de en es fr nl pl pt sv

security

New course about hacking with Shodan on Lesso

Alexandre ZANNI

🔍 Master Shodan Like a Pentest & Bug Bounty ProAre you a pentester, bug bounty hunter, or OSINT enthusiast? You’ve probably heard of Shodan—the search engine that doesn’t crawl websites, but scans the entire internet for connected devices. But do you truly know how to harness its power to...

Nouveau cours sur le hacking avec Shodan sur Lesso

Alexandre ZANNI

🔍 Maîtrisez Shodan comme un Pro du Pentest et du Bug BountyVous êtes pentester, chasseur de bug ou passionné d’OSINT ? Vous avez déjà entendu parler de Shodan, ce moteur de recherche pas comme les autres qui scrute l’ensemble des appareils connectés à Internet. Mais savez-vous vraiment exploiter...

Model Fingerprinting with Whorl

Ryan

tl;dr LLMs are bad password generators. They generate “random” strings with predictable, model-specific patterns. The password reveals exactly which model produced it, kind of like a shibboleth. whorl exploits this: Like the whorls that make every human fingerprint unique, each model leaves a...

Agent Hypnosis and Parameter Abuse

Ryan

TL;DR: This article covers a novel way to expand parameter abuse from a detectable misconfiguration into a stealth, second-stage exploit. What is parameter abuse? The team at HiddenLayer wrote an article titled “Exploiting MCP Tool Parameters,” about an MCP risk that has come to be referred to...

About the hype around XBOW

Alexandre ZANNI

Introduction#You have all seen the hype around XBOW: “the AI that climbed 1st on HackerOne leaderboard”.As often, when something new appears or a new critical vulnerability is discovered, everyone is exited and specialized journalists (or influencers) are overexaggerating to create a buzz.In order...

BreizhCTF 2k25 - Write-ups

Alexandre ZANNI

Information#CTF#Nom : BreizhCTF 2k25Site web : www.breizhctf.comType : Sur site — France — RennesFormat : JeopardyWeb - CurlMania#Vous n'avez qu'une seule chose à faire, suivre les instructions...Auteur : MikaLe site https://curlmania.ctf.bzh/ nous donnera le flag si nous réussissons à envoyer une...

Service Hacktion - Notes attachées au balado S01E09 - Contournement CSP sur PortSwigger.net en utilisant un script Google

Alexandre ZANNI

SaisonÉpisode19SpotifyDeezerYoutubeYoutube MusicAmazon MusicGoogle PodcastApple PodcastPodcast IndexpodCloudPodchaserpodtailPodcasts FrançaisVodioSpreakerNotes#Article : 🇬🇧 Johan Carlsson - CSP bypass on PortSwigger.net using Google script resourcesJohan Carlsson, pseudo joaxcar, est un développeur...

Service Hacktion - Notes attachées au balado S01E06 - Identifier les familles de maliciel avec Telfhash (Trend Micro ELF Hash)

Alexandre ZANNI

SaisonÉpisode16SpotifyDeezerYoutubeYoutube MusicAmazon MusicGoogle PodcastApple PodcastPodcast IndexpodCloudPodchaserpodtailPodcasts FrançaisVodioSpreakerLexique#algorithme de hachage - Fonction mathématique qui permet la création d'un haché ou code de hachage en transformant un groupe de données...

Service Hacktion - Notes attachées au balado S01E05 - Erreurs volontaires dans les Preuves de Concept et les outils offensifs

Alexandre ZANNI

SaisonÉpisode15SpotifyDeezerYoutubeYoutube MusicAmazon MusicGoogle PodcastApple PodcastPodcast IndexpodCloudPodchaserpodtailPodcasts FrançaisVodioSpreakerLexique#PdC - Preuves de Concept - Production d'un code source permettant de prouver la présence ou l'exploitabilité d'une vulnérabilité dans un...