Tyranid's Lair
Tuesday, 14 October 2014
A Tale of Two .NET Methods
›
Sometimes the simplest things amuse me. Take for example CVE-2014-0257 which was a bug in the way DCOM was implemented in .NET which enable...
Sunday, 14 September 2014
Hash Collisions of the Non-Cryptographic Kind
›
Recently I had a bug which required me to create a hash collision between two strings. Fortunately it wasn't a cryptographically secure ...
Thursday, 5 June 2014
Addictive Double-Quoting Sickness
›
Much as I'd love it if people who used "Scare Quotes" (see what I did there) were punished appropriately I doubt my intoleranc...
Tuesday, 27 May 2014
Abusive Directory Syndrome
›
As ever there's been some activity recently on Full Disclosure where one side believes something's a security vulnerability and the...
Wednesday, 21 May 2014
Impersonation and MS14-027
›
The recent MS14-027 patch intrigued me, a local EoP using ShellExecute . It seems it also intrigued others so I pointed out how it probabl...
Saturday, 2 February 2013
Fun with Java Serialization and Reflection
›
Last year I started to have a poke at Java for security vulnerabilities, I am not really sure why, but probably because I was having some su...
Sunday, 6 June 2010
The Quest : Part 2
›
So the last try at making a small Mach-O binary didn't really work. Now I could start fiddling with the linker to see if I can make thin...
‹
›
Home
View web version