HNHacker News
TopNewBestAskShowJobs

pentestercrab

2,279 karma · joined August 11, 2015

submissionscomments

Nastystereo.com

nastystereo.com·1 pts·pentestercrab·
0

Ruby 4.0 Universal RCE Deserialization Gadget Chain

elttam.com·78 pts·pentestercrab·
22

The Sunlight CT Log

sunlight.dev·1 pts·pentestercrab·
0

Cruising for Shells in Flowise – 6 RCEs That Rode Flowise Low and Slow

elttam.com·1 pts·pentestercrab·
0

When Dawkins met Claude – Could this AI be conscious?

unherd.com·64 pts·pentestercrab·
434

Ruby Array Pack Bleed

nastystereo.com·62 pts·pentestercrab·
1

Ruby Array Pack Bleed – Impacts Ruby 1.6.7 to 4.0.0

nastystereo.com·9 pts·pentestercrab·
0

Inline Style Exfiltration: leaking data with chained CSS conditionals

portswigger.net·1 pts·pentestercrab·
0

Marshal madness: A brief history of Ruby deserialization exploits

blog.trailofbits.com·25 pts·pentestercrab·
4

Breaking the Sorting Barrier for Directed Single-Source Shortest Paths

arxiv.org·99 pts·pentestercrab·
3

New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails

elttam.com·1 pts·pentestercrab·
0

Escaping Ruby's Gem:SafeMarshal Sandbox

nastystereo.com·2 pts·pentestercrab·
1

Escaping Ruby's Gem:SafeMarshal Sandbox

nastystereo.com·3 pts·pentestercrab·
0

RubyGem's Gem:SafeMarshal buffer overrun with length larger than fit into a byte

github.com·1 pts·pentestercrab·
0

CORS Vulnerabilities in Go: Vulnerable Patterns and Lessons

pentesterlab.com·1 pts·pentestercrab·
0

Shiny Vulnerabilities in R's Most Popular Web Framework

nastystereo.com·1 pts·pentestercrab·
0

PentesterLab: Web Hacking and Security Code Review 600 exercises and 700 videos

pentesterlab.com·1 pts·pentestercrab·
0

Cross-Site Post Requests Without a Content-Type Header – CSRF Attack

nastystereo.com·2 pts·pentestercrab·
0

Execute commands by sending JSON? Ruby deserialization vulnerabilities

github.blog·2 pts·pentestercrab·
0

JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review

pentesterlab.com·3 pts·pentestercrab·
0

Chosen-Prefix Collisions on AES-Like Hashing

eprint.iacr.org·2 pts·pentestercrab·
0

Ruby 3.4 Universal RCE Deserialization Gadget Chain

nastystereo.com·2 pts·pentestercrab·
1

Ruby's String Slice is Broken

nastystereo.com·3 pts·pentestercrab·
2

Evaluate Markdown code blocks within Vim

github.com·68 pts·pentestercrab·
18

SQL Injection Polyglot Payloads

nastystereo.com·1 pts·pentestercrab·
0

Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewall

assetnote.io·2 pts·pentestercrab·
1

Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewall

assetnote.io·4 pts·pentestercrab·
0

Fuzz Map – fuzzer for GUIs that automatically builds a visual map

fuzzmap.io·1 pts·pentestercrab·
0

nastystereo.com

nastystereo.com·1 pts·pentestercrab·
0

A Single File Ruby on Rails Application

greg.molnar.io·3 pts·pentestercrab·
4
Page 1 of 8Next →