Sign in

Sam Curry

@zlz.bsky.social
1.8K followers 22 following 5 posts
PostsRepliesMedia
Reposted by Sam Curry
David Buchanan @retr0.id · 05/06/2025
userland ROP on day 1 💪
1002039320
Sam Curry @zlz.bsky.social · 23/01/2025
New blog post with @shubs.io: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. Full post here: samcurry.net/hacking-subaru
samcurry.net
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State...
57330
Reposted by Sam Curry
Bee 🐝 @securibee.bsky.social · 16/12/2024
Documentary on Hackers Who Get Paid to Hack Companies. @CyberNews interviewed Bryce (@realytcracker), Ben (@NahamSec), Sam Curry (@zlz), Frederik (@stokfredrik), Neiko (@_specters_), Vanya (@BusesCanFly), Phoenix (LilRed), André (@0xacb).
142
Reposted by Sam Curry
PortSwigger Research @portswiggerres.bsky.social · 04/12/2024
Did you know you can use an ancient magic cookie to downgrade parsers and bypass WAFs?! Hope you enjoy this quality bit of RFC-diving from @d4d89704243.bsky.social! portswigger.net/research/byp...
portswigger.net
Bypassing WAFs with the phantom $Version cookie
HTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known
17327
Reposted by Sam Curry
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Reposted by Sam Curry
SandShark @inert.me · 25/11/2024
This must be the result of the attempts
051
Sam Curry @zlz.bsky.social · 25/11/2024
Does anyone know the max size limit for Bluesky usernames? The DNS and everything resolves correctly for this (253 characters), but it seems to throw 400 bad request when I actually try to assign it.
3261