floyd's | Internal Links | Dofollow |
Home | Internal Links | Dofollow |
About | Internal Links | Dofollow |
RSS | Internal Links | Dofollow |
← Older posts | Internal Links | Dofollow |
Python Sender | Internal Links | Dofollow |
floyd | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Useful scripts | Internal Links | Dofollow |
Web Penetration Testing | Internal Links | Dofollow |
CTF | Internal Links | Dofollow |
http | Internal Links | Dofollow |
pentesting | Internal Links | Dofollow |
python | Internal Links | Dofollow |
script | Internal Links | Dofollow |
sockets | Internal Links | Dofollow |
webserver testing | Internal Links | Dofollow |
Java Bugs with and without Fuzzing – AFL-based Java fuzzers and the Java Security Manager | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Fuzzing | Internal Links | Dofollow |
AFL | Internal Links | Dofollow |
Apache | Internal Links | Dofollow |
fuzzing | Internal Links | Dofollow |
Java | Internal Links | Dofollow |
Java security manager | Internal Links | Dofollow |
JQF | Internal Links | Dofollow |
Kelinci | Internal Links | Dofollow |
Activity wrap-up including polyglots, RIPS, UploadScanner and Java fuzzing | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Various | Internal Links | Dofollow |
area41 | Internal Links | Dofollow |
Java security policy | Internal Links | Dofollow |
PHP | Internal Links | Dofollow |
polyglot | Internal Links | Dofollow |
RIPS | Internal Links | Dofollow |
type unsafe comparison | Internal Links | Dofollow |
UploadScanner | Internal Links | Dofollow |
Wordpress | Internal Links | Dofollow |
Schubser and his cookie dealing friend | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Coding | Internal Links | Dofollow |
Android | Internal Links | Dofollow |
deserialisation | Internal Links | Dofollow |
Firesheep | Internal Links | Dofollow |
MITM | Internal Links | Dofollow |
mod0cookiedealer | Internal Links | Dofollow |
mod0schubser | Internal Links | Dofollow |
modjoda | Internal Links | Dofollow |
BSides Zurich – Nail in the JKS coffin | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Java Key Store | Internal Links | Dofollow |
“Nail in the JKS coffin” as a PDF here | Internal Links | Dofollow |
Password cracking | Internal Links | Dofollow |
BSides Zurich | Internal Links | Dofollow |
JKS | Internal Links | Dofollow |
presentation | Internal Links | Dofollow |
Android Nougat’s certificate pinning security mechanism | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Android | Internal Links | Dofollow |
Fails | Internal Links | Dofollow |
Android Nougat | Internal Links | Dofollow |
Burp | Internal Links | Dofollow |
CA install | Internal Links | Dofollow |
fail | Internal Links | Dofollow |
snakeoil security | Internal Links | Dofollow |
Java Key Store (JKS) format is weak and insecure (CVE-2017-10356) | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
https://www.floyd.ch/?p=985 | Internal Links | Dofollow |
https://www.floyd.ch/?p=1015 | Internal Links | Dofollow |
CVE-2017-10356 | Internal Links | Dofollow |
encryption | Internal Links | Dofollow |
Java Key Store | Internal Links | Dofollow |
Cracking Java’s weak encryption – Nail in the JKS coffin | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
hashcat | Internal Links | Dofollow |
Hashes | Internal Links | Dofollow |
password cracking | Internal Links | Dofollow |
Crash bash | Internal Links | Dofollow |
1 | Internal Links | Dofollow |
bash | Internal Links | Dofollow |
segmentation fault | Internal Links | Dofollow |
iOS TLS session resumption race condition (CVE-2016-10511) | Internal Links | Dofollow |
Reply | Internal Links | Dofollow |
Mobile Security | Internal Links | Dofollow |
Hackerone | Internal Links | Dofollow |
iOS | Internal Links | Dofollow |
session resumption | Internal Links | Dofollow |
TLS | Internal Links | Dofollow |
Twitter | Internal Links | Dofollow |
Code Review | Internal Links | Dofollow |
Firewalls | Internal Links | Dofollow |
Hardware | Internal Links | Dofollow |
Overflow exploits | Internal Links | Dofollow |
HTML5 | Internal Links | Dofollow |
Web Application Fuzzing | Internal Links | Dofollow |
