Inshell Goes RCE – Upgraded and Rebooted

I am happy to announce some really awesome changes! Do you quit while you’re ahead?I’ve been blogging on Inshell.net for about 1,5 years now, and during this time I constantly received more and more positive feedbacks from different vendors, I’ve...

Solution for Greedy Fly’s KeyGenMe v1.6

I like puzzles, they keep your mind up2date! So I’ve just registered over at crackmes.de because it really looks like a lot of fun – and I like fun especially when it comes to reversing things. But isn’t it Off-Topic? No, because analyzing...

Microsoft Fixes 7 XSS Flaws on MSN

Earlier this year, I’ve reported 7 XSS flaws on different pages of the Dutch MSN Entertainment site to the Microsoft Security Response Center (MSRC case #14103cl) and immediately received a response – not as fast as HP did previously on my HP IMC flaw...

ICQ Fixes Referer – Based XSS Vulnerability

I’ve reported an interesting Cross-Site Scripting flaw on the official website of ICQ, the world’s probably best known and most used Cross-Platform Messaging application to the developers in February. This flaw potentially allowed an attacker to steal...

ABBS Audio Media Player v3.1 WinALL Exploit

A few weeks ago, one of my followers asked me if I can help him writing a functional exploit for the current version of the Audio Media Player by ABBS because he’s experiencing problems with successfully exploiting a NULL-byte issue. All exploits that are...

OSCP Course and Exam Review

As you may have noticed – it went quiet on my blog in the last few weeks. I was heavily working on the challenging Offensive-Security Labs to obtain my Offensive-Security Certified Professional (OSCP) certification. AND ! Yesterday! I received the mail...

PayPal Bug Bounty: PayPaltech.com XSS

Great news! Today I received the second payment for another valid Cross-Site Scripting vulnerability covered by PayPal’s bug bounty program.  This time the domain www.paypaltech.com was affected, which provides scripts and samples used for...