Researcher at GitHub Security Lab. Tweets are my own. And BTW, russian warship go f.ck yourself.
ID: 929108264117325830
https://jarlob.github.io 10-11-2017 22:07:26
611 Tweet
415 Takipçi
307 Takip Edilen
NEED YOUR HELP! My Friend/Teacher Soroush (Soroush Dalili) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you
The blog.mantrainfosec.com/blog/18/prepar… post by Balazs Bucsay [EQ] shows how prepared statements can be exploited in NodeJS using mysql and mysql2 packages leading to SQLi! 🪄 So use of prepared statement might not be the ultimate solution here 🥵 as a side note, Balazs Bucsay [EQ] later found this