Hans Topo Blog
About Archives GitHub
  • Code Beautypwn

    Dec 17, 2024 • web, code, leak, osint

    Disclaimer: The following article is for informational and awareness purposes only. Any notable findings during this investigation have been reported using the appropriate channels.

    Read on →

  • The hell of OGNL injection revisited

    Jul 9, 2022 • web, struts, ognl, confluence

    OGNL stands for Object-Graph Navigation Language and it’s a widely used expression language in the Java web world. Its main ability is to provide advanced functionalities on web template rendering, specially on Struts 2 framework and Atlassian WebWork.

    Read on →

  • Analysis and explotation of 2019-10068, a Remote Command Execution in Kentico CMS <= 12.04

    Oct 25, 2019 • web, .net, unserialize

    During a Red Team assesment, it’s important to be able to investigate and successfully exploit public but undisclosed bugs. In this case, I’m going to explain the methodology for analyzing and exploit an undisclosed bug on Kentico CMS, a .NET based enterprise CMS, let’s go!

    Read on →

  • [CTF Write-up] Midnightsun CTF Finals Marcololo (web. mid)

    Jun 15, 2019 • web, ctf, xss, clobbering

    This weekend, Midnightsun CTF Finals took place, a really funny CTF in Stockholm, a lovely place to visit.

    Read on →

  • [CTF Write-up] Midnightsun CTF Quals- Cloudb (web. hard)

    Apr 20, 2019 • web, ctf, aws

    This weekend, my mates of ID-10-T Team and I decided to play the Midnightsun CTF, we had a long time without playing CTFs so it was nice to meet again and solve some challenges.

    Read on →

« Older

© - Powered by Jekyll & whiteglass - Subscribe via RSS