the guly
/home /archive /tags /about

  • 01 Jan 2021 Symfony JMose CommandScheduler RCE

    A journey in a Symfony website with JMose CommandScheduler enabled lead to some interesting results.

  • 07 Sep 2020 rConfig 3.9.4 multiple vulnerabilities

    A journey in rConfig 3.9.4 lead to preauth sql injection, auth bypass, and remote code execution

  • 04 Sep 2020 Achieve Pareto Principle in secure code review, or die trying

    Blog post for my talk about secure code review at End Summer Camp 2K20

  • 01 Feb 2020 eLearnSecurity eXploit Development Student

    Here is my take on eLearnSecurity eXploit Development Student course and relative certification process

Recent Posts

  • Symfony JMose CommandScheduler RCE
  • rConfig 3.9.4 multiple vulnerabilities
  • Achieve Pareto Principle in secure code review, or die trying
  • Long the Ripper
  • eLearnSecurity eXploit Development Student

Tags

  • assembly
  • certifications
  • courses
  • exploit
  • noise
  • red
  • tools
  • web

Sandro "guly" Zaccarini © 1970-2020

Follow me