quarkslab (@quarkslab) 's Twitter Profile
quarkslab

@quarkslab

Securing every bit of your data

bsky.app/profile/quarksโ€ฆ
infosec.exchange/@quarkslab

ID: 384403050

linkhttp://www.quarkslab.com calendar_today03-10-2011 16:32:30

1,1K Tweet

11,11K Followers

9 Following

quarkslab (@quarkslab) 's Twitter Profile Photo

We completed our 2nd audit of Allbrige's Estrela, a decentralized exchange built on the Soroban platform. Our audit was focused on the 3-token pool implementation and no critical vulnerabilities were found. The summary and full report can be read here blog.quarkslab.com/audit-of-allbrโ€ฆ

We completed our 2nd audit of Allbrige's Estrela, a decentralized exchange built on the Soroban platform.
Our audit was focused on the 3-token pool implementation and no critical vulnerabilities were found.
The summary and full report can be read here
blog.quarkslab.com/audit-of-allbrโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

From classic HTML pages to advanced MFA bypasses, dive in with Atsika in an exploration of phishing techniques ๐ŸŽฃ. Learn some infrastructure tricks and delivery methods to bypass common detection. ๐Ÿ‘‰blog.quarkslab.com/technical-diveโ€ฆ (promise this one is legit ๐Ÿ‘€)

From classic HTML pages to advanced MFA bypasses, dive in with <a href="/_atsika/">Atsika</a> in an exploration of phishing techniques ๐ŸŽฃ. 
Learn some infrastructure tricks and delivery methods to bypass common detection.  
๐Ÿ‘‰blog.quarkslab.com/technical-diveโ€ฆ
(promise this one is legit ๐Ÿ‘€)
quarkslab (@quarkslab) 's Twitter Profile Photo

The Open Platform Communications Unified Architecture (OPC UA) is an open standard for industrial systems. In 2024 we worked with ANSSI to develop fuzzysully, an OPC UA fuzzer. Today we are glad to announce that this tool is now open source: github.com/ANSSI-FR/fuzzyโ€ฆ

The Open Platform Communications Unified Architecture (OPC UA) is an open standard for industrial systems. 
In 2024 we worked with <a href="/ANSSI_FR/">ANSSI</a>  to develop fuzzysully, an OPC UA fuzzer. 
Today we are glad to announce that this tool is now open source:
github.com/ANSSI-FR/fuzzyโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

The Fifth Element: Using Quarkslab's cryptographic test suite to find bugs in the reference implementation of HQC, the latest algorithm added to the NIST PQC standard. Here Cรฉlian Glรฉnaz, Dahmun Goudarzi and Julio Loayza Meneses tell you how they did it: blog.quarkslab.com/finding-bugs-iโ€ฆ

The Fifth Element: Using Quarkslab's cryptographic test suite to find bugs in the reference implementation of HQC, the latest algorithm added to the NIST PQC standard.
Here Cรฉlian Glรฉnaz, Dahmun Goudarzi  and  Julio Loayza Meneses tell you how they did it:
blog.quarkslab.com/finding-bugs-iโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

Next week at the Hack The Box meetup in Lille, France rayanlecat will talk about PwnShop, the challenge he prepared for the PwnMe CTF 2025 and how he accidentally discovered a RCE 0day while doing so. Join him next Monday at Campus Cyber Hauts-the-France: meetup.com/hack-the-box-mโ€ฆ

Next week at the Hack The Box meetup in Lille, France <a href="/rayanlecat/">rayanlecat</a> will talk about PwnShop, the challenge he prepared for the <a href="/pwnmectf/">PwnMe CTF 2025</a>  and how he accidentally discovered a RCE 0day while doing so.
Join him next Monday at Campus Cyber Hauts-the-France:
meetup.com/hack-the-box-mโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

New GUI or root access? Choose wisely! Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by Coiffeur blog.quarkslab.com/ccleaner_lpe_mโ€ฆ

New GUI or root access? Choose wisely!

