Rule 1๏ธโฃ : "In WAF we (should not) trust"
Your WAF is doing its best. That's just not enough ๐ฎโ๐จ
A deep dive into Web Application Firewall bypass techniques, discovering why blocked โ doesn't always mean safe.
| website | https://quarkslab.com |
| location | Paris, France |
Rule 1๏ธโฃ : "In WAF we (should not) trust"
Your WAF is doing its best. That's just not enough ๐ฎโ๐จ
A deep dive into Web Application Firewall bypass techniques, discovering why blocked โ doesn't always mean safe.
"Intego X9: Never trust my updates"
Read @coiffeur0x90's research showing how XPC interprocess communications and the update mechanism of the Intego antivirus for MacOS can be abused for local privilege escalation.
"How does it even work?"
The question that keeps hackers' hearts pumping, blood pressure rising, and curiosity growing.
This is @virtualabs's reverse engineering journey into a cheap smartwatch that measures at least one of those.
https://blog.quarkslab.com/nerd-life-weeks-firmware-teardown-we-were-right.html
If you glitch one, can you glitch many?
Extracting automotive firmware is a challenge.
@Phil_BARR3TT explains how he bypassed the IDCODE protection in several variants of the RH850 MCU family using both voltage glitching and side-channel analysis โก๏ธ๐
Another antivirus ๐ก๏ธ, another unfulfilled promise ๐ฃ. @kaluche_ turns Avira's protection into a privilege escalation playground. This time: not 1, not 2, but 3 LPE vectors ๐ via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749).
Find out more: https://blog.quarkslab.com/avira-deserialize-delete-and-escalate-the-proper-way-to-use-an-av.html
Why macOS AVs shouldnโt trust PIDs ๐๐ - new post by @Coiffeur0x90
Intego X9: XPC validation falls back to PID โ PID reuse + posix_spawn() shenanigans ๐ โ confused deputy / privileged methods abused ๐คก๐งจ
Lesson: PID โ identity.
Check it out ๐ https://blog.quarkslab.com/intego_lpe_macos_2.html
You've never been more right to doubt your MacOS antivirus software ๐ฅ
Our latest research by @coiffeur0x90 shows how Intego can be abused for Local Privilege Escalation
Yes, the antivirus.
Yes, as root.
"Dr. Bytecode or: How I Learned to Stop Worrying and Obfuscate Java"
A tale about how @farenain started his journey in Java software obfuscation.
https://blog.quarkslab.com/how-to-write-your-first-obfuscator-of-java-bytecode.html