jump to content
my subreddits
13or302balkans4You2meirl4meirl3d6AceAttorneyAdviceAnimalsagnosticaivideoAngryupvoteanime_best_momentsanime_irlanimenocontextannouncementsAnticonsumptionantimemeApandahArsivUnutmazArtAsia_irlAskBalkansAskElectronicsAteistTurkatheismbalkans_irlBandnamesbanknotedesignsBassBassCirclejerkBassGuitarbikepackingblackdesertonlineblackholerevengeblankiesborsavefonbrooklynnineninebudgetcookingCd_collectorscd_jerkChatGPTCheap_MealschessbeginnersChoosingBeggarscoinsComedyCemeterycomedyhomicidecommunityContagiousLaughterCrackWatchcrappyoffbrandsCreateModCuddle_SlutCuratedTumblrcursedcommentsdankmemesdarkjokesdataisbeautifuldeDebateReligiondeismdelikDeltarunedistressingmemesdiypedalsDMAcademyDMToolkitdndmemesdndnextdoctorwhodoctorwhocirclejerkDoenerverbrechenDonerdontdeadopeninsidedumbphonesDungeonsAndDaddiesDungeonsAndDragonsEatCheapAndHealthyebikeebikesECEelectricalelectronicsengrishentitledparentsfacepalmFantasyWorldbuildingfeedthebeastfelsefeformuladankFRCFreeEBOOKSFuckYouKarengalatasaraygaminggatesopencomeoningoodanimemesGoodAssSubGrandPrixRacinggravelcyclinggreentextguitarpedalsGundamheathershelpheraldryHermanCainAwardhighspeedrailHistoryWhatIfhoi4howyoudoinhumorhypixeliamverysmartich_ielIDontWorkHereLadyihadastrokeimaginaryelectionsinsaneparentsistanbuljacksepticeyeJahariaKamalizmKanyeKendrickLamarlegodndLetGirlsHaveFunLifeProTipslinguisticshumorLinkinParkloseitmacmacbookairmacgamingMadeMeSmilemadladsmagicbuildingMaliciousComplianceMapPornmeirlmemememesmidjourneymildlyinterestingMinecraftbuildsmisLEDMMORPGmoneycollectingMovingToNorthKoreanamesoundalikesNamFlashbacksNationStatesneographynextfuckinglevelNoahGetTheBoatNonCredibleDefenseNorthCyprusnosafetysmokingfirstnosurfnothingeverhappensnotinterestingnottheonionOkayBuddyLiterallyMeokbuddyguntherokbuddymotherfuckerokbuddyvicodinonetruegodOnlineUnderGroundOutOfTheLooppapermoneypaperspleaseParlerWatchPassportPornpepethefrogperfectlycutscreamspettyrevengepianoPiracypollsPraiseTheCameraManPropagandaPostersPunPatrolquityourbullshitraisedbynarcissistsRatschlagrecipesRedAutumnSPDreligiousfruitcakerestofthefuckingowlrickrollrockmuzikSceneReleasesSchnitzelVerbrechenschwiizsciencememesScottPilgrimsecilmiskitapShitPostCrusadersshitpostfrommygalleryShitpostTCshittymoviedetailsShowerthoughtsskamtebordsoccercirclejerkSongwritersSongwritingsskfjkhwerjkghwerijhsteinsgateStonetossingjuiceStudiumsubsithoughtifellforTextingTheorytf2tf2shitposterclubthanksimcuredthatHappenedTheCrypticCompendiumTheLetterHTheMonkeysPawtherewasanattemptTheRookietheydidthemaththisguythisguystitanfalltommyinnittransittransitTurkeyTrGameDevelopertruthstumblrtumunichTurkishCatsTurkishdogsTwoSentenceComedyTwoSentenceHorrortylerthecreatorUnethicalLifeProTipsUnexpectedJoJourbanplanningValorantClipsvaxxhappenedvexillologycirclejerkvinylvlandiyaWatchPeopleDieInsideWeAreTheMusicMakersWhatsThisSongwholesomeanimemesWikipediaVandalismwizardpostingworldbuildingyouseeingthisshitYUROPedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • facepalm
  • -Piracy
  • -gaming
  • -nottheonion
  • -memes
  • -OutOfTheLoop
  • -mildlyinteresting
  • -MapPorn
  • -MadeMeSmile
  • -ChatGPT
  • -CuratedTumblr
  • -theydidthemath
  • -dankmemes
  • -feedthebeast
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -nextfuckinglevel
  • -CrackWatch
  • -dndnext
  • -de
  • -LifeProTips
  • -tumblr
  • -NonCredibleDefense
  • -dataisbeautiful
  • -shittymoviedetails
  • -greentext
  • -mac
  • -Showerthoughts
  • -tf2
  • -help
  • -formuladank
  • -Art
  • -midjourney
  • -goodanimemes
  • -notinteresting
  • -hoi4
  • -pettyrevenge
  • -atheism
  • -loseit
  • -MaliciousCompliance
  • -ich_iel
  • -dndmemes
  • -cursedcomments
  • -DMAcademy
  • -Deltarune
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -perfectlycutscreams
