Justin Steven

323 Followers
68 Following
48 Posts
Smooth Jazz was a super cute SQL Injection challenge by hashkitten for last week’s @DownUnderCTF. It involves the careful and painful threading of three separate needles. We had so much fun solving it that I’ve written up the journey at https://www.justinsteven.com/posts/2023/09/10/ductf-2023-smooth-jazz-sqli/
DownUnderCTF 2023 - Smooth Jazz (SQL Injection)

justinsteven
The VOD of the Gartner Peer Insights widget DOM XSS bug is up! It breaks down the vuln that popped alert on Gradle, LogRhythm, SentinelOne, Synopsys, Veeam, Vodafone and more. Dive into the code, the bug, the POC, the patch and the bypass at https://youtu.be/fCNsZU0uqVs
Computer Hacking - Gartner Peer Insights widget DOM XSS

YouTube

A DOM XSS vulnerability in Gartner's Peer Insights Widget affected the sites of Gradle, LogRhythm, SentinelOne, Synopsys, Veeam, Vodafone and more. Details of the bug, the patch, the bypass, and the final patch are up at https://gartner.com.ring0.lol/

Also, when this toot is two hours old (12pm Sydney time) I'll be live at https://twitch.tv/justinsteven breaking down how I found the bug and how it all worked. If you can't make it then it'll be on YouTube in the coming days, but if you can, come say hi! ❤️

Gartner Peer Insights widget - postMessage DOM XSS vulnerability

If you enjoyed the X41 security review of Git, you might like my work from a while back. RCE via IDEs, shell prompts (including the latest oh-my-zsh), Git pillaging tools and even "git clone -> git status" (still works on modern Git in default config) https://github.com/justinsteven/advisories/blob/main/2022_git_buried_bare_repos_and_fsmonitor_various_abuses.md
advisories/2022_git_buried_bare_repos_and_fsmonitor_various_abuses.md at main · justinsteven/advisories

Contribute to justinsteven/advisories development by creating an account on GitHub.

GitHub

OK, so what does fidget mean? What information do you have around you, right now? Take a deeper look. Why is that WiFi AP named XNF998FE? Why is your laptop's serial number XY3327S? How often is that helicopter circling? Why are so many license plates from a particular state with a specific prefix? Look for the lack of entropy that is an encoded signal.

In the early Metasploit days this involved dumping function addresses of DLLs from a literal binder of DVDs. The opcode database and later analysis by folks like skape (matt miller) and spoonm made exploit development much easier as a result.

Scanning the internet is easy. Understanding all the data coming back takes a lifetime. Grab some data dumps and sift through specific protocols and fields. Toss Fiddler at a Windows thick client (or enable HTTP event tracing).

We are flooded in dodgy software, weak numeration, and information leaks. Stop for a bit, breath, pick one, and go deep.

Had this on a recent engagement and thought I'd provide a cut-down version as a fun little CTF-like challenge.

As an attacker, you can invoke `pwnme()` and control the value of `$filename` via a web request.

You cannot control the contents of the file system that this code is running on. You don't have the ability to upload files.

How do you achieve command injection?

#php #challenge

Streaming more Ghidra development in an hour! 🐉✨ After experimenting a bit yesterday, today we will be implementing a Ghidra analyzer to parse the Golang `gopclntab` to extract function definitions and improve our function discovery phase! 🦾

Come hang out and we will learn more about Ghidra, Golang and compilers together! ✨💜

https://www.twitch.tv/cyberkaida

#Ghidra #Golang #reverseengineering #VTuber #compilers

サイバーカイダ - Twitch

Hi! I'm CyberKaida, I stream reverse engineering and InfoSec stuff! I’m a cyber dragon VTuber from cyberspace here to teach meatspace humans about computers!

Twitch
Fine ok you get *another* blog post, this time about why doing on-device WebAuthn (rather than requiring a separate token) is harder in the PC world than on Macs and why Linux just doesn't have a good story here yet: https://mjg59.dreamwidth.org/62746.html
Captcha Check

Ghidra development stream in an hour! 🐉👩‍💻💫

We’ll be porting the Golang string parsing from our proof of concept script over to our analysis module so string extraction will be automatic! ✨

If we get through this we’ll start work on type extraction and parsing more Golang specific structures. We should be complete enough for a first release soon! ✨💫

https://www.twitch.tv/cyberkaida

#Ghidra #Golang #reverseengineering #VTuber #stream

サイバーカイダ - Twitch

Hi! I'm CyberKaida, I stream reverse engineering and InfoSec stuff! I’m a cyber dragon VTuber from cyberspace here to teach meatspace humans about computers!

Twitch
I've had a wicked cold this last week, and now it's time to hang up the streaming kit. I'll be back in 2023 to see how much further we can get through the Cryptopals series, but in the meantime all we've done (and much more) is at https://www.youtube.com/@JustinSteven. Get into it!
Justin Steven

Teile deine Videos mit Freunden, Verwandten oder der ganzen Welt

YouTube