<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pages on 0day.click</title>
    <link>https://0day.click/page/</link>
    <description>Recent content in Pages on 0day.click</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="https://0day.click/page/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>About</title>
      <link>https://0day.click/page/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://0day.click/page/about/</guid>
      <description>&lt;p&gt;This site contains misc stuff I came across in the last decade or so.&lt;/p&gt;</description>
    </item>
    <item>
      <title>References</title>
      <link>https://0day.click/page/references/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://0day.click/page/references/</guid>
      <description>&lt;h1 id=&#34;talks-and-presentations&#34;&gt;Talks and Presentations&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Nullcon Berlin 2025 - Keynote LLMs Everywhere: The future is now and the past keeps repeating itself - &lt;a href=&#34;https://0day.click/the-future-is-now/&#34;&gt;Slides&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;OffensiveCon 2025 - Parser Differentials - &lt;a href=&#34;https://www.youtube.com/watch?v=Dq_KVLXzxH8&#34;&gt;Video&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://0day.click/parser-diff-talk-oc25/&#34;&gt;Slides&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Invited Talk for &lt;a href=&#34;https://bi0s.in&#34;&gt;Team Bi0s&lt;/a&gt; - Argument Injection - &lt;a href=&#34;https://www.youtube.com/watch?v=FHiJnw9TTX8&#34;&gt;Video&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://docs.google.com/presentation/d/1U8r5CJs9dLOLO2-hj_bHidRMXugUl3ejv8Hdw6bDMv4/&#34;&gt;Slides&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;HITB GSEC 2018 - Surprise Rant 2.0 &lt;a href=&#34;https://www.youtube.com/watch?v=W2SLg--am1A&#34;&gt;Video&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;OffensiveCon 2018 - Surprise Rant &lt;a href=&#34;https://www.youtube.com/watch?v=VTic5d13u2E&#34;&gt;Video&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Ekoparty 2016 - Let Me GitHub That For You (2016 Argentinian Edition) &lt;a href=&#34;https://www.youtube.com/watch?v=g4NiV8tbGT8&#34;&gt;Video&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Hacktivity 2015 - Your Web app, those hackers &amp;amp; you &lt;a href=&#34;https://www.youtube.com/watch?v=p-Njhwp5PZA&#34;&gt;Video&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;HackPra 2015 - Bug Tales &lt;a href=&#34;https://www.youtube.com/watch?v=XWrci09sGMU&#34;&gt;Video&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Hackito Ergo Sum 2014 - Ruby on Rails exploitation and effective backdooring&lt;/li&gt;&#xA;&lt;li&gt;t2-2013 - &amp;lt;3 Ruby on Rails &amp;lt;3&lt;/li&gt;&#xA;&lt;li&gt;HITB Amsterdam 2013 - Attacking Ruby on Rails Applications&lt;/li&gt;&#xA;&lt;li&gt;ZeroNights 2012 - They told me I could be anything, so I became BAh7BkkiDHVzZXJfaWQGOgZFVGkG&lt;/li&gt;&#xA;&lt;li&gt;HITB Malaysia 2011 - Building and Breaking Ruby on Rails&lt;/li&gt;&#xA;&lt;li&gt;Hackito Ergo Sum 2011 - Ruby On Rails From A Code Auditor&amp;rsquo;s Perspective &lt;a href=&#34;https://www.youtube.com/watch?v=o4goIQAzIME&#34;&gt;Video part 1&lt;/a&gt; &lt;a href=&#34;https://www.youtube.com/watch?v=kEE9uaBOPyk&#34;&gt;part 2&lt;/a&gt; &lt;a href=&#34;https://www.youtube.com/watch?v=3oI3gZwVQYk&#34;&gt;part 3&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Berlinsides 2010 - Ruby On Rails From A Code Auditor&amp;rsquo;s Perspective&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;blogposts&#34;&gt;Blogposts&lt;/h1&gt;&#xA;&lt;h2 id=&#34;gitlab&#34;&gt;GitLab&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/git-security-audit/&#34;&gt;Git security audit: Inside the hunt for - and discovery of - CVEs&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/terraform-as-part-of-software-supply-chain-part1-modules-and-providers/&#34;&gt;Terraform as part of the software supply chain&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/two-bugs-and-a-quick-fix-in-gitpod/&#34;&gt;A brief look at Gitpod, two bugs, and a quick fix&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/switching-sides-in-security/&#34;&gt;Switching &amp;ldquo;sides&amp;rdquo; in security&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/how-to-play-gitlab-ctf-at-home/&#34;&gt;How to play GitLab&amp;rsquo;s Capture the Flag at home&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/how-to-exploit-parser-differentials/&#34;&gt;How to exploit parser differentials&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://about.gitlab.com/blog/shopping-for-an-admin-account/&#34;&gt;Shopping for an admin account via path traversal&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;gitlab-security-tech-notes&#34;&gt;GitLab Security Tech Notes&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/devfile/&#34;&gt;Devfile file write vulnerability in GitLab&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/arr-pm/&#34;&gt;arr-pm command execution&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;recurity-labs&#34;&gt;Recurity Labs&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.recurity-labs.com/2019-04-12/knx.html&#34;&gt;KNX, %s and a backdoor&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.recurity-labs.com/2017-08-10/scm-vulns.html&#34;&gt;Compromise On Checkout - Vulnerabilities in SCM Tools&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.recurity-labs.com/2011-05-12/18_06_51.html&#34;&gt;dRuby for Penetration Testers&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.recurity-labs.com/2011-03-09/18_34_04.html&#34;&gt;At Least, I got DoS&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;phenoelit&#34;&gt;Phenoelit&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://194.150.168.69//blog/archives/2014/10/11/tldr_just_another_way_to_get_rce_in_i2p_version_0_9_13/index.html&#34;&gt;TL;DR: Just another way to get RCE in i2p version 0.9.13.&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://194.150.168.69/blog/archives/2013/09/24/ruby_on_rails_default_token_database/index.html&#34;&gt;Ruby on Rails Default Token Database&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://194.150.168.69/blog/archives/2013/02/05/mysql_madness_and_rails/index.html&#34;&gt;MySQL madness and Rails&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://194.150.168.69/blog/archives/2012/12/21/let_me_github_that_for_you/index.html&#34;&gt;Let Me Github That For You&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://194.150.168.69/blog/archives/2012/04/05/a_worst_practice_in_ruby_on_rails/index.html&#34;&gt;A worst practice in Ruby on Rails&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;papers&#34;&gt;Papers&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Attacking Ruby on Rails Applications - &lt;a href=&#34;http://phrack.org/issues/69/12.html#article&#34;&gt;Phrack 69&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;A Vulnerability in Reduced Dakarand from PoC||GTFO 01:02 - &lt;a href=&#34;https://www.alchemistowl.org/pocorgtfo/pocorgtfo02.pdf&#34;&gt;PoC||GTFO 02&lt;/a&gt;:09&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;trainings&#34;&gt;Trainings&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Source Code Auditing Like a Ninja - &lt;a href=&#34;https://gsec.hitb.org/sg2018/sessions/3-day-training-3-source-code-auditing-like-a-ninja/&#34;&gt;HITB GSEC Singapore 2018&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Source Code Auditing Like a Ninja - &lt;a href=&#34;https://archive.conference.hitb.org/hitbsecconf2018ams/sessions/3-day-training-4-source-code-auditing-like-a-ninja/&#34;&gt;HITB Amsterdam 2018&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Ruby on Rails – Auditing &amp;amp; Exploiting the Popular Web Framework - &lt;a href=&#34;https://2015.appsec.eu/trainings/#train11&#34;&gt;OWASP AppSec EU 2015&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Ruby on Rails – Auditing &amp;amp; Exploiting the Popular Web Framework - &lt;a href=&#34;https://2014.appsecusa.org/2014/training/ruby-on-rails-auditing-exploiting-the-popular-web-framework/&#34;&gt;OWASP AppSec USA 2014&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://code-audit-training.gitlab.io/&#34;&gt;Recurity Labs Code Audit Training Archive&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;other&#34;&gt;Other&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Founding member of &lt;a href=&#34;https://wiki.das-labor.org/w/LABOR_Wiki&#34;&gt;das Labor&lt;/a&gt; a Hackerspace in Bochum&lt;/li&gt;&#xA;&lt;li&gt;Review panel member for &lt;a href=&#34;https://threatcon.io&#34;&gt;THREAT CON&lt;/a&gt; 2018 - 2023&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