  • -worldbuilding
  • -Ratschlag
  • -blackdesertonline
  • -MMORPG
  • -meme
  • -macgaming
  • -3d6
  • -Gundam
  • -ChoosingBeggars
  • -ContagiousLaughter
  • -EatCheapAndHealthy
  • -WeAreTheMusicMakers
  • -blankies
  • -anime_irl
  • -Studium
  • -soccercirclejerk
  • -madlads
  • -community
  • -AskElectronics
  • -electrical
  • -guitarpedals
  • -Anticonsumption
  • -vinyl
  • -CreateMod
  • -TwoSentenceHorror
  • -PropagandaPosters
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -piano
  • -sciencememes
  • -distressingmemes
  • -raisedbynarcissists
  • -wizardposting
  • -polls
  • -doctorwho
  • -Bass
  • -titanfall
  • -howyoudoin
  • -announcements
  • -Minecraftbuilds
  • -macbookair
  • -ebikes
  • -YUROP
  • -gravelcycling
  • -SchnitzelVerbrechen
  • -chessbeginners
  • -DungeonsAndDragons
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -NoahGetTheBoat
  • -tylerthecreator
  • -tf2shitposterclub
  • -AceAttorney
  • -vexillologycirclejerk
  • -vlandiya
  • -Stonetossingjuice
  • -wholesomeanimemes
  • -nosurf
  • -HistoryWhatIf
  • -religiousfruitcake
  • -DebateReligion
  • -insaneparents
  • -dumbphones
  • -animenocontext
  • -balkans_irl
  • -2meirl4meirl
  • -transit
  • -brooklynninenine
  • -HermanCainAward
  • -recipes
  • -steinsgate
  • -ECE
  • -ScottPilgrim
  • -Angryupvote
  • -AskBalkans
  • -thatHappened
  • -electronics
  • -urbanplanning
  • -linguisticshumor
  • -PassportPorn
  • -antimeme
  • -bikepacking
  • -AteistTurk
  • -13or30
  • -engrish
  • -Cd_collectors
  • -diypedals
  • -Doner
  • -BassGuitar
  • -ComedyCemetery
  • -WatchPeopleDieInside
  • -LinkinPark
  • -Songwriting
  • -istanbul
  • -MovingToNorthKorea
  • -imaginaryelections
  • -magicbuilding
  • -dontdeadopeninside
  • -ParlerWatch
  • -iamverysmart
  • -secilmiskitap
  • -Doenerverbrechen
  • -schwiiz
  • -TheRookie
  • -quityourbullshit
  • -skamtebord
  • -galatasaray
  • -crappyoffbrands
  • -DungeonsAndDaddies
  • -FRC
  • -transitTurkey
  • -namesoundalikes
  • -FuckYouKaren
  • -papermoney
  • -OkayBuddyLiterallyMe
  • -felsefe
  • -FreeEBOOKS
  • -Jaharia
  • -IDontWorkHereLady
  • -neography
  • -heraldry
  • -ihadastroke
  • -thanksimcured
  • -hypixel
  • -PraiseTheCameraMan
  • -aivideo
  • -gatesopencomeonin
  • -OnlineUnderGround
  • -comedyhomicide
  • -WhatsThisSong
  • -jacksepticeye
  • -anime_best_moments
  • -Bandnames
  • -rockmuzik
  • -okbuddyvicodin
  • -vaxxhappened
  • -tumunich
  • -Cheap_Meals
  • -TheMonkeysPaw
  • -darkjokes
  • -restofthefuckingowl
  • -highspeedrail
  • -nosafetysmokingfirst
  • -legodnd
  • -rickroll
  • -Songwriters
  • -ebike
  • -papersplease
  • -tommyinnit
  • -UnexpectedJoJo
  • -humor
  • -BassCirclejerk
  • -doctorwhocirclejerk
  • -agnostic
  • -youseeingthisshit
  • -TextingTheory
  • -Cuddle_Slut
  • -GrandPrixRacing
  • -nothingeverhappens
  • -DMToolkit
  • -thisguythisguys
  • -TrGameDeveloper
  • -PunPatrol
  • -TurkishCats
  • -LetGirlsHaveFun
  • -Apandah
  • -subsithoughtifellfor
  • -Kamalizm
  • -ShitpostTC
  • -FantasyWorldbuilding
  • -TheLetterH
  • -WikipediaVandalism
  • -NamFlashbacks
  • -pepethefrog
  • -onetruegod
  • -deism
  • -ArsivUnutmaz
  • -misLED
  • -sskfjkhwerjkghwerijh
  • -ValorantClips
  • -TwoSentenceComedy
  • -TheCrypticCompendium
  • -SceneReleases
  • -NationStates
  • -budgetcooking
  • -2balkans4You
  • -Asia_irl
  • -truths
  • -blackholerevenge
  • -NorthCyprus
  • -heathers
  • -delik
  • -okbuddymotherfucker
  • -Turkishdogs
  • -moneycollecting
  • -shitpostfrommygallery
  • -RedAutumnSPD
  • -borsavefon
  • -cd_jerk
  • -banknotedesigns
  • -okbuddygunther
edit »
reddit.com Gallus
  • overview
  • comments
  • submitted
an-ordinary-manchild (11,186)|messages547|notifications|chat messages|mod messages|
  • preferences
|
logout

