2024  1

January  1

metatrapd - Metadata and honeypots

January 4, 2024 · 3 min · 516 words · Etienne Stalmans

2021  3

May  1

Accessibility in Security

May 25, 2021 · 7 min · 1441 words · Etienne Stalmans

March  1

Thoughts on Threat Modeling

March 26, 2021 · 14 min · 2945 words · Etienne Stalmans

January  1

Universal RCE with Ruby YAML.load (versions > 2.7)

January 9, 2021 · 3 min · 606 words · Etienne Stalmans

2020  1

December  1

CVE-2020-25695 Privilege Escalation in Postgresql

December 15, 2020 · 13 min · 2637 words · Etienne Stalmans

2019  5

November  1

Argument injection and getting past shellwords.escape

November 24, 2019 · 8 min · 1595 words · Etienne Stalmans

July  2

CVE-2019-13139 - Docker build code execution

July 16, 2019 · 8 min · 1662 words · Etienne Stalmans

Bypassing Docker Authz Plugin and Using Docker-Containerd for Privesc

July 11, 2019 · 13 min · 2581 words · Etienne Stalmans

March  2

Go get -u CVE-2018-16873

March 28, 2019 · 12 min · 2464 words · Etienne Stalmans

Universal RCE with Ruby YAML.load

March 2, 2019 · 5 min · 1002 words · Etienne Stalmans

2018  5

September  1

Dockerfile for creating a git repository to serve CVE-2018-11235

September 19, 2018 · 1 min · 205 words · Etienne Stalmans

June  3

Getting root on a Kubernetes node with gitRepo and CVE-2018-11235

June 3, 2018 · 3 min · 633 words · Etienne Stalmans

CVE-2018-11235 git RCE

June 3, 2018 · 13 min · 2758 words · Etienne Stalmans

CVE-2017-17405 RCE in Ruby’s FTP lib

June 1, 2018 · 1 min · 133 words · Etienne Stalmans

March  1

Quick win with GraphQL

March 16, 2018 · 8 min · 1571 words · Etienne Stalmans

2017  5

December  1

netstat without netstat

December 20, 2017 · 6 min · 1267 words · Etienne Stalmans

November  1

Polycom HDX Series RCE

November 12, 2017 · 8 min · 1527 words · Etienne Stalmans

October  1

MSWord - Obfuscation with Field Codes

October 23, 2017 · 11 min · 2339 words · Etienne Stalmans

August  1

Phishing with OAuth and o365/Azure

August 2, 2017 · 7 min · 1294 words · Etienne Stalmans

April  1

NAT-to-NAT VPN with WireGuard

April 17, 2017 · 5 min · 988 words · Etienne Stalmans

2016  3

December  2

XXE FTP Server - A {web,ftp}-server for XXE

December 11, 2016 · 3 min · 567 words · Etienne Stalmans

tcpprox - An intercepting TCP proxy

December 11, 2016 · 7 min · 1329 words · Etienne Stalmans

October  1

Powershell Shells

October 3, 2016 · 2 min · 333 words · Etienne Stalmans

2015  5

September  1

Viewing, modifying and replaying websockets

September 10, 2015 · 2 min · 320 words · Etienne Stalmans

August  1

Abusing File Converters

August 22, 2015 · 3 min · 588 words · Etienne Stalmans

June  3

Huawei Quidway Password Extraction

June 17, 2015 · 2 min · 397 words · Etienne Stalmans

Mongo Shell escape

June 15, 2015 · 1 min · 168 words · Etienne Stalmans

Hipsters and data

June 14, 2015 · 2 min · 377 words · Etienne Stalmans