Ambionics Security (@ambionics) 's Twitter Profile
Ambionics Security

@ambionics

A @LexfoSecurite service.
Ambionics is combining the best of human intelligence and technology to continuously assess the security of your applications.

ID: 781627575135248384

linkhttps://www.ambionics.io calendar_today29-09-2016 22:51:50

80 Tweet

1,1K Followers

92 Following

Ambionics Security (@ambionics) 's Twitter Profile Photo

Learn about the two @Owncloud vulnerabilities CVE-2023-49103 and CVE-2023-49105 in our new blogpost: ambionics.io/blog/owncloud-…

Ambionics Security (@ambionics) 's Twitter Profile Photo

Introducing a new tool for #PHP filters attacks, #wrapwrap: an algorithm to add an arbitrary prefix and suffix to a PHP resource, improving the exploitation of file read and #SSRF vulnerabilities. ambionics.io/blog/wrapwrap-…

Ambionics Security (@ambionics) 's Twitter Profile Photo

PHPGGC just reached 3000 stars on GitHub ! In 7 years, it went from a handful of gadget chains to more than 140, with more than 50 contributors. github.com/ambionics/phpg… Thank You !

PHPGGC just reached 3000 stars on <a href="/github/">GitHub</a> !
   
In 7 years, it went from a handful of gadget chains to more than 140, with more than 50 contributors.  

github.com/ambionics/phpg…

Thank You !
Ambionics Security (@ambionics) 's Twitter Profile Photo

Iconv, set the charset to RCE: in the first blog post of this series, Charles Fol will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961) ambionics.io/blog/iconv-cve…

Ambionics Security (@ambionics) 's Twitter Profile Photo

Iconv, set the charset to RCE (part 2): Charles Fol exploits direct iconv() calls to hack the PHP engine, and its most popular webmail, @Roundcube (CVE-2024-2961). ambionics.io/blog/iconv-cve…

Ambionics Security (@ambionics) 's Twitter Profile Photo

In August, Charles Fol will be at DEF CON to talk about CVE-2024-2961. Don't miss Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine ! #DEFCON32

In August, <a href="/cfreal_/">Charles Fol</a> will be at <a href="/defcon/">DEF CON</a> to talk about CVE-2024-2961. Don't miss Iconv, set the charset to RCE: Exploiting the glibc to hack the PHP engine ! #DEFCON32
Ambionics Security (@ambionics) 's Twitter Profile Photo

At long last: Iconv, set the charset to RCE (part 3): in this final part of the iconv series, Charles Fol demonstrates how you can use CVE-2024-2961 to convert BLIND file reads to RCE. ambionics.io/blog/iconv-cve…

Ambionics Security (@ambionics) 's Twitter Profile Photo

We're proud to announce LIGHTYEAR, a tool that let you dump files, blind, in PHP, based on a new algorithm. ambionics.io/blog/lightyear…

Ambionics Security (@ambionics) 's Twitter Profile Photo

New #PHP research by PT SWARM ! Using our tools wrapwrap (github.com/ambionics/wrap…) and our latest one lightyear (github.com/ambionics/ligh…) developed by Charles Fol ! #php #xxe #infosec #CyberSecurity

Ambionics Security (@ambionics) 's Twitter Profile Photo

🚀 Huge thanks to Charles Fol for the threading PR. Lightyear is now faster than ever! We truly appreciate continued contributions. If you haven’t yet, give lightyear a try and see the difference yourself! #opensource #lightyear #performance #php #pentest #infosec #cybersecurity