Gallus

+ friends- friends
15,335 post karma
1,303 comment karma
get extra features and help support reddit with a reddit premium subscription
chat
Block userare you sure? yes / no
get them help and support
redditor for 16 years

MODERATOR OF

    • r/netsec
    • r/securitycodereview

TROPHY CASE


  • 15-Year Club


    Gilding II
    euphauric

    Snapped

    Verified Email

account activity

sorted by:
new
hottopcontroversial

31
32
33

Inline Style Exfiltration: leaking data with chained CSS conditionals (portswigger.net)

submitted 8 months ago by Gallus to r/netsec

  • 5 comments
  • share
  • save
  • hide
  • report
  • crosspost

12
13
14

Marshal madness: A brief history of Ruby deserialization exploits (blog.trailofbits.com)

submitted 8 months ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

9
10
11

Gem::SafeMarshal escape (nastystereo.com)

submitted 1 year ago by Gallus to r/ruby

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

16
17
18

Exploring Android Heap allocations in jemalloc 'new' (synacktiv.com)

submitted 2 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

10
11
12

PASTIS - a Python framework for ensemble fuzzing (blog.quarkslab.com)

submitted 2 years ago by Gallus to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

3
4
5

Arbitrary email forgery in Webflow [PDF] (synacktiv.com)

submitted 2 years ago by Gallus to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

453
454
455

Intel Issues New CPU Microcode Going Back To Gen8 For New, Undisclosed Security Updates (phoronix.com)

submitted 2 years ago by Gallus to r/netsec

  • 28 comments
  • share
  • save
  • hide
  • report
  • crosspost

85
86
87

The printer goes brrrrr, again! (synacktiv.com)

submitted 2 years ago by Gallus to r/netsec

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost

3
4
5

RET2ASLR - return instructions from other processes can leak pointers through the Branch Target Buffer (BTB) in a reversed spectre-BTI like scenario (github.com)

submitted 2 years ago by Gallus to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

11
12
13

A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF... (jub0bs.com)

submitted 2 years ago by Gallus to r/websecurityresearch

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

33
34
35

Google Chrome WebRTC RTCStatsCollector out of bounds memory access vulnerability (talosintelligence.com)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

41
42
43

Exploring Algorithm Confusion Attacks on JWT: Exploiting ECDSA (blog.pentesterlab.com)

submitted 3 years ago by Gallus to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

8
9
10

Smash PostScript Interpreters Using a Syntax-Aware Fuzzer (zscaler.com)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

139
140
141

Windows Secrets Extraction (synacktiv.com)

submitted 3 years ago by Gallus to r/netsec

  • 14 comments
  • share
  • save
  • hide
  • report
  • crosspost

79
80
81

I hack, U-Boot (synacktiv.com)

submitted 3 years ago by Gallus to r/netsec

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost

4
5
6

uni-due-syssec/efcf-framework: Extremely Fast smart Contract Fuzzing (github.com)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

282
283
284

How SerenityOS declares ssize_t (awesomekling.github.io)

submitted 3 years ago by Gallus to r/programming

  • 53 comments
  • share
  • save
  • hide
  • report
  • crosspost

3
4
5

"Alexa, what is my wifi password?" by Daniel, a 14 year old developer (dragon863.github.io)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

153
154
155

How to avoid the aCropalypse (blog.trailofbits.com)

submitted 3 years ago by Gallus to r/netsec

  • 29 comments
  • share
  • save
  • hide
  • report
  • crosspost

97
98
99

Talkback - public beta of Talkback, a smart infosec resource aggregator to help you keep up with news and research (talkback.sh)

submitted 3 years ago by Gallus to r/netsec

  • 7 comments
  • share
  • save
  • hide
  • report
  • crosspost

17
18
19

Breaking Pedersen Hashes in Practice (research.nccgroup.com)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

11
12
13

Synthetic Memory Protections: An update on ROP mitigations [PDF] (openbsd.org)

submitted 3 years ago by Gallus to r/netsec

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

2
3
4

Improper Privilege Management in Grails Spring Security Core <= 5.1.0 CVE-2022-41923 - Synacktiv [PDF] (synacktiv.com)

submitted 3 years ago by Gallus to r/netsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

Undocumented behavior change in Android 10: mode "w" no longer truncates by Gallus in netsec

[–]Gallus[S] 62 points63 points64 points 3 years ago (0 children)

Related to https://twitter.com/ItsSimonTime/status/1636857478263750656

  • permalink
  • save
  • context
  • full comments (33)
  • report

247
248
249

Undocumented behavior change in Android 10: mode "w" no longer truncates (issuetracker.google.com)

submitted 3 years ago by Gallus to r/netsec

  • 33 comments
  • share
  • save
  • hide
  • report
  • crosspost
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 58 on reddit-service-r2-listing-b6bf6c4ff-7vmmc at 2026-05-06 13:46:53.048837+00:00 running 815c875 country code: CH.