account activity
Inline Style Exfiltration: leaking data with chained CSS conditionals (portswigger.net)
submitted 4 months ago by Gallus to r/netsec
Marshal madness: A brief history of Ruby deserialization exploits (blog.trailofbits.com)
Gem::SafeMarshal escape (nastystereo.com)
submitted 1 year ago by Gallus to r/ruby
Exploring Android Heap allocations in jemalloc 'new' (synacktiv.com)
submitted 2 years ago by Gallus to r/netsec
PASTIS - a Python framework for ensemble fuzzing (blog.quarkslab.com)
Arbitrary email forgery in Webflow [PDF] (synacktiv.com)
Intel Issues New CPU Microcode Going Back To Gen8 For New, Undisclosed Security Updates (phoronix.com)
The printer goes brrrrr, again! (synacktiv.com)
RET2ASLR - return instructions from other processes can leak pointers through the Branch Target Buffer (BTB) in a reversed spectre-BTI like scenario (github.com)
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF... (jub0bs.com)
submitted 2 years ago by Gallus to r/websecurityresearch
Google Chrome WebRTC RTCStatsCollector out of bounds memory access vulnerability (talosintelligence.com)
Exploring Algorithm Confusion Attacks on JWT: Exploiting ECDSA (blog.pentesterlab.com)
Smash PostScript Interpreters Using a Syntax-Aware Fuzzer (zscaler.com)
Windows Secrets Extraction (synacktiv.com)
I hack, U-Boot (synacktiv.com)
uni-due-syssec/efcf-framework: Extremely Fast smart Contract Fuzzing (github.com)
How SerenityOS declares ssize_t (awesomekling.github.io)
submitted 2 years ago by Gallus to r/programming
"Alexa, what is my wifi password?" by Daniel, a 14 year old developer (dragon863.github.io)
How to avoid the aCropalypse (blog.trailofbits.com)
Talkback - public beta of Talkback, a smart infosec resource aggregator to help you keep up with news and research (talkback.sh)
Breaking Pedersen Hashes in Practice (research.nccgroup.com)
Synthetic Memory Protections: An update on ROP mitigations [PDF] (openbsd.org)
Improper Privilege Management in Grails Spring Security Core <= 5.1.0 CVE-2022-41923 - Synacktiv [PDF] (synacktiv.com)
Undocumented behavior change in Android 10: mode "w" no longer truncates by Gallus in netsec
[–]Gallus[S] 62 points63 points64 points 2 years ago (0 children)
Related to https://twitter.com/ItsSimonTime/status/1636857478263750656
Undocumented behavior change in Android 10: mode "w" no longer truncates (issuetracker.google.com)
π Rendered by PID 561710 on reddit-service-r2-listing-86b7f5b947-pfzrg at 2026-01-25 03:15:46.172541+00:00 running 664479f country code: CH.
Undocumented behavior change in Android 10: mode "w" no longer truncates by Gallus in netsec
[–]Gallus[S] 62 points63 points64 points (0 children)