
Blaklis
@blaklis_
Infosec web frenglish speaking guy. CTF player with The Flat Network Society. Security researcher & bug bounty hunter.
ID: 932281296172220423
19-11-2017 16:15:56
2,2K Tweet
10,10K Takipçi
67 Takip Edilen







Because $z->xinclude(false) doesn't prevent XInclude directives to be parsed - it actively evaluates xinclude directives :p. A few at-first-sight useless bugs that chained well to get something critical! Swisscom CSIRT even added a bonus for it, for the exploit coolness! Have a


My french team, for the world cup, and in collaboration with my wife, printed me a hoodie with a redacted payload on it. That bug was super fun, but quite hard to exploit! If encoded words, RFC2047 and so on are strange words to you, Gareth Heyes \u2028 presented at the same time their









