Michael Roland (@_mroland) 's Twitter Profile
Michael Roland

@_mroland

Security researcher at @insjku/@jkulinz
Now on infosec.exchange/@mroland

ID: 2706979884

linkhttps://www.mroland.at/ calendar_today04-08-2014 17:11:44

200 Tweet

195 Takipçi

128 Takip Edilen

Michael Roland (@_mroland) 's Twitter Profile Photo

Steak house can't be far when a sign warns you of cattle on the road ........................................................................................ and there it is ;-)

Michael Roland (@_mroland) 's Twitter Profile Photo

Wie man alle OWASP Top 10 abkassiert! Heute haben wir auf der IKT-Sikon erste Details zu CVE-2023-3654/3655/3656 präsentiert. Kompletter Report doi.org/10.35011/ww2q-… tl;dr wir wurden unfreiwillig zu ehrenamtlichen Admins auf hundeten Registrierkassen in der Gastronomie.

Mario Kahlhofer (@blu3r4y_at) 's Twitter Profile Photo

Here is the write-up of the full exploit - explaining the XSS vulnerability, the CSP bypass with a JPEG/JS polyglot, stealing browser cookies, and finally exploiting an XXE in the admin panel to read arbitrary files from the victim server. (5/5) sigflag.at/blog/2023/writ…