-
Symfony JMose CommandScheduler RCE
A journey in a Symfony website with JMose CommandScheduler enabled lead to some interesting results.
-
rConfig 3.9.4 multiple vulnerabilities
A journey in rConfig 3.9.4 lead to preauth sql injection, auth bypass, and remote code execution
-
Achieve Pareto Principle in secure code review, or die trying
Blog post for my talk about secure code review at End Summer Camp 2K20
-
eLearnSecurity eXploit Development Student
Here is my take on eLearnSecurity eXploit Development Student course and relative certification process