Ron Bowes · @iagox86
1057 followers · 265 posts · Server infosec.exchange

Posted a technical of CVE-2022-47986 (CVE_2022_47986 / ), a in IBM's Aspera software, which runs on a humorously old version of Ruby:

attackerkb.com/topics/jadqVo21

#cve202247986 #writeup #ruby #deserialization #vulnerability #attackerkb

Last updated 2 years ago

Christiaan Beek · @ChristiaanB
113 followers · 7 posts · Server infosec.exchange

Fantastic in-depth analytics of CVE-2022-47966: attackerkb.com/topics/gvs0Gv8B @catc0n @todb

#attackerkb

Last updated 2 years ago

Tod Beardsley · @todb
864 followers · 485 posts · Server infosec.exchange

I'm trying to get more serious about actually writing analyses of things that catch my interest. Here's my writeup of #pr_pack mule which is totally the name of this vuln, h/t to @dreadpir8robots .

#attackerkb #pr_pack

Last updated 2 years ago

Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

Wrote up a pair of entries for the two vulnerabilities in that we released today (largely the same as the blog, but more focus on technical and less on the story):

attackerkb.com/topics/i21EbdNx

attackerkb.com/topics/ZClTQn4a

#attackerkb #f5 #BIGIP

Last updated 2 years ago

Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

Since I'm pretty new here, and I got a whole pile of new followers last night, I figured I'd post my own ! Peer pressure etc. :)

In my non-professional life, I'm a living in (been in the US for ~9 years), I have a cool husband named Chris, and we have two pet - green cheek (GCCs) named Clang (like the C compiler) and Sharp (like C#).

Professionally, I've been interested in or working in kinda forever.. in highschool I used to write hacks and cheats for Starcraft / Diablo 2, some of which are on my GitHub profile. They don't work anymore, of course, but you can see what my old C++ code used to look like :)

Then I went to university at the University of , got a degree, and worked as a programmer before having a bunch of different infosec jobs - most recently, Google and Counter Hack.

These days, I'm a Lead Security Researcher at where I spend all day analyzing and finding new ones. I get to write them up on (attackerkb.com), the Rapid7 (blog.rapid7.com), give talks about vulns that I think are cool (I'll be speaking at in Seattle on the first week of December!) and contribute to when they're a good fit!

I also develop challenges, particularly for . We release everything open source afterwards, so you can run them yourself or see our solutions. I also write about them on my blog - although, since I write semi-professionally now, I don't write much other than CTF writeups there.

And finally, me and a bunch of friends founded a called in like 2012, which is 's best (also only) hackerspace. I haven't been there forevvver, but I'm still a card-carrying member and look forward to visiting again some day. :)

It's great to meet all y'all!

#introduction #canadian #seattle #parrots #conures #infosec #manitoba #compsci #rapid7 #vulnerabilities #attackerkb #blog #Hushcon #exploits #metasploit #ctf #bsidessf #hackerspace #skullspace #winnipeg

Last updated 2 years ago