maitai's Avatar

maitai

@maitai.bsky.social

BSc Computer Science Engineering | 24 | Trying to find my way ~ 🍭 http://blig.one

50 Followers  |  225 Following  |  3 Posts  |  Joined: 22.08.2023
Posts Following

Posts by maitai (@maitai.bsky.social)

Preview
Decoding RFID: A comprehensive overview of security, attacks, and the latest innovations WHY2025 RFID reverse engineering has seen significant advancements, yet a comprehensive overview of the field remains scattered across research and practitioner communities. Here the authors presents a struc...

πŸ”₯ The future of RFID hacking isn’t dead, its even more...

At #WHY2025, Kirils and I are breaking down current RFID hacking situation

No fluff. Just spilling the beans.

πŸ—“οΈ 9th of August 13:00 at Andromeda
πŸ”— cfp.why2025.org/why2025/talk...

RT if you’re ready.

13.07.2025 14:40 β€” πŸ‘ 6    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Post image Post image Post image Post image

ζœˆη«γ§ε²‘ε±±ζ—…θ‘Œγ«θ‘Œγ£γ¦γ„γŸ θ²·γ£γ¦γγŸγγ³γ γ‚“γ”γŒγŠγ„γ—γ„

18.04.2025 09:03 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 1

Took me a while, but here is the full article!

If you want to see some weird URL parsing behavior, here you can find a lot of them :)

sec.leonardini.dev/blog/playing...

Disclaimer: no exploits nor vulnerabilities in this post, just some broken code

28.02.2025 20:49 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

This article on Solr and its (in)security is really good πŸ’Ž

And I strongly recommend to read @hacefresko.com previous article on Solr before diving in this one (I will share the link in my reply)

07.03.2025 20:32 β€” πŸ‘ 14    πŸ” 4    πŸ’¬ 2    πŸ“Œ 0
Preview
WezTerm - Wez's Terminal Emulator Wez's Terminal Emulator

@suidpit.bsky.social wezterm.org

07.03.2025 11:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

For this challenge, it was necessary to abuse a discrepancy between the DOM and the rendered page in Firefox's cache handling πŸ’½

πŸ‘‰ bugzilla.mozilla.org/show_bug.cgi...

This allows to shift iframe rendering from one to another leading to a sandbox bypass πŸ”₯

πŸ‘‰ mizu.re/post/an-18-y...

02.03.2025 17:14 β€” πŸ‘ 9    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

@hextreeio.bsky.social πŸ‘€

25.02.2025 20:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Bro is writing malware but also a Mad Max supervillian

15.02.2025 18:00 β€” πŸ‘ 41    πŸ” 5    πŸ’¬ 1    πŸ“Œ 1

AMD published Security Bulletin AMD-SB-7027 addressing CVE-2024-0179 and CVE-2024-21925, the two UEFI SMM vulnerabilities disclosed in our blog post.
Data center, desktop, mobile and embedded processors products are affected:
www.amd.com/en/resources...

13.02.2025 14:35 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Gaining kernel code execution on an MTE-enabled Pixel 8 In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulne...

Happy Friday folks! Here is a throwback to our 2nd most popular research post of 2024, "Gaining kernel code execution on an MTE-enabled Pixel 8" by Man yue Mo github.blog/security/vul...

14.02.2025 11:04 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
a laptop running memtest86+, showing two errors. a wire pokes out from the lower edge of the laptop, annotated as "antenna wire". an orange cigarette/barbecue lighter sits next to it, annotated as "elite hacking tool"

a laptop running memtest86+, showing two errors. a wire pokes out from the lower edge of the laptop, annotated as "antenna wire". an orange cigarette/barbecue lighter sits next to it, annotated as "elite hacking tool"

Can you get root with only a cigarette lighter?

(Yes!)

www.da.vidbuchanan.co.uk/blog/dram-em...

07.10.2024 13:05 β€” πŸ‘ 400    πŸ” 81    πŸ’¬ 15    πŸ“Œ 11
Post image

I keep coming across all these "pseudocode" examples on Wikipedia and in academic papers, and what I don't understand is why the authors can't just learn a real programming language

06.02.2025 19:49 β€” πŸ‘ 78    πŸ” 7    πŸ’¬ 13    πŸ“Œ 1
Post image

Hype!

05.02.2025 21:10 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Flatt Security XSS Challenge - Writeup | maitai's blog

If you are interested in client-side hacking and browser quirks I strongly recommend going through this writeup by @maitai.bsky.social!
It was also cool to collab w/ him on the second chall πŸ€œπŸΏπŸ€›πŸ»
blig.one/2024/11/29/f...

30.11.2024 06:20 β€” πŸ‘ 13    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Preview
Top 10 web hacking techniques of 2024 Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...

04.02.2025 15:02 β€” πŸ‘ 66    πŸ” 36    πŸ’¬ 2    πŸ“Œ 5