0xdf
@0xdf_
Followers
23K
Following
4K
Statuses
3K
Training Architect @ HackTheBox "Potentially a legit security researcher" he/him https://t.co/GCcLVlmdQK https://t.co/uQWVpw4nft 0xdf on discord
Joined January 2015
MagicGardens from @hackthebox_eu has a ton in it! There's a bank trick and XSS via QRcode. There's a buffer overflow via large IPv6 packet. Docker Registry, Django deserialization, and a malicious kernel module as well.
4
20
90
RT @sarperavci: Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it…
0
309
0
During #flareon11, I learned how to use a plugin to automate x64dbg with Python. In this video, I'll show how to set it up, get started, and then walk through my final tracing script.
3
44
180
Trickster from @hackthebox_eu showcases vulnerabilities in PrestaShop, ChangeDetectionIO, and Prusaslicer! In Beyond Root I'll show a ModSecurity configuration that was blocking by user-agent string.
0
13
63
RT @KartikDurg: Check out the fourth article in our Attack Anatomy series, where we dive deep into the techniques employed by Mustang Panda…
0
2
0
@Chirag99Artani @hackthebox_eu I think it requires a very specific setup. Someone has to code an application that will be vulnerable to it. You have found real world struts applications with file upload to try it on?
1
0
0
Caption from @hackthebox_eu has some really tricky by neat request smuggling and HTML injection to get XSS, bypassing HAProxy, and exploiting a thrift / Go log handler. I'll also show patched unintends using Bitbucket DB Viewer and some HAProxy bypasses.
1
28
80
MonitorsThree from @hackthebox_eu, like Monitors and MonitorsTwo, starts with an instance of Cacti. This time I'll get creds from a different site, and abuse those to get RCE. For root, I'll abuse a CVE in Duplicati. In Beyond Root, I'll dig at port 8084
0
20
83
Sightless is a fun, easy-level box from @hackthebox_eu, with a couple CVEs to exploit in SQLPad and Froxlor. I'll play with some unintended exploits in Chrome debug and Froxlor, as well as an SSRF in SQLPad.
0
21
64
Loved the new #HolidayHack format this year, releasing challenges in 4 acts! I'll hack web and JS, curl and PowerShell, hardware and mobile apps. There are two SOC / SIEM like challenges, and ransomware decryption.
0
6
16