The Secret Life of a Bug Bounty Hunter – Frans Rosén @ Security Fest …
Frans Rosén has reported hundreds of security issues using his big white hat since 2012. He have recieved the biggest bounty ever paid on HackerOne, and is one…
From Serialized to Shell :: Exploiting Google Web Toolkit with EL Injection
This is a follow up blog post to my previous post on auditing Google Web Toolkit (GWT). Today we are going to focus on a specific vulnerability that I found ...
Hi, this is my first (and last?) blog post in English. Sorry if there's any grammatical mistake, I'm not too fluent in English. Today, I'll write about ePub file with some of my findings in ePub readers. So What's ePub file? EPUB is an e-book file format with the extension .epub that can be downloaded and read on devices like smartphones, tablets, computers, or e-readers. And in technical implementation An EPUB file is a ZIP archive that contains, in effect, a website—including HTML files, images, CSS style sheets, and other assets. It also contains metadata. EPUB 3 is the latest version....
This book reads you - exploiting services and readers that support the ePub
“We use the ePub format - it is the most popular open book format in the world. We’re very excited about this.” - Steve Jobs, 2010 (original iPad launch)
Reversing the Balong M3/MCU Console – Lightning the Path to Ring 0 | Advanc
Note: I’ve done some more work since this was written. You can find updates here, and a complete compromise here. This weekend, I spent some time continuing my investigation of a Huawei E5573…
#243470 another local file disclosure via ffmpeg - HackerOne
### Summary The fix for https://hackerone.com/reports/242831 can be easily bypassed. It looks like you've banned `file://` substring, which is not enough. ### Repro steps 1. Download `gen_avi.py`...
"Connect all the things!" is, for some time now, the main theme when talking about IoT devices, solutions and products. Our eagerness to find new, at times - i…