Amal PK

@0xkratos.bsky.social

Cyber Security Researcher | CTF Player | VAPT

🏖️🐻 Les Logiciels Libres de l'été, jour 32 : Vulhub : un projet Open Source offrant des environnements vulnérables préconstruits basés sur Docker-Compose. Idéal pour tester et apprendre la gestion des vulnérabilités, chaque environnement inclut un guide d'installation et d'utilisation.

Vulhub
Vulhub is an open-source collection of pre-built vulnerable docker environments for security researchers and educators.

Explore Environments
GitHub
19.0k+ Stars
•
4.6k+ Forks
•
298 Environments
# Clone the repository
git clone --depth 1 https://github.com/vulhub/vulhub.git

# Enter the directory
cd vulhub/spring/CVE-2022-22947

# Start the environment
docker compose up -d

Most open redirects are low-severity or N/A. But used creatively, they can become high impact gadgets. Here are 4 ways to show impact with open redirects:

Bild

🛠️ waymore: Tip #1 📝 By default, waymore will get URLs and download responses (-mode B). If you just want URLs, then use "-mode U". If you just want to download archived responses, then use "-mode R". 🤘

Yesterday I discovered a tweet of mine was referenced in the book "Attacking and Exploiting Modern Web Applications: Discover the mindset, techniques, and tools to perform modern web attacks and exploitation" www.amazon.nl/-/en/Simone-... Since I deleted my account, this is the tweet:

Bild

made an archive collection site thing for all the x3ctf web design stuff i did the intro/outro can be rewatched with websocket replay data (eg the messages and synced mouse cursors) and the platform itself has emulations for auth and flags and stuff u can check it out at x3c.tf/archive/

CVE-2025-21298 Windows OLE Remote Code Execution Vulnerability! A critical vulnerability in Windows Object Linking and Embedding (OLE) technology, which enables remote code execution (RCE) with a CVSS severity score of 9.8. Read more: 0xkrat0s.github.io/posts/CVE-20...

CVE-2025-21298 Windows OLE Remote Code Execution Vulnerability

Overview CVE-2025-21298 is a critical vulnerability in Windows Object Linking and Embedding (OLE) technology, which enables remote code execution (RCE) with a CVSS severity score of 9.8. OLE is a prop...

0xkrat0s.github.io

To summarize what I have learned about Mutation XSS, my CVE, and the solution to my challenge, I wrote a post going through it all. If you like regular XSS, this is a whole new world of crazy techniques and many sanitizer bypasses. You too can learn this! jorianwoltjer.com/blog/p/hacki...

Post: Mutation XSS: Explained, CVE and Challenge | Jorian Woltjer

Learn how to bypass HTML sanitizers by abusing the intricate parsing rules and mutations. Including my CVE-2024-52595 (lxml_html_clean bypass) and the solution to a hard challenge I shared online

jorianwoltjer.com

Informally beginning a bug bounty program for Porffor: offering $100 to anyone who can *run arbitrary code/commands via Porffor only compiling* (`porf wasm foo.js foo.wasm`). 90% sure this is impossible so putting own money on the line ;) (if people are interested in why I think so I can say more)

Extended the starter with shy writers! 😀 If you're not on the list but write about web security, then feel free to reply with the article you're most proud of, and I will add you to the pack! Make sure to resubscribe to not not miss on the amazing 🌐research! go.bsky.app/9JXnB17

Post nicht verfügbar.