Cruising for Shells in Flowise – 6 RCEs That Rode Flowise Low and Slowelttam.com 1pentestercrab1modiscuss
Inline Style Exfiltration: leaking data with chained CSS conditionalsportswigger.net 1pentestercrab1ydiscuss
Marshal madness: A brief history of Ruby deserialization exploitsblog.trailofbits.com 25pentestercrab1y4 comments
Breaking the Sorting Barrier for Directed Single-Source Shortest Pathsarxiv.org 99pentestercrab1y3 comments
New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Railselttam.com 1pentestercrab1ydiscuss
RubyGem's Gem:SafeMarshal buffer overrun with length larger than fit into a bytegithub.com/rubygems 1pentestercrab1ydiscuss
PentesterLab: Web Hacking and Security Code Review 600 exercises and 700 videospentesterlab.com 1pentestercrab1ydiscuss
Cross-Site Post Requests Without a Content-Type Header – CSRF Attacknastystereo.com 2pentestercrab1ydiscuss
Execute commands by sending JSON? Ruby deserialization vulnerabilitiesgithub.blog 2pentestercrab1ydiscuss
JWT Libraries Block Algorithm Confusion: Key Lessons for Code Reviewpentesterlab.com 3pentestercrab1ydiscuss
Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewallassetnote.io 2pentestercrab1y1 comment
Insecurity Through Censorship: Vulnerabilities Caused by the Great Firewallassetnote.io 4pentestercrab1ydiscuss