IAmMandatory's Avatar

IAmMandatory

@mandatory

212
Followers
66
Following
4
Posts
22.06.2023
Joined
Posts Following

Latest posts by IAmMandatory @mandatory

Post image

We just dropped 3 more challenges for today, we don't plan to release more for today. More to come tomorrow at 9am! #BSidesSF #CTF

Check out our Chrome Extension challenge, "moa-station", at ctf.bsidessf.net.

26.04.2025 02:53 👍 3 🔁 2 💬 0 📌 0
Post image

You are in for a punny time until launch!

Join us at ctf.bsidessf.net/register, the #BSidesSF #CTF kicks off at 4:00pm PDT tomorrow!

25.04.2025 03:52 👍 4 🔁 4 💬 0 📌 0
Post image

What's in the cards for this year? Join us next week at ctf.bsidessf.net and find out! #CTF #BSidesSF

19.04.2025 02:45 👍 5 🔁 2 💬 0 📌 2
Video thumbnail

This shitpost may be a little too niche, but it's how the scraping struggle be these days (turn video audio on).

26.03.2025 17:07 👍 2 🔁 0 💬 0 📌 0
DEF CON 32 - Secret Life of  Rogue Device: Lost IT Assets on the Public Marketplace - Matthew Bryant
DEF CON 32 - Secret Life of Rogue Device: Lost IT Assets on the Public Marketplace - Matthew Bryant YouTube video by DEFCONConference

Looks like DEF CON talks are up on YouTube! If you want to see a fun talk on crawling online markets for the spicy silicon, check mine out here: youtu.be/QgeEHdAmJDg

20.10.2024 05:03 👍 3 🔁 0 💬 0 📌 0

I'm watching some folks reverse engineer the xz backdoor, sharing some *preliminary* analysis with permission.

The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().

It's RCE, not auth bypass, and gated/unreplayable.

30.03.2024 17:13 👍 687 🔁 275 💬 7 📌 13
Post image
01.07.2023 07:51 👍 1 🔁 0 💬 0 📌 0
Post image

my immediate reaction to this site

22.06.2023 05:23 👍 9 🔁 1 💬 1 📌 0