@postmodern We don't at the moment but happy to develop one for you if you have an idea you want to share :)
Founder/CEO/Trainer/Researcher/CVE archeologist @PentesterLab. Security engineer. Bugs are my own, not of my employer...
@postmodern We don't at the moment but happy to develop one for you if you have an idea you want to share :)
Ok, a bit early but what are your goals for 2023?
I'm surprised debirdify is still allowed to be honest.
@lcamtuf Lynxes?
Preferences -> Flavours -> Skin -> Mastodon light
People will hate me for this, but that feels already a lot more usable like this already.
Articles worth reading discovered last week:
# CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution
🗞 https://labs.nettitude.com/blog/exploiting-onlyoffice-web-sockets-for-unauthenticated-remote-code-execution/
# Technical challenges with file formats - Speaker Deck
🗞 https://speakerdeck.com/ange/technical-challenges-with-file-formats
# I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS | Spaceraccoon's Blog
🗞 https://spaceraccoon.dev/analyzing-clipboardevent-listeners-stored-xss/
# GitHub - fransr/hot-jar-swapping-urlclassloader: Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes
🗞 https://github.com/fransr/hot-jar-swapping-urlclassloader