KindaRails2Shell - Rails RCE
Please check the blog post here: https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
Security researcher and bug bounty hunter
Please check the blog post here: https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
Please check the blog post here: https://ethiack.com/news/blog/one-click-rce-moltbot
Please check the blog post here: https://ethiack.com/news/blog/dont-fear-the-ai-reaper-using-llms-to-hack-better-and-faster
Please check the blog post here: https://ethiack.com/news/blog/git-arbitrary-configuration-injection-cve-2023-29007
Welcome back to my blog. In this post, I’ll explain the REcollapse technique. I’ve been researching it for the last couple of years to discover weirdly simple but impactful vulnerabilities in hardened targets while doing bug bounties and participating in HackerOne LHEs. This technique can be used to perform zero-interaction account takeovers, uncover new bypasses for web application firewalls, and…
This report has been disclosed on HackerOne: https://hackerone.com/reports/470520
I was invited to H1-702 2018, a HackerOne live-hacking event in Las Vegas that paid over $500k dollars in bounties. One of the targets of this event was GitHub. I like to hack software I use everyday, because I already know lots of features in advance, so I felt GitHub would be a good target. I started playing with GitHub Desktop and found a way to achieve RCE in OSX. But, guess what? It was out…
This report has been disclosed on HackerOne: https://hackerone.com/reports/341876
I want to dedicate this writeup to my grandma, who passed away while I was finishing it. Descansa em Paz, Avó.
Intro Hackerone launched the H1212 CTF challenge on November 13. I’m going to show how I solved it in this post. Thanks @jobertabma and @NahamSec for this awesome challenge! It was fun!