<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Topics · Patrik Grobshäuser</title>
    <link>https://patrik.re/topics/</link>
    <description>Browse Patrik Grobshäuser&#39;s research by subject, including articles published on Searchlight Cyber.</description>
    <language>en-GB</language>
    <atom:link href="https://patrik.re/topics/index.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Wed, 05 Aug 2026 00:30:00 &#43;0200</lastBuildDate>
    <item>
      <title>Where was Mythos when WordPress fell?</title>
      <link>https://patrik.re/where-was-mythos-when-wordpress-fell/</link>
      <guid isPermaLink="true">https://patrik.re/where-was-mythos-when-wordpress-fell/</guid>
      <pubDate>Wed, 05 Aug 2026 00:30:00 &#43;0200</pubDate>
      <description>On marketing claims nobody checks, the 1,000 projects Anthropic never listed, and why an industry full of experts followed along.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>CargoWise WebTracker — The Keys Were in the Cargo</title>
      <link>https://slcyber.io/research-center/cargowise-webtracker-the-keys-were-in-the-cargo/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/cargowise-webtracker-the-keys-were-in-the-cargo/</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 &#43;0000</pubDate>
      <description>Credentials recoverable from a logistics platform&#39;s own tracking interface.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Keys to the Kingdom: Anonymous SQL Injection in Drupal Core</title>
      <link>https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/keys-to-the-kingdom-anonymous-sql-injection-in-drupal-core-cve-2026-9082/</guid>
      <pubDate>Thu, 21 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Unauthenticated SQL injection reachable in Drupal core.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>To Kara, Alex, and Michiel — Your Researchers Are Leaving</title>
      <link>https://patrik.re/to-kara-alex-and-michiel-your-researchers-are-leaving/</link>
      <guid isPermaLink="true">https://patrik.re/to-kara-alex-and-michiel-your-researchers-are-leaving/</guid>
      <pubDate>Wed, 20 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Bug bounty platforms never humanized researchers or triage. Now they&#39;re drowning in AI slop and wondering why their best people are leaving.</description>
      <category>patrik.re</category><category>disclosure</category><category>ai-security</category>
    </item>
    <item>
      <title>New Age of Collisions: Pre-Auth Arbitrary File Read as root in cPanel</title>
      <link>https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/new-age-of-collisions-reading-arbitrary-files-pre-auth-as-root-in-cpanel-cve-2026-29205/</guid>
      <pubDate>Mon, 18 May 2026 00:00:00 &#43;0000</pubDate>
      <description>Reading arbitrary files pre-authentication, as root, on cPanel.</description>
      <category>Searchlight Cyber</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Hyoketsu — Solving the Vendor Dependency Problem in RE</title>
      <link>https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re/</link>
      <guid isPermaLink="true">https://slcyber.io/research-center/hyoketsu-solving-the-vendor-dependency-problem-in-re/</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>Tooling for reverse engineering without waiting on vendor firmware.</description>
      <category>Searchlight Cyber</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Running h1-brain Against a Real Target</title>
      <link>https://patrik.re/running-h1-brain-against-a-real-target/</link>
      <guid isPermaLink="true">https://patrik.re/running-h1-brain-against-a-real-target/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>A start-to-finish walkthrough of using h1-brain on an actual program. From hack() briefing to attack plan.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Teaching Claude Everything You&#39;ve Hacked</title>
      <link>https://patrik.re/teaching-claude-everything-youve-hacked/</link>
      <guid isPermaLink="true">https://patrik.re/teaching-claude-everything-youve-hacked/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>h1-brain is an MCP server that gives Claude your HackerOne bounty history and a database of public disclosures. Setup and first sync.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>What h1-brain Actually Does</title>
      <link>https://patrik.re/what-h1-brain-actually-does/</link>
