ጳውሎስ 파울로스

@PaulosYibelo

specializing in web application security, shiro & kitfo, bitcoin, oauth... hacker! landlord :D

ಅಕ್ಟೋಬರ್ 2014 ಸಮಯದಲ್ಲಿ ಸೇರಿದ್ದಾರೆ

@PaulosYibelo ತಡೆಹಿಡಿಯಲಾಗಿದೆ

ನೀವು ಖಚಿತವಾಗಿಯೂ ಈ ಟ್ವೀಟ್‌ಗಳನ್ನು ನೋಡಲು ಬಯಸುವಿರಾ? ಟ್ವೀಟ್‌ಗಳನ್ನು ನೋಡುವುದು @PaulosYibelo ಅವರನ್ನು ತಡೆತೆರವುಗೊಳಿಸುವುದಿಲ್ಲ.

  1. ಪಿನ್ ಮಾಡಿದ ಟ್ವೀಟ್
    ಮಾರ್ಚ್ 31,2015
  2. ಜನ 26

    Releasing… ==== A polyglot inception written in four file formats – all at the same time: = JPEG = CSS = JS = HTML

  3. ಜನ 28
  4. ಜನ 26

    Another Cisco WebEx 1.0.5 RCE (Arbitrary Command Execution in via Module Whitelist Bypass) found by

  5. ಜನ 23

    There was a secret URL in WebEx that allowed any website to run arbitrary code. ¯\_(ツ)_/¯

  6. ಜನ 20
  7. ಜನ 17
  8. ಜನ 14

    The bug is finally fixed: How to inject JS in a static PDF to steal it without user interaction

  9. ಜನ 12
  10. ಜನ 8

    Hacker tip: always be coding - it'll broaden your perspective on how software is build and learn you new tricks how to get around defenses.

  11. ಜನ 7

    GitHub Enterprise SQL Injection - Incorrect usage of Rails ActiveRecord leads to SQL Injection

  12. ಜನ 6

    [ 2013 ] NSA: We made a database of everyone. Wikileaks: THIS IS AN OUTRAGE! [ 2017 ] Wikileaks: We're gonna make a database of everyone.

  13. ಜನ 2

    he was ahead of his time

  14. ಜನ 3

    Kaspersky identified SSL certificates by a 32bit fingerprint (!!!), making it trivial for MITM to create collisions.

  15. ಡಿಸೆಂ 31,2016

    Two days ago someone registered a British company called `; DROP TABLE "COMPANIES";-- LTD`. Oh well...

  16. ಜನ 1

    hah, my CSP nonce bypass:

  17. ಜನ 1

    <animate> works as well of course <svg><animate href= attributeName=href to=//14.rs /><script id=x src=x></script

  18. ಡಿಸೆಂ 31,2016

    Another type of CSP nonce bypass. FF+Chrome. Works with traditional reflected XSS. Happy new year!

  19. ಡಿಸೆಂ 30,2016
  20. ጳውሎስ 파울로스 ಹಿಂಬಾಲಿಸಿದ್ದಾರೆ , , and 6 others
    • @frgx

      Security Engineer at Dropbox. Previously, Berkeley CS Grad. Opinions are my own, and mostly wrong. Him/he.

    • @4lemon

      Web Application Security Researcher

  21. ಡಿಸೆಂ 29,2016

    Amazing Row Hammer presentation by creates factorizable SSH keys with bit flips.

ಲೋಡಿಂಗ್ ಸಮಯ ಸ್ವಲ್ಪ ತೆಗೆದುಕೊಳ್ಳುತ್ತಿರುವಂತೆನಿಸುತ್ತದೆ.

Twitter ಸಾಮರ್ಥ್ಯ ಮೀರಿರಬಹುದು ಅಥವಾ ಕ್ಷಣಿಕವಾದ ತೊಂದರೆಯನ್ನು ಅನುಭವಿಸುತ್ತಿರಬಹುದು. ಮತ್ತೆ ಪ್ರಯತ್ನಿಸಿ ಅಥವಾ ಹೆಚ್ಚಿನ ಮಾಹಿತಿಗೆ Twitter ಸ್ಥಿತಿಗೆ ಭೇಟಿ ನೀಡಿ.

    ಇದನ್ನೂ ಸಹ ನೀವು ಇಷ್ಟಪಡಬಹುದು

    ·