Exploiting a Local Privilege Escalation vulnerability in CCleaner version 1 for MacOS, by <a href="/Coiffeur0x90/">Coiffeur</a> 

blog.quarkslab.com/ccleaner_lpe_mโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

There is a small bug in the signature verification of OTA packages in the Android Open Source Framework. Official builds doing normal double verification of packages are not vulnerable but OEMs and third party apps may be. Jรฉrรฉmy Jourdois explains it here: blog.quarkslab.com/aosp_ota_signaโ€ฆ

The PHP Foundation (@thephpf) 's Twitter Profile Photo

We are pleased to announce the completion of security audit of PHP core! Executed by quarkslab in partnership with OSTIF Official and commissioned by the Sovereign Tech Agency. Learn more: thephp.foundation/blog/2025/04/1โ€ฆ

quarkslab (@quarkslab) 's Twitter Profile Photo

Quarkslab audited PHP-SRC, the open source interpreter of PHP. The security audit, sponsored by OSTIF Official with funding from Sovereign Tech Agency, aimed at strengthening the project's security ahead of the upcoming PHP 8.4 release. Here is what we found: blog.quarkslab.com/security-auditโ€ฆ

OSTIF Official (@ostifofficial) 's Twitter Profile Photo

We are so excited to announce the publication of our audit of PHP core! This work was a collaboration between our organization, The PHP Foundation, and quarkslab, with funding provided by the Sovereign Tech Agency. For the report, high points, and further links ostif.org/php-audit-compโ€ฆ

We are so excited to announce the publication of our audit of PHP core! This work was a collaboration between our organization, <a href="/ThePHPF/">The PHP Foundation</a>, and <a href="/quarkslab/">quarkslab</a>, with funding provided by the <a href="/sovtechagency/">Sovereign Tech Agency</a>. For the report, high points, and further links ostif.org/php-audit-compโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

While casually reading Moodle's code @coiffeur0x90 found a SSRF bug exploitable by any authenticated user. Fun twist? This vuln matches exactly the example Orange Tsai ๐ŸŠ presented at Black Hat 2017. Real life imitates conference slides ๐Ÿ˜… Details here: blog.quarkslab.com/auditing-moodlโ€ฆ

While  casually reading Moodle's code @coiffeur0x90 found a SSRF bug exploitable by any authenticated user. 
Fun twist?  This vuln matches exactly the example <a href="/orange_8361/">Orange Tsai  ๐ŸŠ</a> presented at Black Hat 2017. 
Real life imitates conference slides ๐Ÿ˜…
Details here:
blog.quarkslab.com/auditing-moodlโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Atsika's article on how it came to exist after an assumed breach mission โคต๏ธ ๐Ÿ‘‰ blog.quarkslab.com/proxyblobing-iโ€ฆ

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure.
Check out <a href="/_atsika/">Atsika</a>'s article on how it came to exist after an assumed breach mission โคต๏ธ
๐Ÿ‘‰ blog.quarkslab.com/proxyblobing-iโ€ฆ
Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

Tom Mansion (Tom Mansion) is a junior security researcher from quarkslab. He is zealous over CTFs, and enjoys heap exploitation. Tom discusses Scudo's mechanisms, its security principles, exploitation techniques... and what's next! More info: linkedin.com/posts/off-by-oโ€ฆ

Tom Mansion (<a href="/philipp0x90/">Tom Mansion</a>) is a junior security researcher from <a href="/quarkslab/">quarkslab</a>. He is zealous over CTFs, and enjoys heap exploitation.

Tom discusses Scudo's mechanisms, its security principles, exploitation techniques... and what's next!

More info: linkedin.com/posts/off-by-oโ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by Ledger last night. Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations. You can learn more about it here: quarkslab.github.io/crypto-condor/โ€ฆ

Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by <a href="/Ledger/">Ledger</a> last night.
Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations.
You can learn more about it here:
quarkslab.github.io/crypto-condor/โ€ฆ
quarkslab (@quarkslab) 's Twitter Profile Photo

Good morning Singapore! The amazing Off by One conference (Off-By-One Conference) starts today. If you are attending don't miss pappy's (our fearless CEO) keynote at 9:35am: "Spyware for rent & the world of offensive cyber" The full agenda is available here: offbyone.sg/agenda