      <guid isPermaLink="true">https://patrik.re/what-h1-brain-actually-does/</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>Every tool in h1-brain, explained. Your reports, public disclosures, and the hack() briefing that ties them together.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Replaced by a Goldfish</title>
      <link>https://patrik.re/replaced-by-a-goldfish/</link>
      <guid isPermaLink="true">https://patrik.re/replaced-by-a-goldfish/</guid>
      <pubDate>Fri, 06 Mar 2026 00:00:00 &#43;0000</pubDate>
      <description>Opus 4.6, the pentesting hype, and why most of the AI discourse around security is just noise.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Daily Workflows with the Email Agent</title>
      <link>https://patrik.re/daily-workflows-with-the-email-agent/</link>
      <guid isPermaLink="true">https://patrik.re/daily-workflows-with-the-email-agent/</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Real usage patterns for an AI email agent — morning triage, thread summaries, draft replies, and where the human stays in the loop.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Gmail API Credentials the Paranoid Way</title>
      <link>https://patrik.re/gmail-api-credentials-the-paranoid-way/</link>
      <guid isPermaLink="true">https://patrik.re/gmail-api-credentials-the-paranoid-way/</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Setting up Google Cloud OAuth credentials with minimal scopes for an AI email agent — because &#39;full access&#39; is never the right default.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Guardrails That Actually Work</title>
      <link>https://patrik.re/guardrails-that-actually-work/</link>
      <guid isPermaLink="true">https://patrik.re/guardrails-that-actually-work/</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>A four-layer defense model for AI email agents — because no single safety measure is enough when your inbox is on the line.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Wiring Gmail into OpenClaw</title>
      <link>https://patrik.re/wiring-gmail-into-openclaw/</link>
      <guid isPermaLink="true">https://patrik.re/wiring-gmail-into-openclaw/</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Installing the Gmail MCP server, configuring agent tools, and filtering down to only the operations you actually want.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Writing a SOUL.md for Email</title>
      <link>https://patrik.re/writing-a-soul-md-for-email/</link>
      <guid isPermaLink="true">https://patrik.re/writing-a-soul-md-for-email/</guid>
      <pubDate>Wed, 25 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Defining hard rules, tone guidelines, and PII handling for an AI email agent — because &#39;be helpful&#39; isn&#39;t a security policy.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Syncing Obsidian to a Headless Server</title>
      <link>https://patrik.re/syncing-obsidian-to-a-headless-server/</link>
      <guid isPermaLink="true">https://patrik.re/syncing-obsidian-to-a-headless-server/</guid>
      <pubDate>Fri, 20 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Running Obsidian in a headless Docker container with Obsidian Sync, giving AI agents direct access to your vault.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Connecting Claude Max and Telegram</title>
      <link>https://patrik.re/connecting-claude-max-and-telegram/</link>
      <guid isPermaLink="true">https://patrik.re/connecting-claude-max-and-telegram/</guid>
      <pubDate>Thu, 19 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Using OAuth credentials from a Claude Max subscription to power OpenClaw agents, and wiring up a Telegram bot for mobile access.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Securing the Dashboard with Nginx Proxy Manager</title>
      <link>https://patrik.re/securing-the-dashboard-with-nginx-proxy-manager/</link>
      <guid isPermaLink="true">https://patrik.re/securing-the-dashboard-with-nginx-proxy-manager/</guid>
      <pubDate>Wed, 18 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Putting the OpenClaw Control UI behind HTTPS with basic auth, WebSocket passthrough, and a proper Content Security Policy — all through Nginx Proxy Manager.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Setting Up OpenClaw on a Hetzner ARM64 Server</title>
      <link>https://patrik.re/setting-up-openclaw-on-hetzner-arm64/</link>
      <guid isPermaLink="true">https://patrik.re/setting-up-openclaw-on-hetzner-arm64/</guid>
      <pubDate>Tue, 17 Feb 2026 00:00:00 &#43;0000</pubDate>
