Sign in

ϻг_ϻε

@steven.srcincite.io
1.1K followers 115 following 49 posts

Hermetic Initiate. Exploring conscience and the nature of reality. I also hack things.

PostsRepliesMedia
Reposted by ϻг_ϻε
Atredis Partners @atredispartners.bsky.social · 28/01/2026
Command & Conquer'd: worming RCEs through a classic multiplayer game. Check out the full writeup from our @districtcon.bsky.social Junkyard submission here: www.atredis.com/blog/2026/1/... By @droner.bsky.social and @jordan9001.bsky.social #Security #modding #rce
atredis.com
General Graboids: Worms and Remote Code Execution in Command & Conquer — Atredis Partners
[this work was conducted collaboratively by Bryan Alexander and Jordan Whitehead] This post details several vulnerabilities discovered in the popular online game Command & Conquer: Generals. We…
0109
ϻг_ϻε @steven.srcincite.io · 29/01/2026
Oh I nearly forgot about this platform
050
Reposted by ϻг_ϻε
fromveeko.bsky.social @fromveeko.bsky.social · 29/01/2026
@steven.srcincite.io did some cool stuff, check it out! srcincite.io/blog/2026/01...
srcincite.io
Samstung Part 1 :: Remote Code Execution in MagicINFO 9 Server
One weekend, I decided to unpack some of the patches that Samsung have been sending out for their MagicINFO 9 solution. During this process, I discovered mul...
032
Reposted by ϻг_ϻε
Peter Stöckli @ulldma.bsky.social · 12/03/2025
If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292). github.blog/security/sig...
github.blog
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials
Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.
11110
Reposted by ϻг_ϻε
Jasmine 🌌🔭 @astrojaz.bsky.social · 05/02/2025
NEW JWST IMAGE SHOWING A PROTOPLANETARY DISK AROUND A NEWLY FORMED STAR!!! 🤩
A close-in image of a protoplanetary disc around a newly formed star. Many different wavelengths of light are combined and represented by separate and various colors. A dark line across the center is the disc, made of opaque dust: the star is hidden in here and creates a strong glow in the center. A band going straight up is a jet, while other outflows form flares above and below the disc, and a tail coming off to one side.
301007207
Reposted by ϻг_ϻε
Michael Stepankin @artsploit.com · 22/01/2025
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! github.blog/security/vul...
12916
ϻг_ϻε @steven.srcincite.io · 22/01/2025
media.tenor.com
a cartoon character is holding a bunch of money and the words shut up and are above him
ALT: a cartoon character is holding a bunch of money and the words shut up and are above him
010
ϻг_ϻε @steven.srcincite.io · 22/01/2025
This is what I love about Chris, authenticity: muffsec.com/blog/abstain.... Btw I couldn’t agree more with his conclusion about the event.
muffsec.com
Abstaining From Pwn2own – muffSec
030
Reposted by ϻг_ϻε
SwiftOnSecurity @swiftonsecurity.com · 17/01/2025
Bitcoin is enemy of culture because it introduces monetary incentive where only prestige belongs.
217315
Reposted by ϻг_ϻε
Stephen Fewer @stephenfewer.bsky.social · 16/01/2025
I wrote a PoC for the recent Ivanti Connect Secure stack buffer overflow, CVE-2025-0282, based on the exploitation strategy watchTowr published, along with an assessment of exploitability given the lack of a suitable info leak to break ASLR: attackerkb.com/assessments/...
1118
Reposted by ϻг_ϻε
Kelsey Hightower @kelseyhightower.com · 13/01/2025
What's the point of being rich if you can't afford to do the right thing.
730272814108
Reposted by ϻг_ϻε
James Kettle @jameskettle.com · 08/01/2025
Nominations are now open for the Top 10 Web Hacking Techniques of 2024! Browse the contestants and submit your own here: portswigger.net/research/top...
portswigger.net
Top ten web hacking techniques of 2024: nominations open
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
12819
Reposted by ϻг_ϻε
Natalie Silvanovich @natashenka.bsky.social · 10/01/2025
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium.org/issues/36869...
project-zero.issues.chromium.org
Project Zero
13816
ϻг_ϻε @steven.srcincite.io · 03/01/2025
youtu.be/a6EnyQ0Dy50?...
youtu.be
Aleph Bass — an aleph bet song by Darshan :: אלף בית – דרשן
YouTube video by Darshan Project
010
Reposted by ϻг_ϻε
Nicolas Grégoire @agarri.fr · 27/12/2024
Positive Technologies published two scenarios they encountered during pentests, where they pivot to the internal network thanks to an Internet-facing Exchange server and its numerous SSRF vectors 💎
static.ptsecurity.com
163
ϻг_ϻε @steven.srcincite.io · 27/12/2024
Nice fail troll
000
Reposted by ϻг_ϻε
Nicolas Grégoire @agarri.fr · 20/12/2024
TIL how easy it is to ask curl to dump TLS session keys to disk 🛠️ Simply set the environment variable `SSLKEYLOGFILE=/path/to/file` 😅 Note: it also works for Firefox and Chrome Extremely useful when combined with Wireshark 👍
613336
