AnalysisResearchAnalysis of XXE 0days in PHPSpreadsheet < 3.4.0We deep-dive into how it has been possible to find two XXE 0day vulnerabilities in PHPSPreadsheet, bypassing the actual defences and subsequent fixes. 12/03/2025Read more
AnalysisAnalysis of CVE-2022-23093 (FreeBSD Ping Stack Overflow)We are analyzing CVE-2022-23093, step by step, to eventually answer the question: is it possible to get RCE, or not? 24/05/2023Read more
ProjectsSQLMap.sh – DNS Exfiltration made easySQLMap.sh is a wrapper for SQLMap that allows using Interact.sh as a DNS server to exfiltrate data without any configuration. 19/12/2022Read more