      <description>Getting Node.js 22 and OpenClaw running on a fresh Hetzner CAX ARM64 Ubuntu Noble server — including the ARM64 gotchas nobody warns you about.</description>
      <category>patrik.re</category><category>ai-security</category>
    </item>
    <item>
      <title>Jolokia endpoints: JNDI RCE and heap dumps</title>
      <link>https://patrik.re/how-i-made-more-than-30k-with-jolokia-cves/</link>
      <guid isPermaLink="true">https://patrik.re/how-i-made-more-than-30k-with-jolokia-cves/</guid>
      <pubDate>Tue, 16 Jun 2020 00:00:00 &#43;0000</pubDate>
      <description>A full lab build and exploitation walkthrough for exposed Jolokia JMX endpoints: reflected XSS (CVE-2018-1000129), JNDI remote code execution via a rogue LDAP server (CVE-2018-1000130), and dumping the Java heap to recover credentials.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Visual recon with Aquatone and WebScreenshot</title>
      <link>https://patrik.re/visual-recon-a-beginners-guide/</link>
      <guid isPermaLink="true">https://patrik.re/visual-recon-a-beginners-guide/</guid>
      <pubDate>Sat, 05 May 2018 00:00:00 &#43;0000</pubDate>
      <description>A VPS-based workflow chaining Aquatone subdomain discovery, WebScreenshot capture and express-photo-gallery into a browsable wall of screenshots for triaging a large attack surface.</description>
      <category>patrik.re</category><category>reconnaissance</category>
    </item>
    <item>
      <title>Android certificate pinning bypass with Frida</title>
      <link>https://patrik.re/the-stony-path-of-android--f0-9f-a4-96-bug-bounty-bypassing-certificate-pinning/</link>
      <guid isPermaLink="true">https://patrik.re/the-stony-path-of-android--f0-9f-a4-96-bug-bounty-bypassing-certificate-pinning/</guid>
      <pubDate>Sat, 21 Oct 2017 00:00:00 &#43;0000</pubDate>
      <description>A walkthrough of installing the Burp CA on an Android device, running frida-server and using an SSL re-pinning Frida script to intercept traffic from apps that pin certificates.</description>
      <category>patrik.re</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>.htpasswd exposed, DES hash cracked</title>
      <link>https://patrik.re/bugbounty-decoding-a--f0-9f-98-b1-00000-htpasswd-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-decoding-a--f0-9f-98-b1-00000-htpasswd-bounty/</guid>
      <pubDate>Thu, 08 Sep 2016 00:00:00 &#43;0000</pubDate>
      <description>Directory brute-forcing a private bug bounty target turned up a world-readable .htpasswd whose descrypt hash, once cracked, opened four staging and development subdomains.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>Google Cloud Console: dormant stored XSS</title>
      <link>https://patrik.re/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/</guid>
      <pubDate>Tue, 17 May 2016 00:00:00 &#43;0000</pubDate>
      <description>An XSS payload stored as a Google Cloud project name executed months later in the unfiltered project-deletion error message, earning a $5,000 VRP reward, plus the impact argument that got it past a self-XSS classification.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Shopify POS firmware: extracting a root hash</title>
      <link>https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</link>
      <guid isPermaLink="true">https://patrik.re/digging-into-the-shopify-pos-firmware-part-1/</guid>
      <pubDate>Fri, 09 Oct 2015 00:00:00 &#43;0000</pubDate>
      <description>An in-scope Shopify POS endpoint exposed the card reader&#39;s firmware bundles, which unpack via binwalk, a dd carve at 0x202024 and jffs2dump into a JFFS2 root filesystem containing a salted MD5 root hash.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Stop OS X Spotlight Leaking Your Location</title>
      <link>https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</link>
      <guid isPermaLink="true">https://patrik.re/research-stop-osx-spotlight-from-sending-your-location/</guid>
      <pubDate>Mon, 15 Jun 2015 00:00:00 &#43;0000</pubDate>
      <description>Proxying OS X Spotlight through Burp showed it shipping the user&#39;s latitude and longitude to api.smoot.apple.com on every search, with two ways to block the request.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>XSS via XML File Upload on PayPal</title>
      <link>https://patrik.re/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-papyal-xml-upload-cross-site-scripting-vulnerability/</guid>
