pritch
@elpritchos
just wanna htp and control eip!
ID: 775212452619235328
12-09-2016 06:00:26
154 Tweet
150 Followers
300 Following
Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confus… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code
I'm doing a talk at the OWASP Brisbane meetup on the 18th of November on Code Review, JWT, Golang... It's going to be a lot of fun and I will bring swag and stickers! meetup.com/brisbane-owasp…
I just published a new blog post sharing an improved Deserialization Gadget Chain for Ruby! It builds on the work of others, including Leonardo Giovanni, Peter Stöckli GitHub Security Lab and William Bowling @[email protected] nastystereo.com/security/ruby-…
The detailed version of our #WorstFit attack is available now! 🔥 Check it out! 👉 blog.orange.tw/posts/2025-01-… cc: splitline 👁️🐈⬛
The Fetch API supports Blob objects as request bodies, not just strings! Blobs can omit a type, enabling cross-site POST requests without a Content-Type header. Even with non-empty bodies, the Blob's data becomes the request body! (credit: Luke Jahnke)