Sam Curry
@zlz.bsky.social
📤 1813
📥 22
📝 5
reposted by
Sam Curry
David Buchanan
8 months ago
userland ROP on day 1 💪
102
2057
393
New blog post with
@shubs.io
: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. Full post here:
samcurry.net/hacking-subaru
loading . . .
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State...
https://samcurry.net/hacking-subaru
12 months ago
5
73
36
reposted by
Sam Curry
Bee 🐝
about 1 year ago
Documentary on Hackers Who Get Paid to Hack Companies. @CyberNews interviewed Bryce (@realytcracker), Ben (@NahamSec), Sam Curry (
@zlz
), Frederik (
@stokfredrik
), Neiko (@_specters_), Vanya (@BusesCanFly), Phoenix (LilRed), André (
@0xacb
).
1
4
2
reposted by
Sam Curry
PortSwigger Research
about 1 year ago
Did you know you can use an ancient magic cookie to downgrade parsers and bypass WAFs?! Hope you enjoy this quality bit of RFC-diving from
@d4d89704243.bsky.social
!
portswigger.net/research/byp...
loading . . .
Bypassing WAFs with the phantom $Version cookie
HTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known
https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie
1
73
32
reposted by
Sam Curry
Luke Jahnke
about 1 year ago
My latest blog post is live!
nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
3
79
33
reposted by
Sam Curry
SandShark
about 1 year ago
This must be the result of the attempts
0
5
1
Does anyone know the max size limit for Bluesky usernames? The DNS and everything resolves correctly for this (253 characters), but it seems to throw 400 bad request when I actually try to assign it.
about 1 year ago
3
27
1
you reached the end!!
feeds!
log in