Advertisement ยท 728 ร— 90

Posts by Louis Dion-Marcil

it is crazy to me that we still cannot do this

5 months ago 1 0 0 0
Post image

I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! ๐Ÿ”ฅ

The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs ๐Ÿ‘‡

gmsgadget.com

1/4

8 months ago 23 13 1 0
Preview
Trix Shots: Remote Code Execution on Aviatrix Controller | Google Cloud Blog Red team case study detailing the discovery of two critical vulnerabilities in the Aviatrix Controller software.

wrote some words about vulnerabilities i found in Aviatrix during a red team cloud.google.com/blog/topics/...

9 months ago 4 1 0 0
Preview
The Signal Clone the Trump Admin Uses Was Hacked TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.

TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. โ€œI would say the whole process took about 15-20 minutes,โ€ the hacker said micahflee.com/the-signal-c...

11 months ago 271 109 8 14
Video

๐Ÿš€ Another plugin in the Caido Store!

Introducing "Data Grep" by @bebiksior.

Extract data from requests and responses. Great for building wordlists, finding secrets, or powering your recon.

Check it out: github.com/caido-commun...

11 months ago 6 1 0 0

Got sniped into the challenge and ended up doing some cool XSS research :D

11 char XSS with mind-boggling race-conditions.

TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)

It's shorter than location=name !!

terjanq.me/solutions/jo...

1 year ago 30 11 1 1
Preview
Bridging the Gap: Elevating Red Team Assessments with Application Security Testing | Google Cloud Blog Red team and targeted external assessments should incorporate application security expertise to better simulate modern adversaries.

I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec

cloud.google.com/blog/topics/...

1 year ago 18 7 0 0
Advertisement

Environments are something I've wanted for a while now.

1 year ago 12 3 0 0
Post image

My latest blog post is live! nastystereo.com/security/cro...

Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon

1 year ago 79 29 3 4
Preview
Flatt Security XSS Challenge Execute alert(origin) on each challenge origins.

Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far
challenge-xss.quiz.flatt.training

1 year ago 6 2 0 0
TIL: Some surprising code execution sources in bash

add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsec

1 year ago 5 1 0 0

yeah wrote this yrs ago, would not use this as-is ๐Ÿ˜‚

1 year ago 3 0 0 0
Preview
sudo-backdoor/sudo at master ยท ldionmarcil/sudo-backdoor Wraps sudo; transparently steals user's credentials and exfiltrate over DNS. For those annoying times when you get a shell/file write on a sudoers account and need to leverage their credentials...

shocking how efficient this method is. patience > crazy exploits
github.com/ldionmarcil/...

1 year ago 4 0 1 0