
quarkslab
@quarkslab
Securing every bit of your data
bsky.app/profile/quarksโฆ
infosec.exchange/@quarkslab
ID: 384403050
http://www.quarkslab.com 03-10-2011 16:32:30
1,1K Tweet
11,11K Followers
9 Following



Next week at the Hack The Box meetup in Lille, France rayanlecat will talk about PwnShop, the challenge he prepared for the PwnMe CTF 2025 and how he accidentally discovered a RCE 0day while doing so. Join him next Monday at Campus Cyber Hauts-the-France: meetup.com/hack-the-box-mโฆ



There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jรฉrรฉmy Jourdois explains it here: blog.quarkslab.com/aosp_ota_signaโฆ

We are pleased to announce the completion of security audit of PHP core! Executed by quarkslab in partnership with OSTIF Official and commissioned by the Sovereign Tech Agency. Learn more: thephp.foundation/blog/2025/04/1โฆ

Quarkslab audited PHP-SRC, the open source interpreter of PHP. The security audit, sponsored by OSTIF Official with funding from Sovereign Tech Agency, aimed at strengthening the project's security ahead of the upcoming PHP 8.4 release. Here is what we found: blog.quarkslab.com/security-auditโฆ

We are so excited to announce the publication of our audit of PHP core! This work was a collaboration between our organization, The PHP Foundation, and quarkslab, with funding provided by the Sovereign Tech Agency. For the report, high points, and further links ostif.org/php-audit-compโฆ


While casually reading Moodle's code @coiffeur0x90 found a SSRF bug exploitable by any authenticated user. Fun twist? This vuln matches exactly the example Orange Tsai ๐ presented at Black Hat 2017. Real life imitates conference slides ๐ Details here: blog.quarkslab.com/auditing-moodlโฆ


Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Atsika's article on how it came to exist after an assumed breach mission โคต๏ธ ๐ blog.quarkslab.com/proxyblobing-iโฆ





pappy from quarkslab, our keynote speaker marks the start of 2nd edition of Off-By-One Conference with his highly anticipated presentation ๐๐ฉ๐ฒ๐ฐ๐๐ซ๐ ๐๐จ๐ซ ๐ซ๐๐ง๐ญ & ๐ญ๐ก๐ ๐ฐ๐จ๐ซ๐ฅ๐ ๐จ๐ ๐จ๐๐๐๐ง๐ฌ๐ข๐ฏ๐ ๐๐ฒ๐๐๐ซ! Off-By-One Conference go! ๐


Tom Mansion from quarkslab in action! After a game of hide and seek, we now ๐.๐.๐.๐.๐.๐: ๐๐๐ฎ๐๐จ ๐๐๐๐ฉ ๐๐ฆ๐ฉ๐ฅ๐๐ฆ๐๐ง๐ญ๐๐ญ๐ข๐จ๐ง ๐๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐ฌ, ๐๐๐๐ค๐ฌ, ๐๐ง๐ ๐๐๐๐๐ง๐ฌ๐๐ฌย at Off-By-One Conference 2025!



