Michael Stepankin's Avatar

Michael Stepankin

@artsploit.com.bsky.social

Security Researcher at GitHub Security Lab, ex Portswigger. https://artsploit.blogspot.com/

178 Followers  |  48 Following  |  1 Posts  |  Joined: 15.11.2024  |  1.429

Latest posts by artsploit.com on Bluesky

Post image

Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now itโ€™s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! github.blog/security/vul...

22.01.2025 18:16 โ€” ๐Ÿ‘ 28    ๐Ÿ” 16    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Remote Code Execution with Spring Properties Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...

I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy!

Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...

26.11.2024 23:57 โ€” ๐Ÿ‘ 76    ๐Ÿ” 36    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 2
Post image

How's your day going?

15.11.2024 08:53 โ€” ๐Ÿ‘ 26    ๐Ÿ” 2    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

@artsploit.com is following 20 prominent accounts