RSSAmplifier

Blog

floyd's

IT Security

floyd.chRSS feed ↗10 posts

Latest posts

Citrix copy/paste circumvention on MacOS

As an security researcher it is not a big surprise that Citrix with disabled copy/paste can be circumvented and small texts easily copy and pasted in both directions. But while I think most IT security researchers know that, not many Continue reading

Certificate is not standards compliant on MacOS/iOS, error -9802, strict TLS Trust evaluation failed

This is a little rant about Apple and how they implemented their security checks around certificates. TL;DR: You can t have a certificate that is valid for more than 825 days. Like many others, I have a private trusted CA certificate Continue reading

MacOS built-in VPN IKEv2 force remove VPN DNS resolver

This is for once not a security related post, but as I couldn t find one important detail on the Internet, I thought I ll share my story. When connecting with the MacOS built-in VPN service to a server, MacOS (12, Monterey) Continue reading

Cross-origin resource sharing: unencrypted origin trusted PoC

I thought of a way to make this blog a little bit more active than one post every 4 years. And I thought I will stick to my old mantra of it doesn t always have to be ultra l33t hacks , Continue reading

New year, new host, same hacks

Wow, it s been a while, last post was 2018. I ve been very busy. Back in 2019 my co-founder Martin and me created Pentagrid. Many things also fell asleep during the pandemic, as social interaction got harder. I ve moved this blog Continue reading

Python Sender

Last week I played my first Capture The Flag (CTF) where I really tried solving the challenges for a couple of hours. It was a regular jeopardy style CTF with binaries, web applications and other server ports. I don t think Continue reading

Java Bugs with and without Fuzzing – AFL-based Java fuzzers and the Java Security Manager

In the last half a year I have been doing some fuzzing with AFL-based Java fuzzers, namely Kelinci and JQF. I didn t really work with java-afl. The contents of this post are: Various AFL-based Java fuzzers are available that can Continue reading

Activity wrap-up including polyglots, RIPS, UploadScanner and Java fuzzing

A tweet of takesako including a C/C++/Perl/Ruby/Python polyglot got me interested, so I created two follow-up polyglots based on his work and put them on github. Recently I also evaluated the RIPS PHP scanner and I did that with some Continue reading

Schubser and his cookie dealing friend

I actually forgot to post this in February, so I m a little late but the topic is as current as it was back then. One week in February my colleague, Jan Girlich and me took some time to review our Continue reading

BSides Zurich – Nail in the JKS coffin

On Saturday I was happy to speak at the fabulous BSides Zurich about the Java Key Store topic. You can find my slides Nail in the JKS coffin as a PDF here. It was my second time at a BSides Continue reading