriptless Attacks: Why CSS is My Favorite Programming Language www.youtube.com/watch?v=Owp-...
youtube.com
TROOPERS25: Scriptless Attacks - Why CSS is My Favorite Programming Language
YouTube video by TROOPERS IT Security Conference
000
pspaul @pspaul95.bsky.social · 04/11/2025
This was pretty fun to exploit! Even though I didn't manage to pwn the version used for Pwn2Own Berlin, I still learned a ton about LLMs. Maybe I can get my revenge in future competitions 🤞
051
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 16/09/2025
Using SonarQube to solve a CTF challenge? Done! ✅ Learn how we detected a 0-day vulnerability during #KalmarCTF, making us first to solve the challenge! From Zip Slip to RCE, using lazy class loading: www.sonarsource.com/blog/code-se... #appsec #CTF #vulnerability
sonarsource.com
031
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 08/07/2025
🔓⏫ After compromising every endpoint within an organization, our “Caught in the FortiNet” blog series comes to an end with one more thing. Read more about FortiClient's XPC mistake that allows local privilege escalation to root on macOS: www.sonarsource.com/blog/caught-... #appsec #security
sonarsource.com
Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations (3/3)
In the last blog of this series, we will focus back on FortiClient and learn how the inner workings of this application work, and what crucial mistake happened that led to us uncovering a local privil...
032
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 01/07/2025
📁🫷🚧Can't control the extension of a file upload, but you want an XSS? Read more on how we overcame this obstacle to further exploit entire organizations using Fortinet endpoint protection: www.sonarsource.com/blog/caught-... #appsec #vulnerability #bugbountytips
sonarsource.com
Caught in the FortiNet: How Attackers Can Exploit FortiClient to Compromise Organizations (2/3)
We recently discovered critical vulnerabilities in Fortinet’s endpoint protection solution that enable attackers to fully compromise organizations with minimal user interaction. In this second article...
011
pspaul @pspaul95.bsky.social · 26/06/2025
Great bug chain by my team mate Yaniv that can pwn a whole org, starting with a single user click! I was also able to contribute a bit by creating my first port of a Chrome n-day exploit :)
000
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 24/06/2025
Catch our second talk at #TROOPERS25: 🕸️ Caught in the FortiNet: Compromising Organizations Using Endpoint Protection Yaniv Nizry will tell you the story of multiple vulnerabilities in Fortinet products that can compromise an entire organization, starting with a single click
041
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 23/06/2025
Coming to #TROOPERS25 this week? We'll be there too, presenting our research! 🎨 Scriptless Attacks: Why CSS is My Favorite Programming Language @pspaul95.bsky.social will convince you why CSS should not be overlooked in client-side web attacks and what is possible without JavaScript today
Title: Scriptless Attacks: Why CSS is My Favorite Programming Language
Speaker: Paul Gerste, Vulnerability Researcher, Sonar
Date: Wednesday, June 25, 2025
Time: 2:15 pm
Location: Track 3
042
pspaul @pspaul95.bsky.social · 10/06/2025
This was a fun one to discover! SQL syntax can be ambiguous, and MySQL anticipated this a long time ago. Other SQL dialects stuck to the spec, leading to SQL injection when the right stars align:
010
Reposted by pspaul
SonarResearch @sonarresearch.bsky.social · 24/04/2025
📊⚠️ Data in danger! We found an XSS vulnerability in Grafana with the help of SonarQube. Learn about the details in our latest blog post: www.sonarsource.com/blog/data-in... #appsec #security #vulnerability
sonarsource.com
Data in Danger: Detecting Cross-Site Scripting in Grafana
Learn how SonarQube detected a Cross-Site Scripting (XSS) vulnerability in Grafana, a popular open-source data observability platform.
032
Reposted by pspaul
Rebane @rebane2001.bsky.social · 27/03/2025
"wow, this css property would be amazing for my css crime, i wonder what the browser support is looking like"
Browser compatibility
There is no browser implementing this feature.
1414
pspaul @pspaul95.bsky.social · 19/02/2025
Ever wondered what the Alt-Svc header is used for? Well, it can make you a MitM if you control it! I can finally publish the writeup to my GymTok challenge: control the header, become MitM, and perform a cross-protocol attack! blog.pspaul.de/posts/gymtok...
blog.pspaul.de
GymTok: Breaking TLS Using the Alt-Svc Header
Ever wondered what the Alt-Svc response header is used for? Turns out it can be used to become a Man-in-the-Middle and attack TLS!
022
pspaul @pspaul95.bsky.social · 06/02/2025
Wow, thanks for 2nd place! Didn't expect this, maybe it's my sign to finally write it down in text form and tackle all the follow-up ideas 👀
181