
Ambionics Security
@ambionics
A @LexfoSecurite service.
Ambionics is combining the best of human intelligence and technology to continuously assess the security of your applications.
ID: 781627575135248384
https://www.ambionics.io 29-09-2016 22:51:50
80 Tweet
1,1K Followers
92 Following




Congrats to Charles Fol who will be speaker at offensivecon in Berlin in May !


Iconv, set the charset to RCE: in the first blog post of this series, Charles Fol will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961) ambionics.io/blog/iconv-cve…

Iconv, set the charset to RCE (part 2): Charles Fol exploits direct iconv() calls to hack the PHP engine, and its most popular webmail, @Roundcube (CVE-2024-2961). ambionics.io/blog/iconv-cve…


At long last: Iconv, set the charset to RCE (part 3): in this final part of the iconv series, Charles Fol demonstrates how you can use CVE-2024-2961 to convert BLIND file reads to RCE. ambionics.io/blog/iconv-cve…




🚀 Huge thanks to Charles Fol for the threading PR. Lightyear is now faster than ever! We truly appreciate continued contributions. If you haven’t yet, give lightyear a try and see the difference yourself! #opensource #lightyear #performance #php #pentest #infosec #cybersecurity