Charles Fol (@cfreal_) 's Twitter Profile
Charles Fol

@cfreal_

previously @ambionics @LexfoSecurite
– blogs: ambionics.io/blog blog.lexfo.fr cfreal.github.io

ID: 1020272903529684993

linkhttps://ambionics.io/blog calendar_today20-07-2018 11:43:10

263 Tweet

4,4K Followers

656 Following

Ambionics Security (@ambionics) 's Twitter Profile Photo

We're proud to announce LIGHTYEAR, a tool that let you dump files, blind, in PHP, based on a new algorithm. ambionics.io/blog/lightyear…

Charles Fol (@cfreal_) 's Twitter Profile Photo

LIGHTYEAR: - Can dump large files, even through a GET parameter - Retrieves characters using dichotomy - Does not cause PHP warnings

Luke Jahnke (@lukejahnke) 's Twitter Profile Photo

🧵My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! nastystereo.com/security/ruby-…

🧵My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE!

nastystereo.com/security/ruby-…
Charles Fol (@cfreal_) 's Twitter Profile Photo

This year again, I am lucky enough to get nominated twice for the Top Ten Hacking Techniques, for my research on iconv and PHP, and lightyear. This time feels a bit special however, as these are my last blog posts on Ambionics Security. ambionics.io/blog/iconv-cve… ambionics.io/blog/lightyear…

PT SWARM (@ptswarm) 's Twitter Profile Photo

🔥 The "impossible" XXE in PHP? Not so impossible anymore. Our researcher Aleksandr Zhurnakov discovered an interesting combination of PHP wrappers and a feature of XML parsing in libxml2 to exploit it. Read: swarm.ptsecurity.com/impossible-xxe…

🔥 The "impossible" XXE in PHP? Not so impossible anymore.

Our researcher Aleksandr Zhurnakov discovered an interesting combination of PHP wrappers and a feature of XML parsing in libxml2 to exploit it.

Read: swarm.ptsecurity.com/impossible-xxe…
Airbus Security Lab (@airbusseclab) 's Twitter Profile Photo

Passionate about hacking & cybersecurity? Airbus is looking for a Vulnerability Research & Exploitation Specialist in France! 💻 Reverse engineering, Red Teaming ✈️Join a global aerospace & defense leader Apply now! 🚀 ag.wd3.myworkdayjobs.com/en-US/Airbus/j…

Phith0n (@phithon_xg) 's Twitter Profile Photo

#vulhub #CyberSecurity #opensource #infosec Announcing some exciting news from the Vulhub project! We've been busy making big improvements: 1⃣. Completely rebuilt our website from the ground up! Check it out: vulhub.org

#vulhub #CyberSecurity #opensource #infosec 
Announcing some exciting news from the Vulhub project! We've been busy making big improvements:
1⃣. Completely rebuilt our website from the ground up! Check it out: vulhub.org
Caitlin Condon (@catc0n) 's Twitter Profile Photo

The subtitle of this blog is "a plea to security news outlets to please do their due diligence before slapping 'exploited in the wild' headlines on new CVEs" rapid7.com/blog/post/2025…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Synacktiv is looking for an additional team leader in Paris for its Reverse-Engineering Team! Find out if you are a good candidate by reading our offer (🇫🇷). synacktiv.com/responsable-eq…

¯\_(ツ)_/¯ (@chocapikk_) 's Twitter Profile Photo

🚨 New unauthenticated #RCE module for vBulletin 5.1.0-6.0.3 landed in Metasploit! No CVE assigned, but credit to Egidio Romano (EgiX) for the original write-up: karmainsecurity.com/dont-call-that… 🔗 PR: github.com/rapid7/metaspl…

🚨 New unauthenticated #RCE module for vBulletin 5.1.0-6.0.3 landed in Metasploit! No CVE assigned, but credit to Egidio Romano (EgiX) for the original write-up: karmainsecurity.com/dont-call-that…

🔗 PR: github.com/rapid7/metaspl…
Alain M. (@plopz0r) 's Twitter Profile Photo

Just finished my talk at #securityfest, you can find all the details in my latest blog post: blog.scrt.ch/2025/06/04/son…

Charles Fol (@cfreal_) 's Twitter Profile Photo

lightyear just got 6 times faster! Although I now work at Synacktiv, I proposed a PR for the tool to support threading and compression, greatly reducing the time required to dump a file. Dumping the demo /etc/passwd now takes 48s instead of 5m30. github.com/ambionics/ligh…

GrapheneOS (@grapheneos) 's Twitter Profile Photo

This article by Nicolas Stefanski at Synacktiv provides a high quality technical overview of our hardened_malloc project used in GrapheneOS: synacktiv.com/en/publication… It has great coverage of the memory layout, memory tagging integration, slab quarantines and allocation approach.

Lexfo (@lexfosecurite) 's Twitter Profile Photo

🔔 New research from Lexfo on pre- & post-authentication vulnerabilities in WSO2 products — uncovering bypasses, RCE, SSRF, CSRF, and account-takeover risks. See our detail article → blog.lexfo.fr/wso2.html #cybersecurity #infosec #offensivesecurity #pentest #WSO2