Tyranid's Lair

Tuesday, 14 October 2014

A Tale of Two .NET Methods

›
Sometimes the simplest things amuse me. Take for example CVE-2014-0257 which was a bug in the way DCOM was implemented in .NET which enable...
Sunday, 14 September 2014

Hash Collisions of the Non-Cryptographic Kind

›
Recently I had a bug which required me to create a hash collision between two strings. Fortunately it wasn't a cryptographically secure ...
Thursday, 5 June 2014

Addictive Double-Quoting Sickness

›
Much as I'd love it if people who used "Scare Quotes" (see what I did there) were punished appropriately I doubt my intoleranc...
Tuesday, 27 May 2014

Abusive Directory Syndrome

›
As ever there's been some activity recently on Full Disclosure where one side believes something's a security vulnerability and the...
Wednesday, 21 May 2014

Impersonation and MS14-027

›
The recent  MS14-027  patch intrigued me, a local EoP using ShellExecute . It seems it also intrigued others so I pointed out how it probabl...
Saturday, 2 February 2013

Fun with Java Serialization and Reflection

›
Last year I started to have a poke at Java for security vulnerabilities, I am not really sure why, but probably because I was having some su...
Sunday, 6 June 2010

The Quest : Part 2

›
So the last try at making a small Mach-O binary didn't really work. Now I could start fiddling with the linker to see if I can make thin...
‹
›
Home
View web version
Powered by Blogger.