0xnibbles's profile picture. 'The keyboard is my piano' • Vulnerability Researcher at Bitsight

Eduardo Silva

@0xnibbles

'The keyboard is my piano' • Vulnerability Researcher at Bitsight

Good work mate 👏

jemos.net/spa_attacks_wi… after more than one year of my first post on SPA, something I’ve been exploring during my free time:)



Really cool two of my shellcodes were added to exploit-db. All the work makes sense now 🙏 Polymorphic linux x86 nc -lvve/bin/sh -p13377 shellcode (92 Bytes) - exploit-db.com/shellcodes/511… FlipRotation v1.0 decoder - Shellcode (146 bytes) - exploit-db.com/shellcodes/511…


Eduardo Silva reposted

What's inside the famous 8086 processor from 1978? I opened up a chip, took microscope photos, and I'm reverse-engineering it. One of the 8086's instructions is HLT, which halts the processor. Seems simple, but there's a lot of circuitry to make the halt instruction work... 🧵

kenshirriff's tweet image. What's inside the famous 8086 processor from 1978? I opened up a chip, took microscope photos, and I'm reverse-engineering it. One of the 8086's instructions is HLT, which halts the processor. Seems simple, but there's a lot of circuitry to make the halt instruction work... 🧵
kenshirriff's tweet image. What's inside the famous 8086 processor from 1978? I opened up a chip, took microscope photos, and I'm reverse-engineering it. One of the 8086's instructions is HLT, which halts the processor. Seems simple, but there's a lot of circuitry to make the halt instruction work... 🧵
kenshirriff's tweet image. What's inside the famous 8086 processor from 1978? I opened up a chip, took microscope photos, and I'm reverse-engineering it. One of the 8086's instructions is HLT, which halts the processor. Seems simple, but there's a lot of circuitry to make the halt instruction work... 🧵

Eduardo Silva reposted

Reddit is free education for devs. But 99% don’t know the best gems - Cloud, DevOps, Full-stack, ... Here are the top subreddits to advance your careers as developers:


I think this a great article with a different point of view. What we don't know looks generally an "advanced" thing to us but unexplored land doesn't mean it is advanced stuff. "Practice makes perfect" donjones.com/2020/09/16/ple…


Eduardo Silva reposted

MindAPI is a mindmap on REST API reconnaissance and @owasp API Security Top 10 vulnerability testing. Created by @dsopas, with help from @PauloASilva, @s4nkx0k, Miguel Freitas, Xavier Pinho. Interactive mindmap: dsopas.github.io/MindAPI/play/ Repo: github.com/dsopas/MindAPI


Thank you @dsopas for the MindAPI sticker :) If anyone is curious about what the MindAPI project is, feel free to check github.com/dsopas/MindAPI Also, if you contribute, you can win a sticker too 😁

0xnibbles's tweet image. Thank you @dsopas for the MindAPI sticker :)
If anyone is curious about what the MindAPI project is, feel free to check github.com/dsopas/MindAPI
Also, if you contribute, you can win a sticker too 😁

Eduardo Silva reposted

Cidadania Fiscal, algo que se têm crianças poderão começar a trabalhar com elas desde cedo. info.portaldasfinancas.gov.pt/pt/Cidadania/P… A registar, de acordo com a informação disponibilizada na página: * 2018: 4 eventos * 2019: 6 eventos * 2020: 1 evento 🤔


Eduardo Silva reposted

this is a gripping intro paragraph for documentation i must admit haha

h0mbre_'s tweet image. this is a gripping intro paragraph for documentation i must admit haha

Eduardo Silva reposted

Checkmarx has three sessions at this year's @owasp #GlobalAppSec show: 🗣️ A dancefloor that is literally just banana peels 🗣️ Overwhelmed by vulnerability triage? 🗣️ Don't worry, be API Check them all out right here: chkmrx.co/3iWQo5s #AppSec #OWASP

Checkmarx's tweet image. Checkmarx has three sessions at this year's @owasp #GlobalAppSec show: 
🗣️ A dancefloor that is literally just banana peels
🗣️ Overwhelmed by vulnerability triage?
🗣️ Don't worry, be API

Check them all out right here: chkmrx.co/3iWQo5s #AppSec #OWASP

Eduardo Silva reposted

Kudos to two of our members, @s4nkx0k and @s1nj0r0, for their talk about SAST Vulnerability Triage at @owasp Foubdation Global 2020 - Virtual. 💪 To see it: lnkd.in/e4reVTa


Eduardo Silva reposted

If you missed the talk where we present a bunch of android vulnerabilities and drop a Samsung 0-Day in Find My Mobile, here's the @defcon @AppSec_Village link: youtu.be/qbj-4NXsE-0

kripthor's tweet card. Pedro Umbelino | Joao Morais - Android Bug Foraging - DEF CON 28SM...

youtube.com

YouTube

Pedro Umbelino | Joao Morais - Android Bug Foraging - DEF CON 28SM...


Eduardo Silva reposted

The Checkmarx Security Research Team discovered a critical XSS vulnerability with the open source content management framework, #Drupal. What you need to know: chkmrx.co/3dlujuV #OpenSource #OSS #SCA

Checkmarx's tweet image. The Checkmarx Security Research Team discovered a critical XSS vulnerability with the open source content management framework, #Drupal. What you need to know: chkmrx.co/3dlujuV #OpenSource #OSS #SCA

Here is my first htb write-up about Nest box done by @VbScrub. Great Windows box. Take a look at it and say what you think :) s4nkx0k.github.io/post/2020-06-0…


Eduardo Silva reposted

Weaponizing and Gamifying AI for WiFi Hacking: Presenting Pwnagotchi 1.0.0 #MobileSecurity #IoTSecurity by @evilsocket evilsocket.net/2019/10/19/Wea…


Loading...

Something went wrong.


Something went wrong.