XSS | Internal Links | Dofollow |
November 2018 | Internal Links | Dofollow |
September 2018 | Internal Links | Dofollow |
May 2018 | Internal Links | Dofollow |
April 2018 | Internal Links | Dofollow |
September 2017 | Internal Links | Dofollow |
July 2017 | Internal Links | Dofollow |
March 2017 | Internal Links | Dofollow |
December 2016 | Internal Links | Dofollow |
November 2016 | Internal Links | Dofollow |
December 2015 | Internal Links | Dofollow |
October 2015 | Internal Links | Dofollow |
June 2015 | Internal Links | Dofollow |
March 2015 | Internal Links | Dofollow |
January 2015 | Internal Links | Dofollow |
December 2014 | Internal Links | Dofollow |
October 2014 | Internal Links | Dofollow |
September 2014 | Internal Links | Dofollow |
February 2014 | Internal Links | Dofollow |
December 2013 | Internal Links | Dofollow |
August 2013 | Internal Links | Dofollow |
February 2013 | Internal Links | Dofollow |
January 2013 | Internal Links | Dofollow |
December 2012 | Internal Links | Dofollow |
October 2012 | Internal Links | Dofollow |
September 2012 | Internal Links | Dofollow |
August 2012 | Internal Links | Dofollow |
June 2012 | Internal Links | Dofollow |
April 2012 | Internal Links | Dofollow |
March 2012 | Internal Links | Dofollow |
February 2012 | Internal Links | Dofollow |
December 2011 | Internal Links | Dofollow |
November 2011 | Internal Links | Dofollow |
October 2011 | Internal Links | Dofollow |
September 2011 | Internal Links | Dofollow |
August 2011 | Internal Links | Dofollow |
July 2011 | Internal Links | Dofollow |
October 2010 | Internal Links | Dofollow |
September 2010 | Internal Links | Dofollow |
August 2010 | Internal Links | Dofollow |
July 2010 | Internal Links | Dofollow |
June 2010 | Internal Links | Dofollow |
May 2010 | Internal Links | Dofollow |
aes | Internal Links | Dofollow |
AppleScript | Internal Links | Dofollow |
ARM | Internal Links | Dofollow |
bing | Internal Links | Dofollow |
buffer overflow | Internal Links | Dofollow |
code alignment | Internal Links | Dofollow |
control characters | Internal Links | Dofollow |
corelan | Internal Links | Dofollow |
Cracking | Internal Links | Dofollow |
CRASS | Internal Links | Dofollow |
cross-compiling | Internal Links | Dofollow |
decompiling | Internal Links | Dofollow |
Firewalls | Internal Links | Dofollow |
Google Market | Internal Links | Dofollow |
JD-GUI | Internal Links | Dofollow |
Mac | Internal Links | Dofollow |
Metasploit | Internal Links | Dofollow |
mona.py | Internal Links | Dofollow |
OWASP | Internal Links | Dofollow |
perimeter-security | Internal Links | Dofollow |
ruby | Internal Links | Dofollow |
seh | Internal Links | Dofollow |
shared hosting | Internal Links | Dofollow |
Ubuntu | Internal Links | Dofollow |
unicode | Internal Links | Dofollow |
Windows | Internal Links | Dofollow |
XSS | Internal Links | Dofollow |
Twitter | External Links | Dofollow |
Github | External Links | Dofollow |
Hackerone | External Links | Dofollow |
easy Remote Command Execution (RCE) | External Links | Dofollow |
pwntools | External Links | Dofollow |
Python Sender | External Links | Dofollow |
Kelinci | External Links | Dofollow |
JQF | External Links | Dofollow |
java-afl | External Links | Dofollow |
github | External Links | Dofollow |
AFL | External Links | Dofollow |
tried to ask | External Links | Dofollow |
Apache Common’s | External Links | Dofollow |
one of the examples explained | External Links | Dofollow |
lcamtuf’s very interesting experiment | External Links | Dofollow |
lcamtuf’s corpus on the AFL website | External Links | Dofollow |
ArrayIndexOutOfBoundsException which I reported to Apache | External Links | Dofollow |
idea of differential fuzzing for crypto libraries | External Links | Dofollow |
Address Sanitizer (ASAN) | External Links | Dofollow |
Jakub Wilk it might be tricky to implement due to async-signal-safe filesystem functions | External Links | Dofollow |
simple Java Security Manager policy file I created | External Links | Dofollow |
Apache Tika | External Links | Dofollow |