      <pubDate>Wed, 07 Jan 2015 00:00:00 &#43;0000</pubDate>
      <description>PayPal&#39;s invoicing feature accepted .xml attachments, and an XHTML-namespaced script element inside the XML executed when the file was served back. Includes the exploitability argument needed to qualify it for a bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>PayPal merchant directory reflected XSS</title>
      <link>https://patrik.re/bugbounty-reflected-cross-site-scripting-at-paypal-com/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-reflected-cross-site-scripting-at-paypal-com/</guid>
      <pubDate>Mon, 15 Dec 2014 00:00:00 &#43;0000</pubDate>
      <description>A duplicated q parameter in PayPal&#39;s merchant directory let an injected payload break out of script context, producing a reflected XSS that PayPal patched within days.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Hijacking a Prezi Subdomain Redirect ($500)</title>
      <link>https://patrik.re/bugbounty-malicious-redirect-on-mailroom-prezi-com/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-malicious-redirect-on-mailroom-prezi-com/</guid>
      <pubDate>Wed, 10 Dec 2014 00:00:00 &#43;0000</pubDate>
      <description>mailroom.prezi.com concatenated the request path onto its own hostname when redirecting, so a request to /.attacker-domain sent victims to a lookalike attacker-controlled host.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>BillMeLater: XSS Through a Style Attribute</title>
      <link>https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-reflected-cross-site-scripting-billmelater/</guid>
      <pubDate>Mon, 17 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A Firefox-only reflected XSS on wwwb.search.billmelater.com, achieved by closing out of a style attribute and injecting a fresh script element, which the vendor classified as out of scope.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Two Weeks of a Kippo SSH Honeypot</title>
      <link>https://patrik.re/research-ssh-honeypot-honey-wss-sh-com/</link>
      <guid isPermaLink="true">https://patrik.re/research-ssh-honeypot-honey-wss-sh-com/</guid>
      <pubDate>Mon, 17 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>Results from two weeks of a Kippo SSH honeypot in November 2014: roughly 4,000 brute-force attempts, 2,500 distinct credential pairs, and a source distribution dominated by hosts in China.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>PayPal Stored XSS via a Signup Flow Bypass</title>
      <link>https://patrik.re/bugbounty-paypal-stored-xss-security-bypass/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-paypal-stored-xss-security-bypass/</guid>
      <pubDate>Tue, 11 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A stored XSS in PayPal&#39;s account name field, delivered to arbitrary users through invoices after bypassing the signup flow&#39;s security check by truncating the workflow URL to /webapps/.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>DOM XSS on PayPal&#39;s Main Domain</title>
      <link>https://patrik.re/bugbounty-paypal-dom-xss-main-domain/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-paypal-dom-xss-main-domain/</guid>
      <pubDate>Wed, 05 Nov 2014 00:00:00 &#43;0000</pubDate>
      <description>A payload placed in the URL fragment reached a DOM sink on PayPal&#39;s main domain and executed; PayPal closed the report as a duplicate.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>XSS in Google Tag Manager via JSON Import</title>
      <link>https://patrik.re/bugbounty-the-5000-google-xss/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-the-5000-google-xss/</guid>
      <pubDate>Fri, 31 Oct 2014 00:00:00 &#43;0000</pubDate>
      <description>Google Tag Manager validated macro names in the web UI but not in the JSON container import path, so a payload smuggled through a file upload executed and earned a $5,000 bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>Stored XSS in Three WordPress Chat Plugins</title>
      <link>https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</link>
      <guid isPermaLink="true">https://patrik.re/wordpress-3x-vulnerable-chat-plugins-3/</guid>
      <pubDate>Thu, 02 Oct 2014 00:00:00 &#43;0000</pubDate>
      <description>WP Live Chat Support, MyLiveChat and Provide Support all accepted stored cross-site scripting during a 2014 customer install.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Chrome backslash URLs and XSS filter bypass</title>
