Louis Nyffenegger :verified:

Founder/CEO/Trainer/Researcher/CVE archeologist @PentesterLab. Security engineer. Bugs are my own, not of my employer...

Louis Nyffenegger :verified:snyff@infosec.exchange
2024-02-17

@postmodern We don't at the moment but happy to develop one for you if you have an idea you want to share :)

Louis Nyffenegger :verified:snyff@infosec.exchange
2022-12-19

Ok, a bit early but what are your goals for 2023?

Louis Nyffenegger :verified:snyff@infosec.exchange
2022-12-18

I'm surprised debirdify is still allowed to be honest.

Louis Nyffenegger :verified:snyff@infosec.exchange
2022-12-18

@lcamtuf Lynxes?

Louis Nyffenegger :verified:snyff@infosec.exchange
2022-12-18

@real_sag_astar

Preferences -> Flavours -> Skin -> Mastodon light

Louis Nyffenegger :verified:snyff@infosec.exchange
2022-12-18

People will hate me for this, but that feels already a lot more usable like this already.

Mastodon in light mode
Louis Nyffenegger :verified: boosted:
PentesterLab :verified:PentesterLab@infosec.exchange
2022-12-18

Articles worth reading discovered last week:

# CVE-2021-43444 to 43449: Exploiting ONLYOFFICE Web Sockets for Unauthenticated Remote Code Execution
🗞 labs.nettitude.com/blog/exploi

# Technical challenges with file formats - Speaker Deck
🗞 speakerdeck.com/ange/technical

# I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS | Spaceraccoon's Blog
🗞 spaceraccoon.dev/analyzing-cli

# GitHub - fransr/hot-jar-swapping-urlclassloader: Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes
🗞 github.com/fransr/hot-jar-swap

#PentesterLabWeekly

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst