| user: | pentestercrab |
| created: | August 11, 2015 |
| karma: | 2.3k |
| 1. | |
| 2. | The Sunlight CT Log(sunlight.dev) |
| 3. | |
| 4. | |
| 5. | Ruby Array Pack Bleed(nastystereo.com) |
| 6. | Ruby Array Pack Bleed – Impacts Ruby 1.6.7 to 4.0.0(nastystereo.com) |
| 7. | |
| 8. | Marshal madness: A brief history of Ruby deserialization exploits(blog.trailofbits.com) |
| 9. | |
| 10. | |
| 11. | Escaping Ruby's Gem:SafeMarshal Sandbox(nastystereo.com) |
| 12. | Escaping Ruby's Gem:SafeMarshal Sandbox(nastystereo.com) |
| 13. | |
| 14. | CORS Vulnerabilities in Go: Vulnerable Patterns and Lessons(pentesterlab.com) |
| 15. | Shiny Vulnerabilities in R's Most Popular Web Framework(nastystereo.com) |
| 16. | |
| 17. | Cross-Site Post Requests Without a Content-Type Header – CSRF Attack(nastystereo.com) |
| 18. | |
| 19. | JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review(pentesterlab.com) |
| 20. | Chosen-Prefix Collisions on AES-Like Hashing(eprint.iacr.org) |
| 21. | Ruby 3.4 Universal RCE Deserialization Gadget Chain(nastystereo.com) |
| 22. | Ruby's String Slice is Broken(nastystereo.com) |
| 23. | Evaluate Markdown code blocks within Vim(github.com) |
| 24. | SQL Injection Polyglot Payloads(nastystereo.com) |