      <link>https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</link>
      <guid isPermaLink="true">https://patrik.re/google-chrome-security-multiple-leading-slashes-in-urls-may-confuse-some-server-side-xss-filters/</guid>
      <pubDate>Tue, 17 Jun 2014 00:00:00 &#43;0000</pubDate>
      <description>Chrome resolves and executes a script URL written as http: followed by any number of backslashes. Firefox does not, and that difference can slip past pattern-matching XSS filters, closed by Chromium as wontfix.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Path Traversal on map.prezi.com ($1,000)</title>
      <link>https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</link>
      <guid isPermaLink="true">https://patrik.re/bug-bounty-prezi-map-prezi-com-path-traversal/</guid>
      <pubDate>Wed, 21 May 2014 00:00:00 &#43;0000</pubDate>
      <description>A path traversal issue on Prezi&#39;s map.prezi.com subdomain, fixed within two days of reporting and rewarded with a $1,000 bounty.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>Seven PayPal Bugs, Zero Bounties</title>
      <link>https://patrik.re/a-tale-of-7-vulnerabilities-paypal-bug-bounty/</link>
      <guid isPermaLink="true">https://patrik.re/a-tale-of-7-vulnerabilities-paypal-bug-bounty/</guid>
      <pubDate>Sun, 20 Apr 2014 00:00:00 &#43;0000</pubDate>
      <description>A 2014 run through PayPal&#39;s bug bounty scope: seven confirmed issues across paypal.com, financing.paypal.com, apps.paypal.com and the paypal-*.com family, all closed as duplicate or invalid.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>160 German tax office sites vulnerable to XSS</title>
      <link>https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</link>
      <guid isPermaLink="true">https://patrik.re/were-on-heise-german-found-160-sites-vulnerable-to-xss/</guid>
      <pubDate>Mon, 11 Nov 2013 00:00:00 &#43;0000</pubDate>
      <description>Reflected cross-site scripting across 160 German tax office websites, disclosed via heise.de and forwarded to CERT-Bund for coordinated remediation.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>disclosure</category>
    </item>
    <item>
      <title>PHP 5.3.3–5.3.6 socket_connect Bind Shell</title>
      <link>https://patrik.re/php-5-3-3-5-3-6-exploit-bind-shell/</link>
      <guid isPermaLink="true">https://patrik.re/php-5-3-3-5-3-6-exploit-bind-shell/</guid>
      <pubDate>Sat, 06 Jul 2013 00:00:00 &#43;0000</pubDate>
      <description>A public PHP 5.3.3-5.3.6 socket_connect exploit carrying a bind-TCP shell payload, dropped as an uploaded PHP file and located with an nmap sweep of ports 4000-4500.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
    <item>
      <title>SQL injection to root on a 2013 lab box</title>
      <link>https://patrik.re/from-nobody-to-root-advanced-sql-injection/</link>
      <guid isPermaLink="true">https://patrik.re/from-nobody-to-root-advanced-sql-injection/</guid>
      <pubDate>Tue, 07 May 2013 00:00:00 &#43;0000</pubDate>
      <description>Chaining a login-form SQL injection through sqlmap&#39;s --os-shell into a Linux 2.6.32 local root exploit to go from the &#39;nobody&#39; user to full control of the server.</description>
      <category>patrik.re</category><category>web-exploitation</category>
    </item>
    <item>
      <title>iTunes anti-debugging bypass with GDB and LLDB</title>
      <link>https://patrik.re/itunes-exploit-development/</link>
      <guid isPermaLink="true">https://patrik.re/itunes-exploit-development/</guid>
      <pubDate>Sun, 10 Mar 2013 00:00:00 &#43;0000</pubDate>
      <description>Defeating iTunes&#39; ptrace-based anti-debugging on OS X by breaking on ptrace and rewriting the rdi register, and porting the bypass from Apple&#39;s GDB to LLDB to get a Python-capable debugger.</description>
      <category>patrik.re</category><category>reverse-engineering</category>
    </item>
    <item>
      <title>Yahoo&#39;s /14 and an exposed phpinfo.php</title>
      <link>https://patrik.re/bugbounty-yahoo-phpinfo-php-disclosure/</link>
      <guid isPermaLink="true">https://patrik.re/bugbounty-yahoo-phpinfo-php-disclosure/</guid>
      <pubDate>Sun, 20 Jan 2013 00:00:00 &#43;0000</pubDate>
      <description>Pivoting from Yahoo&#39;s main A record to its ARIN netblock and sweeping all 260,000 addresses in the /14 for an exposed phpinfo.php.</description>
      <category>patrik.re</category><category>web-exploitation</category><category>reconnaissance</category>
    </item>
  </channel>
</rss>
