Cruising for Shells in Flowise – 6 RCEs That Rode Flowise Low and Slowelttam.com·1 pts·pentestercrab·0
Inline Style Exfiltration: leaking data with chained CSS conditionalsportswigger.net·1 pts·pentestercrab·0
Marshal madness: A brief history of Ruby deserialization exploitsblog.trailofbits.com·25 pts·pentestercrab·4
Breaking the Sorting Barrier for Directed Single-Source Shortest Pathsarxiv.org·99 pts·pentestercrab·3
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Railselttam.com·1 pts·pentestercrab·0
RubyGem's Gem:SafeMarshal buffer overrun with length larger than fit into a bytegithub.com·1 pts·pentestercrab·0
PentesterLab: Web Hacking and Security Code Review 600 exercises and 700 videospentesterlab.com·1 pts·pentestercrab·0
Cross-Site Post Requests Without a Content-Type Header – CSRF Attacknastystereo.com·2 pts·pentestercrab·0
Execute commands by sending JSON? Ruby deserialization vulnerabilitiesgithub.blog·2 pts·pentestercrab·0
JWT Libraries Block Algorithm Confusion: Key Lessons for Code Reviewpentesterlab.com·3 pts·pentestercrab·0
Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewallassetnote.io·2 pts·pentestercrab·1
Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewallassetnote.io·4 pts·pentestercrab·0