* identify calls to common fingerprinting APIs
* decode/decrypt known data collector payloads
* Hook things without leaving a trace
* detect obfuscated scripts & deobfuscate
+ more
I wrote about it!
nullpt.rs/reverse-engineering-browser
* identify calls to common fingerprinting APIs
* decode/decrypt known data collector payloads
* Hook things without leaving a trace
* detect obfuscated scripts & deobfuscate
+ more
I wrote about it!
nullpt.rs/reverse-engineering-browser
unit42.paloaltonetworks.com/github-actio...
unit42.paloaltonetworks.com/github-actio...
Today's a phenomenal day for research papers. Leaking memory contents using DNS requests???
Xie Xie, yes please gfw.report/publications...
Today's a phenomenal day for research papers. Leaking memory contents using DNS requests???
Xie Xie, yes please gfw.report/publications...
It is easy to access the file system of the docker containers through /proc/[pid]/root/, this makes it easy to run tools not available in the container, copy and edit files etc.
This is especially useful for hardened containers
It is easy to access the file system of the docker containers through /proc/[pid]/root/, this makes it easy to run tools not available in the container, copy and edit files etc.
This is especially useful for hardened containers
It is easy to access the file system of the docker containers through /proc/[pid]/root/, this makes it easy to run tools not available in the container, copy and edit files etc.
This is especially useful for hardened containers
It is easy to access the file system of the docker containers through /proc/[pid]/root/, this makes it easy to run tools not available in the container, copy and edit files etc.
This is especially useful for hardened containers
pchaigno.github.io/bpf/2025/01/...
I plan to keep the list up-to-date.
pchaigno.github.io/bpf/2025/01/...
I plan to keep the list up-to-date.
#attacksurfacemanagement
#attacksurfacemanagement
For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
Essentially it is small hot-swappable programs that run in the linux kernel, making it possible to e.g. log arguments to syscall and userland functions. It is also possible to change the behaviour of syscalls (some limits apply)
Essentially it is small hot-swappable programs that run in the linux kernel, making it possible to e.g. log arguments to syscall and userland functions. It is also possible to change the behaviour of syscalls (some limits apply)
If you like regular XSS, this is a whole new world of crazy techniques and many sanitizer bypasses. You too can learn this!
jorianwoltjer.com/blog/p/hacki...
If you like regular XSS, this is a whole new world of crazy techniques and many sanitizer bypasses. You too can learn this!
jorianwoltjer.com/blog/p/hacki...
Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
#vulnerability #exploit #greynoise #null #byte
#vulnerability #exploit #greynoise #null #byte
Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
Read more here: www.volexity.com/blog/2024/11...
Read more here: www.volexity.com/blog/2024/11...
jdomeracki.github.io/2024/11/09/s...
jdomeracki.github.io/2024/11/09/s...
I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.
naehrdine.blogspot.com/2024/11/reve...
I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented.
naehrdine.blogspot.com/2024/11/reve...
youtu.be/bCNnloBaw_U?...
youtu.be/bCNnloBaw_U?...
Created a small tool to just this by looking up each apex domain against the Tranco list (list of the 4.7m most common domains) and showing the rank.
It is available at github.com/AlfredBerg/d...
Created a small tool to just this by looking up each apex domain against the Tranco list (list of the 4.7m most common domains) and showing the rank.
It is available at github.com/AlfredBerg/d...