Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
pentestercrab
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
Nastystereo.com
(nastystereo.com)
1 points
by
pentestercrab
9d ago
|
0 comments
2.
▲
Ruby 4.0 Universal RCE Deserialization Gadget Chain
(elttam.com)
78 points
by
pentestercrab
1mo ago
|
22 comments
3.
▲
The Sunlight CT Log
(sunlight.dev)
1 points
by
pentestercrab
1mo ago
|
0 comments
4.
▲
Cruising for Shells in Flowise – 6 RCEs That Rode Flowise Low and Slow
(elttam.com)
1 points
by
pentestercrab
2mo ago
|
0 comments
5.
▲
by
pentestercrab
5mo ago
(63 points, 4 days ago, 431 comments) https://news.ycombinator.com/item?id=47972481
6.
▲
When Dawkins met Claude – Could this AI be conscious?
(unherd.com)
64 points
by
pentestercrab
5mo ago
|
434 comments
7.
▲
Ruby Array Pack Bleed
(nastystereo.com)
62 points
by
pentestercrab
9mo ago
|
1 comments
8.
▲
Ruby Array Pack Bleed – Impacts Ruby 1.6.7 to 4.0.0
(nastystereo.com)
9 points
by
pentestercrab
9mo ago
|
0 comments
9.
▲
Inline Style Exfiltration: leaking data with chained CSS conditionals
(portswigger.net)
1 points
by
pentestercrab
1y ago
|
0 comments
10.
▲
Marshal madness: A brief history of Ruby deserialization exploits
(blog.trailofbits.com)
25 points
by
pentestercrab
1y ago
|
4 comments
11.
▲
Breaking the Sorting Barrier for Directed Single-Source Shortest Paths
(arxiv.org)
99 points
by
pentestercrab
1y ago
|
3 comments
12.
▲
by
pentestercrab
1y ago
There seems to have been a recent uptick in phishers using goo.gl URLs. Yes, even without new URLs being accepted by registering expired domains with an old reference.
13.
▲
by
pentestercrab
1y ago
The risky.biz podcast episode got pulled too: https://bsky.app/profile/patrick.risky.biz/post/3lmioqiobks2...
14.
▲
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails
(elttam.com)
1 points
by
pentestercrab
2y ago
|
0 comments
15.
▲
Escaping Ruby's Gem:SafeMarshal Sandbox
(nastystereo.com)
2 points
by
pentestercrab
2y ago
|
1 comments
16.
▲
Escaping Ruby's Gem:SafeMarshal Sandbox
(nastystereo.com)
3 points
by
pentestercrab
2y ago
|
0 comments
17.
▲
RubyGem's Gem:SafeMarshal buffer overrun with length larger than fit into a byte
(github.com)
1 points
by
pentestercrab
2y ago
|
0 comments
18.
▲
CORS Vulnerabilities in Go: Vulnerable Patterns and Lessons
(pentesterlab.com)
1 points
by
pentestercrab
2y ago
|
0 comments
19.
▲
Shiny Vulnerabilities in R's Most Popular Web Framework
(nastystereo.com)
1 points
by
pentestercrab
2y ago
|
0 comments
20.
▲
PentesterLab: Web Hacking and Security Code Review 600 exercises and 700 videos
(pentesterlab.com)
1 points
by
pentestercrab
2y ago
|
0 comments
21.
▲
Cross-Site Post Requests Without a Content-Type Header – CSRF Attack
(nastystereo.com)
2 points
by
pentestercrab
2y ago
|
0 comments
22.
▲
Execute commands by sending JSON? Ruby deserialization vulnerabilities
(github.blog)
2 points
by
pentestercrab
2y ago
|
0 comments
23.
▲
JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review
(pentesterlab.com)
3 points
by
pentestercrab
2y ago
|
0 comments
24.
▲
Chosen-Prefix Collisions on AES-Like Hashing
(eprint.iacr.org)
2 points
by
pentestercrab
2y ago
|
0 comments
25.
▲
by
pentestercrab
2y ago
Once again GTFOBins[0] proving to be a valuable resource. [0] https://gtfobins.github.io/
26.
▲
Ruby 3.4 Universal RCE Deserialization Gadget Chain
(nastystereo.com)
2 points
by
pentestercrab
2y ago
|
1 comments
27.
▲
by
pentestercrab
2y ago
Thanks for the feedback, fixed!
28.
▲
Ruby's String Slice is Broken
(nastystereo.com)
3 points
by
pentestercrab
2y ago
|
2 comments
29.
▲
Evaluate Markdown code blocks within Vim
(github.com)
68 points
by
pentestercrab
2y ago
|
18 comments
30.
▲
SQL Injection Polyglot Payloads
(nastystereo.com)
1 points
by
pentestercrab
2y ago
|
0 comments
More ›