Mon 04 November 2024
In this blog post, we describe new techniques to dump PHP files leveraging filters, and a tool that does it.
Mon 30 September 2024
In this blog post, we will explore how we can exploit CNEXT, but blind, covering the cases where we have a file read primitive, but cannot get the output.
Thu 26 September 2024
An authentication bypass vulnerability was found on Jupiter X Core Plugin <= 4.7.5 (CVE-2024-7781).
A pre-authentication remote code execution vulnerability was found on Jupiter X Core Plugin <= 4.6.5 (CVE-2024-7772).
Wed 04 September 2024
Retrieve C2 from a wild StealC sample using Binary Ninja API.
Tue 03 September 2024
Retrieve C2 from unpacked loader (stage2) of a wild StealC sample and unpack stage 3 all with MIASM.
Check our offensive & continuous web security assessment service