the guly
/home /archive /tags /about

  • 01 Jan 2021 Symfony JMose CommandScheduler RCE

    A journey in a Symfony website with JMose CommandScheduler enabled lead to some interesting results.

  • 07 Sep 2020 rConfig 3.9.4 multiple vulnerabilities

    A journey in rConfig 3.9.4 lead to preauth sql injection, auth bypass, and remote code execution

  • 01 Aug 2019 Advanced Web Attack and Exploitation - Offensive Security Web Expert

    Here is my take on Advanced Web Attack and Exploitation course and relative exam for Offensive Security Web Expert

Recent Posts

  • Symfony JMose CommandScheduler RCE
  • rConfig 3.9.4 multiple vulnerabilities
  • Achieve Pareto Principle in secure code review, or die trying
  • Long the Ripper
  • eLearnSecurity eXploit Development Student

Tags

  • assembly
  • certifications
  • courses
  • exploit
  • noise
  • red
  • tools
  • web

Sandro "guly" Zaccarini © 1970-2020

Follow me