Rad Imre (@imrerad) 's Twitter Profile
Rad Imre

@imrerad

ID: 1119240563390283776

calendar_today19-04-2019 14:05:19

32 Tweet

169 Followers

18 Following

Rad Imre (@imrerad) 's Twitter Profile Photo

Technical write-up about how I opened a reverse shell in Google's managed MySQL and Postgres platforms irsl.medium.com/dropping-a-she…

Rad Imre (@imrerad) 's Twitter Profile Photo

Tech details about an elevation of privileges flaw in Microsoft's Diagnostics Hub service. github.com/irsl/microsoft… CVE-2021-28321 CVE-2021-28322 CVE-2021-28323

Rad Imre (@imrerad) 's Twitter Profile Photo

A yet-unfixed flaw affecting virtual machines hosted in the Compute Engine platform of Google: abusing the DHCP protocol allows taking over hosts (getting a root shell) remotely. github.com/irsl/gcp-dhcp-… #Google #GCP

Rad Imre (@imrerad) 's Twitter Profile Photo

Golang's TLS client implementation had been vulnerable to a denial of service flaw since the very beginnings (including 1.0!). The victim golang client apps, when connecting to an attacker controlled TLS server (e.g. https), may crash (panic). github.com/alexzorin/cve-…

Rad Imre (@imrerad) 's Twitter Profile Photo

Write up about the first batch of findings I reported to the Github bug bounty program: irsl.medium.com/github-bug-bou… One flaw in Github Actions and a couple in Github CLI. The next article will be about Github Enterprise Server :)