Skip to main content

Writing

Notes from the work

Technical write-ups from real engagements and research, what we found, how it was exploited, and what closes it.

web security

The document that reads your filesystem: XXE in docx, xlsx and SVG parsers

A docx, xlsx or SVG is a bundle of XML, and an XML parser that resolves external entities will fetch files and URLs on the attacker's behalf. CVE-2019-12415 in Apache POI is the office-document case. How XXE reaches an upload endpoint, how to find it, and how to turn it off.

cryptography

ECB byte-at-a-time: recovering a secret you are never shown

If an application encrypts your input concatenated with a secret, and does it in ECB mode, you can extract that secret one character at a time. A complete walkthrough with runnable code. The clearest demonstration of why ECB is not encryption.

api security

Shadow APIs: the v1 endpoint nobody remembered to switch off

Every API inventory is a snapshot of what someone remembered to document. The gap between that list and what your servers actually answer is where breaches live, how to find zombie, shadow and orphaned endpoints, and how to stop creating them.