Thank you -- hoping to get a few more blog posts out soon :)
10.06.2025 02:21 β π 4 π 0 π¬ 0 π 0Thank you -- hoping to get a few more blog posts out soon :)
10.06.2025 02:21 β π 4 π 0 π¬ 0 π 0userland ROP on day 1 πͺ
05.06.2025 08:48 β π 2053 π 324 π¬ 101 π 63
New blog post with @shubs.io:
We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely.
Full post here: samcurry.net/hacking-subaru
Documentary on Hackers Who Get Paid to Hack Companies. @CyberNews interviewed Bryce (@realytcracker), Ben (@NahamSec), Sam Curry (@zlz), Frederik (@stokfredrik), Neiko (@_specters_), Vanya (@BusesCanFly), Phoenix (LilRed), AndrΓ© (@0xacb).
16.12.2024 15:49 β π 4 π 2 π¬ 1 π 0
Did you know you can use an ancient magic cookie to downgrade parsers and bypass WAFs?! Hope you enjoy this quality bit of RFC-diving from @d4d89704243.bsky.social!
portswigger.net/research/byp...
My latest blog post is live! nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
This must be the result of the attempts
25.11.2024 18:21 β π 5 π 1 π¬ 0 π 0I'm slowly making my way there... will see where it starts giving me a bad request error as I approach 253 π
25.11.2024 07:49 β π 3 π 0 π¬ 0 π 0Yup, all parts <63. Wondering if Bluesky explicitly prevented huge usernames as a quality of life thing? π
25.11.2024 07:38 β π 1 π 0 π¬ 1 π 0Does anyone know the max size limit for Bluesky usernames? The DNS and everything resolves correctly for this (253 characters), but it seems to throw 400 bad request when I actually try to assign it.
25.11.2024 06:48 β π 27 π 1 π¬ 3 π 0