Exploiting vulnerabilities in Johnson & Johnson web apps
https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
Recent content in Home on Dan [the] Salmon
https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
https://www.youtube.com/watch?v=FTFn4UZsA5U
https://www.youtube.com/watch?v=YVoF_mI8MIw
2026 # From User to Operator: How to Run a Tor Relay and Defend Online Freedom SecretCon. June 5 Slides 2025 # Prioritizing Internal Pentests: so much to hack, so little time SecretCon. June 19 Video 2019 # miniprint - A Medium Interaction Research Honeypot Colloquium on Information Assurance, Cybersecurity, and Management. May 24 Slides
I spoke a few weeks ago at SecretCon! I meant to put up a post about it ahead of time, but I had a lot of work to do getting the slides in order that it didn’t happen. This is the second year in a row I have given a talk there - you can read about last year’s talk here . This year’s talk was about running Tor relays, something I’ve done for a few years but haven’t…
This week, my team was cooperatively working on hacking an Ubuntu machine on HackTheBox and got to the point of exploiting a Command Injection vulnerability. Naturally, my first suggestion was to pop over to revshells to quickly get a reverse shell payload we could copy/paste. After starting a listener on the attacker machine, we grabbed the first Bash reverse shell entry labelled Bash -i : sh -i…
https://media.ccc.de/v/39c3-a-tale-of-two-leaks-how-hackers-breached-the-great
https://www.youtube.com/watch?v=wVY47hNzgJk
https://www.youtube.com/watch?v=raHBq0rUdJQ
https://www.youtube.com/watch?v=NF11JolTMwo
https://www.youtube.com/watch?v=FYHvL8V_m-Q
https://www.youtube.com/watch?v=f-LTMUFQzjQ Really great talk about a very interesting problem: creating VMs that can run unmodified device firmware to emulate complicated devices like routers.
https://www.youtube.com/watch?v=RpkYQDaEKMo
https://www.youtube.com/watch?v=aBsf75c1zqw
https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable
https://www.youtube.com/watch?v=zr5y6Bapbnw
https://www.youtube.com/watch?v=N1FAOb1krBk
https://www.youtube.com/watch?v=1bj7hg3FlQo
https://www.youtube.com/watch?v=cYZmRp90hss Also explored in this episode of Darknet Diaries
https://www.youtube.com/watch?v=2zrcemxCg4Y
https://www.youtube.com/watch?v=VlOUGECw6kc
https://www.youtube.com/watch?v=WCnojaEpF2I
https://www.youtube.com/watch?v=v76lYD5odfA
https://allistair.sh/blog/breaking-heroku-postgres/
https://www.youtube.com/watch?v=KwI2daso3ug
https://www.youtube.com/watch?v=yFeYiWqQ6RE
https://app.media.ccc.de/v/39c3-don-t-look-up-there-are-sensitive-internal-links-in-the-clear-on-geo-satellites
https://www.youtube.com/watch?v=wpA8NBzzy00
https://media.ccc.de/v/39c3-from-silicon-to-darude-sand-storm-breaking-famous-synthesizer-dsps
https://www.youtube.com/watch?v=Q1S-PVo3GlA
https://www.youtube.com/watch?v=_39UbCePFfw
https://www.youtube.com/watch?v=SQz4nySj4hg
https://www.youtube.com/watch?v=6Kw901oqxI8
https://h4x0r.org/funreliable/
While discussing some benchmarks I ran on the zpool in my Proxmox server, it was suggested that the SSDs backing the pool were severely bottlenecking performance. The pool consisted of 4x WD Blue 1TB SATA SSDs which I chose years ago for budget reasons. After doing some research on the benefits of upgrading from consumer to enterprise SSDs - lower latency and higher endurance to name two - I…
https://www.youtube.com/watch?v=pH_4pgoCHDQ
https://www.youtube.com/watch?v=o-rsKWodGvA
https://satcom.sysnet.ucsd.edu/
https://arstechnica.com/security/2025/11/fbi-arrests-ransomware-clean-up-experts-for-planting-ransomware/
https://www.youtube.com/watch?v=djM70O0SnsY
https://kennedn.com/blog/posts/tapo/
https://youtu.be/tHj0-Gzvbeo
https://www.youtube.com/watch?v=gm1ZAjmdHzA
https://embracethered.com/blog/posts/2025/wrapping-up-month-of-ai-bugs/ This a fantastic collection of vulnerabilities found in AI tools. I will definitely be referring to these write-ups the next time I have an LLM app to pentest.
https://www.securityalliance.org/news/2025-09-npm-supply-chain
https://www.youtube.com/watch?v=AybRhz56NCk by Pedro Umbelino at hack.lu
https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/
https://research.kudelskisecurity.com/2025/08/19/how-we-exploited-coderabbit-from-a-simple-pr-to-rce-and-write-access-on-1m-repositories/
https://techno-fandom.org/~hobbit/cars/ev/offnet.html
https://eaton-works.com/2025/08/18/intel-outside-hack/