Antonio Francesco Sardella

38 Followers
93 Following
93 Posts
AppSec Engineer | Security Engineering Manager | Organizer of Meethack (Torino) | CTF player | he/him | ๐Ÿดโ€โ˜ ๏ธ ๐Ÿ‡ช๐Ÿ‡บ ๐Ÿ‡ฎ๐Ÿ‡น | Opinions are my own.
Websitehttps://m3ssap0.github.io
GitHubhttps://github.com/m3ssap0
LinkedInhttps://www.linkedin.com/in/antoniofrancescosardella
Meethack Torinohttps://www.meetup.com/it-IT/meethack/
Who could have figured out that automatically downloading half the internet and ten thousand always-changing dependencies every time you build could actually be a weakness?

We got this "HIGH security problem" reported for #curl earlier today:

"The -o / --output parameter in cURL does not restrict or sanitize file paths. When passed relative traversal sequences (e.g., ../../), cURL writes files outside the current working directory, allowing arbitrary file overwrite. In automated or privileged environments (CI/CD, root containers), this leads to Remote Code Execution (RCE), privilege escalation, and supply chain risk."

Never a dull moment.

This friday is Friday the 13th. The proper way to avoid the bad luck that day can cause is to push your code to production before you leave for the day.
File upload e cosa puรฒ andare storto sulla tua applicazione #cybersecurity #development #web

YouTube
DEF CON 32 - Your CI CD Pipeline Is Vulnerable, But It's Not Your Fault - Elad Pticha, Oreen Livni

YouTube
Breaking Down Multipart Parsers: File upload validation bypass

TL;DR: Basically, all multipart/form-data parsers fail to fully comply with the RFC, and when it comes to validating filenames or content uploaded by users, there are always numerous ways to bypass validation. We'll test various bypass techniques against PHP, Node.js, and Python parsers, as well as popular

Sicuranext Blog

No Hat 2024 - AWS CloudQuarry: Searching for secrets in public AMIs - Eduard Agavriloae, Matei Josephs

https://youtu.be/QYTXMJScZZk

#nohat2024 #cybersecurity #security #infosec #hacking #aws #ami #cloudsecurity #secrets #credentials #cloud #secretsleakage #leakage

No Hat 2024 - E. Agavriloae & M. Josephs - AWS CloudQuarry: Searching for secrets in public AMIs

YouTube

No Hat 2024 - Exploring and Exploiting an Android "Smart POS" Payment Terminal - Jacopo Jannone

https://youtu.be/a9BFGlxP71Y

#nohat2024 #cybersecurity #security #infosec #hacking #android #pos #payment #creditcard

No Hat 2024 - Jacopo Jannone - Exploring and Exploiting an Android โ€œSmart POSโ€ Payment Terminal

EXPLORING AND EXPLOITING AN ANDROID "SMART POS" PAYMENT TERMINALToday, credit card terminals are undergoing a drastic evolution, moving from specialized hard...

YouTube