Nicky Bloor
@nickstadb
Followers
2K
Following
3K
Media
556
Statuses
5K
Coder, hacker, infosec researcher, adrenaline junkie. Once hiked Ben Nevis, Scafell Pike, and Snowdon in 22h 48m. Not a snake oil peddler.
Manchester, UK
Joined September 2009
Deserialization, reflection, and memory-resident shellcode execution come to mind with PrecodeFixupThunk being the first step of the JIT mechanism (hat-tip to @_xpn_ for weird ways to run unmanaged code in .NET!). Anyone observed this, or have any more specific suggestions?
1
0
0
Are there any funky .NET exploitation techniques that might lead to a crash in clr!PrecodeFixupThunk?
1
0
0
In other news - my @Steel_Con talk has been accepted! Looking forward to it. Catch you there if you're going!
2
3
13
That's another one ticked! Did not go as well as I'd have liked but it was a brutal one today. The heat took a lot of people out. Hope everyone's ok and congrats to the 92k or so marathoners today whether at London or Manchester! #ManchesterMarathon
1
0
5
Apache security team have reviewed and revised this one! CVE-2025-24859 in Apache Roller has been downgraded to CVSS 2.1, panic over ;)
CVE database is becoming a joke TBH, when things like CVE-2025-24859 are published with a CVSS score of 10.0 - To exploit this vulnerability you first need to obtain a valid session token, then you only maintain access to the corresponding user account...
1
0
4
Intercepting HTTPS Communication in Flutter : Going Full Hardcore Mode with Frida : https://t.co/S4j441guU3
0
51
204
CVE database is becoming a joke TBH, when things like CVE-2025-24859 are published with a CVSS score of 10.0 - To exploit this vulnerability you first need to obtain a valid session token, then you only maintain access to the corresponding user account...
2
1
9
It's time! Picked this one up about 9 years ago, not long after I had my first Smog Rocket @BeavertownBeer !
0
1
0
A colleague pointed me today to an insane exploit primitive if you control a PHP include() with a fixed .php extension and no upload: https://t.co/sy9s72KMKT
4
89
347
#lazyweb Anyone know how I can run Android Auto in a VM, with a view to later running it on a Raspberry Pi or similar? Also looking to modify it so open source preferably. Currently building a VM to look at OpenAuto but any pointers would be brill!
2
1
1
Epic clear run down Snake Pass this morning so I'm in Sheffield early.
0
0
2
@TenableSecurity Tempted to have a pop at some of the competition 🤣 Although I only scratched the surface of the HP Device Manager RMI service, I'd bet there's more to find there.
0
0
2
@TenableSecurity Nessus still says no known exploit for these vulns despite me publishing it and notifying them three years ago 🤣 Wonder how many times this has been reported and wontfixed because "no exploit"! Stable, unauthenticated, no interaction RCE in default config.
1
0
5
Man this was a banging hack. Miss getting properly stuck into stuff for mad r00t like that!
Unauthenticated Java RMI service -> SQLi smuggled via HQL injection -> Use SYSTEM privs to overwrite Postgres config -> Reload Postgres config to enable remote connections -> Connect to Postgres with the backdoor account -> Execute SQL -> RCE as SYSTEM. Fuck yeah and g'night! 🤘
1
0
4
Too hot for this. Why no sprinklers or jelly babies this year @Great_Run ?! I reckon I would have run at least 2 minutes faster with those 🤣
1
0
6