another related research about web based file upload functionalities (UploadScanner Burp extension) | External Links | Dofollow |
severe security issues in the past | External Links | Dofollow |
multiple | External Links | Dofollow |
issues | External Links | Dofollow |
“works-for-me” Kelinci fork | External Links | Dofollow |
similar but distinct problems | External Links | Dofollow |
article from 2004 | External Links | Dofollow |
TMSJSPGE on github | External Links | Dofollow |
CVE-2018-1338 | External Links | Dofollow |
Apache Tika’s BPGParser | External Links | Dofollow |
CVE-2018-1339 | External Links | Dofollow |
Apache Tika’s ChmParser | External Links | Dofollow |
libbpg | External Links | Dofollow |
the fuzzing project | External Links | Dofollow |
CHMLib | External Links | Dofollow |
Two independent StackOverflowException issues in Apache PDFBOX to parse PDF files | External Links | Dofollow |
An ArrayIndexOutOfBoundsException in Apache Commons ZipFile to parse zip files | External Links | Dofollow |
An IllegalArgumentException in Gagravarr VorbisJava to parse ogg files | External Links | Dofollow |
OpenJDK on ARM had horrible performance with JQF | External Links | Dofollow |
fixed three independent issues and implemented a test case/benchmark for the fixed Tika 1.18 in JQF | External Links | Dofollow |
JQF couldn’t handle timeouts either | External Links | Dofollow |
afl-cmin | External Links | Dofollow |
a Java Security Manager policy | External Links | Dofollow |
Endless loop in RiffReader | External Links | Dofollow |
Oracle assigned CVE-2018-3214 to this issue with a CVSS score of 5.3 and fixed it with a Java update | External Links | Dofollow |
Tim Allison also mitigated it on the Apache Tika side | External Links | Dofollow |
sample QCP file “fart_3.qcp” from the public ffmpeg samples | External Links | Dofollow |
An endless loop in Junrar | External Links | Dofollow |
Infinite loop in Apache Tika’s IptcAnpaParser | External Links | Dofollow |
Infinite loop in Apache PDFbox’ AdobeFontMetricsParser | External Links | Dofollow |
An issue when a specially crafted zip content is read with Apache Commons Compress | External Links | Dofollow |
fixed in Apache Commons Compress | External Links | Dofollow |
A tweet of takesako including a C/C++/Perl/Ruby/Python polyglot | External Links | Dofollow |
two follow-up polyglots based on his work and put them on github | External Links | Dofollow |
RIPS PHP scanner | External Links | Dofollow |
PHP type unsafe comparisons like the one I found in this WordPress plugin | External Links | Dofollow |
albinowax also added a new check for the backslash powered scanner Burp extension | External Links | Dofollow |
workshop on my yet unreleased Burp Proxy UploadScanner extension at the area41 conference in Zurich | External Links | Dofollow |
modjoda | External Links | Dofollow |
mod0schubser | External Links | Dofollow |
mod0cookiedealer | External Links | Dofollow |
Firesheep | External Links | Dofollow |
the official announcement about this user-added certificate security is here | External Links | Dofollow |
is raising the bar for defenders, not for attackers | External Links | Dofollow |
BSides Zurich | External Links | Dofollow |
https://cryptosense.com/mighty-aphrodite-dark-secrets-of-the-java-keystore/ | External Links | Dofollow |
https://unpack.debug.su/pocorgtfo/pocorgtfo15.pdf | External Links | Dofollow |
https://github.com/floyd-fuh/JKS-private-key-cracker-hashcat | External Links | Dofollow |
Oracle Critical Patch Update Advisory – October 2017 | External Links | Dofollow |
POC||GTFO journal edition 0x15 came out a while ago | External Links | Dofollow |
hashcat password cracking tool | External Links | Dofollow |
Bash-4.4 patch 12 | External Links | Dofollow |
whoopsie | External Links | Dofollow |
The maintainers of bash were notified | External Links | Dofollow |
published on Hackerone | External Links | Dofollow |
Proudly powered by WordPress | External Links | Dofollow |
Social
Social Data
Cost and overhead previously rendered this semi-public form of communication unfeasible.
But advances in social networking technology from 2004-2010 has made broader concepts of sharing possible.