RSSAmplifier

Blog

2763

Security researcher and bug bounty hunter

0xacb.comRSS feed ↗10 posts

Latest posts

KindaRails2Shell - Rails RCE

Please check the blog post here: https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066

OpenClaw One-Click ATO to RCE

Please check the blog post here: https://ethiack.com/news/blog/one-click-rce-moltbot

AI for Ethical Hacking

Please check the blog post here: https://ethiack.com/news/blog/dont-fear-the-ai-reaper-using-llms-to-hack-better-and-faster

Git Arbitrary Configuration Injection

Please check the blog post here: https://ethiack.com/news/blog/git-arbitrary-configuration-injection-cve-2023-29007

Till REcollapse

Welcome back to my blog. In this post, I’ll explain the REcollapse technique. I’ve been researching it for the last couple of years to discover weirdly simple but impactful vulnerabilities in hardened targets while doing bug bounties and participating in HackerOne LHEs. This technique can be used to perform zero-interaction account takeovers, uncover new bypasses for web application firewalls, and…

RCE on Steam Client via buffer overflow in Server Info

This report has been disclosed on HackerOne: https://hackerone.com/reports/470520

GitHub Desktop RCE (OSX)

I was invited to H1-702 2018, a HackerOne live-hacking event in Las Vegas that paid over $500k dollars in bounties. One of the targets of this event was GitHub. I like to hack software I use everyday, because I already know lots of features in advance, so I felt GitHub would be a good target. I started playing with GitHub Desktop and found a way to achieve RCE in OSX. But, guess what? It was out…

SSRF in Shopify Exchange to RCE

This report has been disclosed on HackerOne: https://hackerone.com/reports/341876

H1-202 CTF - Writeup

I want to dedicate this writeup to my grandma, who passed away while I was finishing it. Descansa em Paz, Avó.

H1-212 CTF - Writeup

Intro Hackerone launched the H1212 CTF challenge on November 13. I’m going to show how I solved it in this post. Thanks @jobertabma and @NahamSec for this awesome challenge! It was fun!