Monday, November 29, 2021

Exploiting TotalMeltdown: the fine way

CVE-2018-1038 aka TotalMeltdown is quite an old bug (2018) but still an awesome bug so i decided to write a decent exploit for it.The vulnerability was discovered by @ulffrisk, The first functioning LPE...

Abusing libxml2 quirks to bypass SAML authentication on GitHub Enterprise (CVE-2025-23369)

Last year, GitHub had issued some CVEs for issues that affected their SAML authentication implementation, for example, you can read about CV...