An Trinh (@_tint0) 's Twitter Profile
An Trinh

@_tint0

ID: 720254228128632833

linkhttps://tint0.com calendar_today13-04-2016 14:16:04

23 Tweet

1,1K Followers

250 Following

An Trinh (@_tint0) 's Twitter Profile Photo

Great usage of the xpath attack vector in xmlsec. A powerful deserialization bug and an ssrf in the public interface to break yet another SSO product. Beautiful stuff!

An Trinh (@_tint0) 's Twitter Profile Photo

Great work Khoa! Neat trick exploiting the content handler feature. Always love the feeling a research being appreciated and more research made.

Calif (@calif_io) 's Twitter Profile Photo

In a recent engagement, we encountered a target running CraftCMS, and discovered a Remote Code Execution vulnerability that allowed us to compromise the target. blog.calif.io/p/craftcms-rce CC yeuchimse

Calif (@calif_io) 's Twitter Profile Photo

New blog post: in a recent engagement, we turned a simple XSRF in Argo CD to a shell with cluster admin privileges. No fix is available. We recommend hosting Argo CD on an isolated domain. Details: blog.calif.io/p/argo-cd-csrf

Calif (@calif_io) 's Twitter Profile Photo

Wormable Substack XSS: blog.calif.io/p/wormable-sub… It must have been years since the last time a wormable XSS was found in a major social media website. This beautiful type confusion XSS attack vector is a gift that keeps on giving. But most of all, samy kamkar is our hero!