Sam Curry
@zlz.bsky.social
📤 1782
📥 22
📝 5
reposted by
Sam Curry
David Buchanan
4 months ago
userland ROP on day 1 💪
103
2069
400
New blog post with
@shubs.io
: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. Full post here:
samcurry.net/hacking-subaru
loading . . .
Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel
On November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State...
https://samcurry.net/hacking-subaru
8 months ago
5
73
36
reposted by
Sam Curry
Bee 🐝
10 months ago
Documentary on Hackers Who Get Paid to Hack Companies. @CyberNews interviewed Bryce (@realytcracker), Ben (@NahamSec), Sam Curry (
@zlz
), Frederik (
@stokfredrik
), Neiko (@_specters_), Vanya (@BusesCanFly), Phoenix (LilRed), André (
@0xacb
).
1
4
2
reposted by
Sam Curry
PortSwigger Research
10 months ago
Did you know you can use an ancient magic cookie to downgrade parsers and bypass WAFs?! Hope you enjoy this quality bit of RFC-diving from
@d4d89704243.bsky.social
!
portswigger.net/research/byp...
loading . . .
Bypassing WAFs with the phantom $Version cookie
HTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known
https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie
1
73
32
reposted by
Sam Curry
Luke Jahnke
10 months ago
My latest blog post is live!
nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
3
79
33
reposted by
Sam Curry
SandShark
10 months ago
This must be the result of the attempts
0
5
1
Does anyone know the max size limit for Bluesky usernames? The DNS and everything resolves correctly for this (253 characters), but it seems to throw 400 bad request when I actually try to assign it.
10 months ago
3
27
1
you reached the end!!
feeds!
log in