whira (@whira_wr) 's Twitter Profile
whira

@whira_wr

ID: 1062824306

calendar_today05-01-2013 11:48:35

80 Tweet

63 Followers

406 Following

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Read SolarWine's writeup for Hack-A-Sat finals and find out how to regain control of the satellite 🛰️, repair the sabotaged payload and finally take a shot of the moon!

Charles Fol (@cfreal_) 's Twitter Profile Photo

SplDoublyLinkedList::offsetUnset exploit. This vulnerability appeared in #PHP 5.3, and was still here in PHP 8! If you're interested in PHP exploitation, check the exploit: I had to trigger the bug a lot of times to increment a UAF'ed zend_string.len.

Lexfo (@lexfosecurite) 's Twitter Profile Photo

rpc2socks is a client-server solution developed by LEXFO that allows to drop and remotely run a custom RPC + SOCKS-through-SMB server application on a #Windows target, from a Unix or Windows host. The tool is open source and available here : github.com/lexfo/rpc2socks

Lexfo (@lexfosecurite) 's Twitter Profile Photo

#Symfony's secret fragments: Learn how a configuration problem leads to Remote code Execution on Symfony-based applications : ambionics.io/blog/symfony-s…

Ambionics Security (@ambionics) 's Twitter Profile Photo

Our Ambionics / Lexfo team chained a few bugs on Sqreen's microagent to get remote code execution on some Sqreen-protected servers. Learn how we found and exploited the vulnerabilities: ambionics.io/blog/sqreen-rce

Synacktiv (@synacktiv) 's Twitter Profile Photo

You don't want to play ball? Sometimes you don't have to! Read how Sylvain recovers pin state from BGA casings with minimal equipment: synacktiv.com/publications/p…

You don't want to play ball? Sometimes you don't have to! Read how Sylvain recovers pin state from BGA casings with minimal equipment:

synacktiv.com/publications/p…
Ambionics Security (@ambionics) 's Twitter Profile Photo

Learn how we exploited a tricky #vulnerability to get remote code execution on #Laravel #php framework, when in debug mode. ambionics.io/blog/laravel-d…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

New blogpost by Lexfo about #Danabot #Malware. Since the last blog post from Proofpoint about the version 4 of DanaBot, the new samples available integrate minor changes. This blogpost is about the differences spot between those different versions. blog.lexfo.fr/danabot-malwar…

Charles Fol (@cfreal_) 's Twitter Profile Photo

Since the title of my upcoming talk at Sthack got leaked, there's not much point hiding it anymore: I will present a Privilege Escalation bug affecting PHP-FPM. It will get patched in the upcoming days. Blogpost will follow.

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Thank you Sthack 2021 for this great event ! Our researcher Charles Fol showed how he exploited two vulnerabilities to escalate his privileges to root on #PHP-FPM. Details of the exploitation will soon follow on Ambionics Security' blog.

Thank you <a href="/sth4ck/">Sthack</a> 2021 for this great event ! Our researcher <a href="/cfreal_/">Charles Fol</a> showed how he exploited two vulnerabilities to escalate his privileges to root on #PHP-FPM. Details of the exploitation will soon follow on <a href="/ambionics/">Ambionics Security</a>' blog.
Charles Fol (@cfreal_) 's Twitter Profile Photo

Tomorrow, #php 8.0.12 gets released, patching CVE-2021-21703. This is a Local Root vulnerability on PHP-FPM. If you're using #nginx and PHP, you ARE using PHP-FPM. If you're using #apache, you MIGHT BE using PHP-FPM. Patch your systems.

Ambionics Security (@ambionics) 's Twitter Profile Photo

Read the details about #CVE-2021-21703 on our Ambionics' blog, a 10 year-old Local Root vulnerability affecting PHP-FPM, #PHP FastCGI's server. PHP-FPM is often used with major HTTPd servers such as #NGINX and #Apache. ambionics.io/blog/php-fpm-l…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

New blogpost available ! This article is a step-by-step guide to #reverse an APK protected with #DexGuard using Jadx : blog.lexfo.fr/dexguard.html

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Learn how we discovered 5 distinct vulnerabilities on WatchGuard #Firebox/#XTM firewalls, and obtained a pre-auth Remote Code Execution as root #0day (CVE-2022-31789, CVE-2022-31790). ambionics.io/blog/hacking-w…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

Introducing sshimpanzee, a reverse shell made by Titouan Lazard based on openssh's sshd. It supports DNS, ICMP and HTTP encapsulation as well as SOCKS and HTTP Proxies : blog.lexfo.fr/sshimpanzee.ht…

Lexfo (@lexfosecurite) 's Twitter Profile Photo

#Fortinet patched #CVE-2023-27997, a critical vulnerability affecting its VPN #Fortigate. Our latest blogpost describes the technical details about the bug, a pre-auth heap overflow, with a twist. #xortigate blog.lexfo.fr/xortigate-cve-…

Tavis Ormandy (@taviso) 's Twitter Profile Photo

First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! lock.cmpxchg8b.com/zenbleed.html

Lexfo (@lexfosecurite) 's Twitter Profile Photo

🔔 New research from Lexfo on pre- & post-authentication vulnerabilities in WSO2 products — uncovering bypasses, RCE, SSRF, CSRF, and account-takeover risks. See our detail article → blog.lexfo.fr/wso2.html #cybersecurity #infosec #offensivesecurity #pentest #WSO2