back
user profile
pentestercrab
2,279karma·284submissions·August 11, 2015
recent activity (284 total)
comment
The second sentence of the blog post states: We were also unable to control the contents of a file on disk, and bruteforcing process identifiers (PIDs) and file descriptors found no interesting r…
comment
https://intelx.io/?did=25626760-7371-4872-be87-68c350f7baac
comment
Sounds very interesting, thanks for sharing. Do you have any more information or perhaps a URL to a write-up for this? Or do you remember the challenge name?
comment
It does not require opening a browser, it can cause a browser to open.
comment
Yes, that works fine. The hard part is finding a suitable .so already on the system. The following (credit to Tavis Ormandy) creates /tmp/testing $ RUBYOPT="-r/usr/lib64…
comment
From TFA: These vulnerabilities would have allowed an attacker who claimed the S3 bucket to offer malicious firmware updates to Linux desktops and servers running legacy versions of fwupd. Some extra …
comment
Some extra details can be found in the relevant Twitter thread[0] relating to affected Linux distributions. [0] https://twitter.com/justinsteven/status/1270113960021209088 …
comment
http://geometrylearning.com/DeepFaceDrawing/ says "[Coming Soon]" for the code.…