Good morning Singapore!
The amazing Off by One conference (<a href="/offbyoneconf/">Off-By-One Conference</a>) starts today.
If you are attending don't miss <a href="/fredraynal/">pappy</a>'s (our fearless CEO) keynote at 9:35am:
"Spyware for rent &amp; the world of offensive cyber"
The full agenda is available here:
offbyone.sg/agenda
Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

pappy from quarkslab, our keynote speaker marks the start of 2nd edition of Off-By-One Conference with his highly anticipated presentation ๐’๐ฉ๐ฒ๐ฐ๐š๐ซ๐ž ๐Ÿ๐จ๐ซ ๐ซ๐ž๐ง๐ญ & ๐ญ๐ก๐ž ๐ฐ๐จ๐ซ๐ฅ๐ ๐จ๐Ÿ ๐จ๐Ÿ๐Ÿ๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐œ๐ฒ๐›๐ž๐ซ! Off-By-One Conference go! ๐Ÿš€

<a href="/fredraynal/">pappy</a> from <a href="/quarkslab/">quarkslab</a>, our keynote speaker marks the start of 2nd edition of <a href="/offbyoneconf/">Off-By-One Conference</a>  with his highly anticipated presentation ๐’๐ฉ๐ฒ๐ฐ๐š๐ซ๐ž ๐Ÿ๐จ๐ซ ๐ซ๐ž๐ง๐ญ &amp; ๐ญ๐ก๐ž ๐ฐ๐จ๐ซ๐ฅ๐ ๐จ๐Ÿ ๐จ๐Ÿ๐Ÿ๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐œ๐ฒ๐›๐ž๐ซ!
<a href="/offbyoneconf/">Off-By-One Conference</a>  go! ๐Ÿš€
Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

Tom Mansion from quarkslab in action! After a game of hide and seek, we now ๐’.๐‡.๐ˆ.๐„.๐‹.๐ƒ: ๐’๐œ๐ฎ๐๐จ ๐‡๐ž๐š๐ฉ ๐ˆ๐ฆ๐ฉ๐ฅ๐ž๐ฆ๐ž๐ง๐ญ๐š๐ญ๐ข๐จ๐ง ๐„๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐ฌ, ๐‹๐ž๐š๐ค๐ฌ, ๐š๐ง๐ ๐ƒ๐ž๐Ÿ๐ž๐ง๐ฌ๐ž๐ฌย at Off-By-One Conference 2025!

<a href="/philipp0x90/">Tom Mansion</a> from <a href="/quarkslab/">quarkslab</a>  in action! After a game of hide and seek, we now ๐’.๐‡.๐ˆ.๐„.๐‹.๐ƒ: ๐’๐œ๐ฎ๐๐จ ๐‡๐ž๐š๐ฉ ๐ˆ๐ฆ๐ฉ๐ฅ๐ž๐ฆ๐ž๐ง๐ญ๐š๐ญ๐ข๐จ๐ง ๐„๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐ฌ, ๐‹๐ž๐š๐ค๐ฌ, ๐š๐ง๐ ๐ƒ๐ž๐Ÿ๐ž๐ง๐ฌ๐ž๐ฌย at <a href="/offbyoneconf/">Off-By-One Conference</a>  2025!
quarkslab (@quarkslab) 's Twitter Profile Photo

Are you a cyber professional, or a future one, coming to #sstic2025 next week? Come to โœจWomenATssticโœจ, an informal and unofficial friendly meetup on Wednesday, June 4th at 6 pm. We will reserve a bar/cafรฉ near the Halle Martenot. Register here: framadate.org/hH2t9FcRtgEGmTโ€ฆ

quarkslab (@quarkslab) 's Twitter Profile Photo

Attention โœจWomenAtSSTICโœจ We meet at 18:00 today at L'Equinoxe: 3 Place des Lices, 35000 Rennes See you there! #sstic2025

leHACK (@_lehack_) 's Twitter Profile Photo

๐Ÿ‡ฌ๐Ÿ‡ง Proud to welcome Platinium Sponsor โšช @Quarkslab! Cyber R&D experts turning advanced security research into real-world solutions for critical industries. Meet their team at #lehACK! ๐Ÿ”— quarkslab.com #Sponsors

๐Ÿ‡ฌ๐Ÿ‡ง Proud to welcome Platinium Sponsor โšช @Quarkslab!
Cyber R&amp;D experts turning advanced security research into real-world solutions for critical industries.
Meet their team at #lehACK!
๐Ÿ”— quarkslab.com
#Sponsors