@0xjdow.bsky.social

Incoherent offsec retweets, hacking @ Scorpion Labs

From SSRF discovery to RCE exploitation in 32 iterations. XBOW systematically analyzed TiTiler's expression parser, discovered Python execution through error patterns, then crafted payloads using subclass traversal to achieve command execution. Complete analysis: bit.ly/46XzOiA

XBOW – Beyond the Bands: Exploiting TiTiler’s Expression Parser for Remote Code Execution

A methodical analysis of TiTiler's API endpoints and its expression parser, leading to arbitrary Python code execution on the server.

bit.ly

Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE. Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...

Bild

For the new folks, Bsky felt alive for me after following 200+ people which I found by looking for “starter packs” like the one I link here. Make sure you complete your profile with image/description, post, be generous with likes so people know you are reading their posts. bsky.app/profile/matt...

Shatter 🅅 𓅃⭐@shatter.bsky.social · 2y ago

Reminder that this is Bluesky and not Xitter. Dont expect 50 million inpressions per day because nothing is driving traffic to you except followers and reskeets.