Reposted by ϻг_ϻε
Alex Chapman @ajxchapman.bsky.social · 22/12/2024
CVE-2024-12727 Sophos coming in with an unauthenticated SQLi in their firewall appliance 👏
29225
ϻг_ϻε @steven.srcincite.io · 22/12/2024
These are some really nice blog posts regarding algo confusion bugs in JWT by @pentesterlab.com pentesterlab.com/blog/jwt-alg... & pentesterlab.com/blog/another... nice one @snyff.pentesterlab.com!
pentesterlab.com
PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.
1205
ϻг_ϻε @steven.srcincite.io · 22/12/2024
Life doesn’t need to be complicated
020
Reposted by ϻг_ϻε
Piotr Bazydło @chudypb.bsky.social · 19/12/2024
[4/n] My Hexacon 2023 talk about .NET Deserialization. New gadgets, insecure serialization (RCE through serialization) and custom gadgets found in the products codebase. Talk: www.youtube.com/watch?v=_CJm... White paper: github.com/thezdi/prese...
youtube.com
HEXACON2023 - Exploiting Hardened .NET Deserialization by Piotr Bazydło
YouTube video by Hexacon
052
Reposted by ϻг_ϻε
Louis Nyffenegger @snyff.pentesterlab.com · 18/12/2024
I put together a VERY limited (for now) list of web hackers in a Starter pack: go.bsky.app/9uay4Ad A lot of people are missing (I will try to add more as I find them) but make sure you follow people already in the list!
33114
ϻг_ϻε @steven.srcincite.io · 18/12/2024
It’s a different poc per app that’s vulnerable. Most struts apps that use a vuln framework are probably not vuln because they still need to implement an upload feature in a specific way. TL;DR don’t lose sleep over it.
131
ϻг_ϻε @steven.srcincite.io · 17/12/2024
S2-067 is a fantastic bypass of the patch for S2-066. It uses ONGL to re-write the upload filename property in order to bypass the filename path traversal checks. PoC: if the target bean is called "UploadFile" the your target parameter is "top.UploadFileFileName". 🤯
062
Reposted by ϻг_ϻε
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658
Reposted by ϻг_ϻε
onion person @junlper.beer · 17/12/2024
wokism is out of control
1016880367
ϻг_ϻε @steven.srcincite.io · 16/12/2024
…and what is your office? My office is that which is in the higher aspirant of the soul - Ma’at
000
ϻг_ϻε @steven.srcincite.io · 16/12/2024
Mexico is always a good idea, though I maybe biased :D
030
Reposted by ϻг_ϻε
James Forshaw @tiraniddo.dev · 12/12/2024
A companion blog to my Bluehat 2024 presentation on OleView.NET is up now. googleprojectzero.blogspot.com/2024/12/wind...
googleprojectzero.blogspot.com
01812
Reposted by ϻг_ϻε
Piotr Bazydło @chudypb.bsky.social · 12/12/2024
I wrote a fun, little blog post. Remote pre-auth file deletion in SolarWinds ARM allowed to achieve LPE on AD machines 🙃
196
ϻг_ϻε @steven.srcincite.io · 12/12/2024
Imagine a perspective like this on sleep. Carl Jung would turn in his grave.
000
ϻг_ϻε @steven.srcincite.io · 12/12/2024
empirical number?
000
ϻг_ϻε @steven.srcincite.io · 06/12/2024
Here is a great follow up blog post to my blog Remote Code Execution with Spring properties written by Elliot Ward: snyk.io/articles/rem...
snyk.io
Remote Code Execution with Spring Boot 3.4.0 Properties | Snyk
this article introduces two methods for leveraging Logback configuration to achieve Remote Code Execution (RCE) in Spring Boot applications. These techniques are effective on the latest version of Spr...
0218
ϻг_ϻε @steven.srcincite.io · 06/12/2024
Shit posting on wastebook and having my family all triggered is the glory I get on a Friyay!
040
Reposted by ϻг_ϻε
Luke Jahnke @nastystereo.com · 04/12/2024
My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation! nastystereo.com/security/rub...
1198
ϻг_ϻε @steven.srcincite.io · 04/12/2024
I can give you a few ;-)
010
ϻг_ϻε @steven.srcincite.io · 01/12/2024
So much better 👍🏻
010
ϻг_ϻε @steven.srcincite.io · 29/11/2024
Thank you! Your most welcome 🙏🏻
010
Reposted by ϻг_ϻε
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
ϻг_ϻε @steven.srcincite.io · 27/11/2024
Thanks m8! It means a lot from you! <3
010
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
ϻг_ϻε @steven.srcincite.io · 26/11/2024
If it’s valid how are you gonna get into the logs 🤪
020
Reposted by ϻг_ϻε
Luke Jahnke @nastystereo.com · 25/11/2024
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, @ulldma.bsky.social and @vakzz.bsky.social nastystereo.com/security/rub...
0155
ϻг_ϻε @steven.srcincite.io · 25/11/2024
Trust me, the Chinese hack Spring apps harder than you: juejin.cn/post/6972564...
juejin.cn
182
ϻг_ϻε @steven.srcincite.io · 24/11/2024
Thanks Alex!
000
ϻг_ϻε @steven.srcincite.io · 24/11/2024
Ah thanks!
010
ϻг_ϻε @steven.srcincite.io · 24/11/2024
Ah thanks man
010
ϻг_ϻε @steven.srcincite.io · 23/11/2024
But I guess folks just don’t call it validation at that point, and granted they would have a point. Because one has an explicit intent vs implicitly type check.
110