Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
newguy33
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
newguy33
3mo ago
Critical is an overstatement but it userland PHP execution does not equate to native process control. There are many situations where an attacker may have constrained PHP execution, gadget execution, template or plugin execution, deserializ
2.
▲
by
newguy33
3mo ago
Yea, that's what's confusing. some of these are like lower level slop but some are like genuine criticals. Floci, libssh2, c-ares, FFmpeg, and the PHP one are all LEGIT./ The Ghidra one for example, not so much. I cant help b
3.
▲
by
newguy33
3mo ago
I disagree. That FFmpeg code execution is absolutely nasty
4.
▲
by
newguy33
3mo ago
Ghidra one is pretty weak, but I checked out the ones that were interesting to me (c-ares, libssh2, ffmpeg) and they seem to all work as of the latest upstream commit. Weird