Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @scannell_simon
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @scannell_simon
-
Pinned Tweet
I published my exploit for this here: https://github.com/scannells/exploits … Happy new year everyone!https://twitter.com/scannell_simon/status/1322981977545494533 …
0:29Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
The plural of regex is regrets
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
MyBB fixed a Persistent XSS (CVE-2021-27279) in MyBB < 1.8.25 found by our researcher Igor Sak-Sakovskiy. RCE is possible when chained with CVE-2021-27890, reported by Simon Scannell & Carl Smith. Advisory: https://mybb.com/versions/1.8.25/ …pic.twitter.com/CYeN4grpDf
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
Tired of hopping between boring
#BugBounty programs? We are looking for full-time#Java and#CSharp vulnerability researchers to join our R&D team and uncover impactful#security bugs in popular open-source projects: https://www.sonarsource.com/company/jobs/vulnerability-research …pic.twitter.com/LtfxbsL6gb
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
We are excited that our security researchers
@scannell_simon and@swapgs are honored with a nomination for this year's ... - Best Client-Side Bug (RCE through CS:GO) - Best Privilege Escalation Bug (CVE-2020-27194) - Most Under-Hyped Research (Composer)https://twitter.com/PwnieAwards/status/1420362071225556995 …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
So excited to finally release my blog post- Kernel Pwning with eBPF: a Love Story. I cover eBPF, the verifier, debugging, exploitation, mitigations and other cool findings! I do root cause analysis and exploit CVE-2021-3490 for LPE with PoC included.https://www.graplsecurity.com/post/kernel-pwning-with-ebpf-a-love-story …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
We discovered a
#Java and#JavaScript code vulnerability in Zimbra webmail that could enable attackers to steal all emails of an organization by sending one malicious email. Learn more in our new blog post: https://blog.sonarsource.com/zimbra-webmail-compromise-via-email …#appsec#infosecpic.twitter.com/B7Cfwdc1Hn
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Really happy to have published something again, especially web stuff! pre-auth Stored XSS in email body + SSRFhttps://blog.sonarsource.com/zimbra-webmail-compromise-via-email …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
Yet another Linux kernel exploitation write-up! CVE-2021-22555: Turning \x00\x00 into 10000$https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
My first blog post as a vulnerability researcher is up
Check it out to learn about blind and error-based NoSQL injections in RocketChat that ended up giving me RCE!https://twitter.com/SonarSource/status/1394669606888001536 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
Just published the source code for both proxy and pocs https://github.com/brymko/csgo-exploits …https://twitter.com/the_secret_club/status/1393211695389188096 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
I've written multiple OSes, dozens of compilers, and even developed entirely new algorithms. I'm a high-school dropout.https://twitter.com/EmilyKager/status/1393223289233838082 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Really happy to publish something again. I have to admit I'm proud of the info leak, it enabled the exploit to be 100% reliable. We might publish the exploit code soonhttps://twitter.com/the_secret_club/status/1393211695389188096 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
XXE Vulnerability in
#WordPress <5.7.1: Learn what attackers were able to do and how to patch your#PHP8 code. https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/?utm_source=twitter&utm_medium=social&utm_campaign=wordpress&utm_content=security&utm_term=mofu …#security#appsecpic.twitter.com/XIHysLAlqdThanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
You can read about our work in the latest VICE articlehttps://www.vice.com/en/article/dyvgej/counter-strike-bug-allows-hackers-to-take-over-a-pc-with-a-steam-invite …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
I wonder if it's possible to challenge H1 legally for enforcing unlimited NDA on those bug reports while never acting on them?
@k8em0 do you know of any precedent?https://twitter.com/the_secret_club/status/1381632980628692996 …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
Valve ignoring security researchers is not just specific to the secret club. Here we see Bien Pham demonstrate his Remote Code Execution exploit that has not been patched for over a year.https://twitter.com/bienpnn/status/1381616325391384577 …
0:37Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
Two years ago, slidybat reported a remote code execution affecting Team Fortress 2. It can be triggered by joining a community server. It has yet to be patched.pic.twitter.com/JqIQu18g3O
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
looking forward to the blog post on this one, should it ever be fixed! :)https://twitter.com/the_secret_club/status/1380960120725733376 …
0:11Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
MyBB Remote Code Execution Chain (CVE-2021-27889, CVE-2021-27890) https://blog.sonarsource.com/mybb-remote-code-execution-chain … A guest post by our
#security research friends@scannell_simon and@cffsmith who found critical code vulnerabilities in the MyBB forum.#appsecpic.twitter.com/sbagkKzQMc
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Simon Scannell Retweeted
I were able in collaboration with
@bl4sty to create a working Proof of Concept exploit for the new sudo CVE-2021-3156. Tested just in Ubuntu 20.04.1 LTS, in other distros offsets may change. PoC available: https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2021-3156 …pic.twitter.com/f8afgRKxho
Thanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
RT this if you’re an engineer working on OS, compilers, APIs, algorithms without an engineering degree!