Pwning Infrastructure via file protocol
A new support ticket feature. A suspicious download_url parameter. An unfiltered file:// protocol. Got a config file. 99+ plaintext secrets exposed
5 min read
Search for a command to run...
Exploring the art and science of offensive security
A new support ticket feature. A suspicious download_url parameter. An unfiltered file:// protocol. Got a config file. 99+ plaintext secrets exposed
A meditation on the ancient pattern of civilizational decay, my thoughts on erosion of critical thinking and worship of ignorance.
In this non-technical post, I talk about why red teaming doesn't have to turn you into the villain, discussed various non-technical aspects of responsible red teaming.