infosec_au Profile Banner
shubs Profile
shubs

@infosec_au

Followers
55K
Following
10K
Media
249
Statuses
5K

Co-founder, security researcher. Building an attack surface management platform, @assetnote

halcyon
Joined August 2013
Don't wanna be here? Send us removal request.
@infosec_au
shubs
3 days
RT @n1nj4sec: I recently found a blind FreeMarker SSTI on a bbp. It was not possible to RCE but I found some nice gadgets to enumerate acce….
0
46
0
@infosec_au
shubs
5 days
RT @nullpt_rs: Reverse Engineering Vercel's BotID by @blastbots .
Tweet media one
0
19
0
@infosec_au
shubs
5 days
To kick off our Christmas and July research posts, we explain how we achieved persistent XSS on every Adobe Experience Manager Cloud instance, not twice, but thrice! This is now patched across all of AEM cloud, but what an interesting attack surface!
Tweet media one
2
38
198
@infosec_au
shubs
6 days
We’re celebrating Christmas in July this year, starting July 1st. We’ll release a security research post on Searchlight Cyber’s blog each week over the month. To be the first to know, subscribe to our RSS feed here:
Tweet media one
4
15
95
@infosec_au
shubs
10 days
RT @spaceraccoonsec: When I asked @infosec_au to write a foreword for "From Day Zero to Zero Day," I didn't anticipate how perfectly he wou….
0
13
0
@infosec_au
shubs
11 days
RT @ITSecurityguard: Honestly a bit surreal, but I’ll be joining @assetnote as a Security Researcher soon🦆. Excited to be part of such a br….
0
4
0
@infosec_au
shubs
13 days
How do we turn bad SSRF (blind) into good SSRF (full response)? The @assetnote Security Research team at @SLCyberSec used a novel technique involving HTTP redirect loops and incremental status codes that leaked the full HTTP resp. It may work elsewhere!
Tweet media one
6
179
605
@infosec_au
shubs
17 days
RT @TantoSecurity: The post is at and we hope you enjoy reading it as much as we enjoyed putting it together! ❤️.
0
11
0
@infosec_au
shubs
24 days
RT @spaceraccoonsec: Sadly, other than the security team, nobody cares about the security tools you build. Here’s how to avoid getting suck….
0
10
0
@infosec_au
shubs
25 days
RT @0xLupin: 2 AM in a Tokyo hotel room: @assetnote x Depi find a Dependency Confusion vuln that lands RCE on Netflix !. 🚀 Shout-out to @i….
0
48
0
@infosec_au
shubs
29 days
@ryotkak @Geluchat @kevin_mizu I forgot to mention. @ajxchapman made an impossible RCE chain possible. His work was inspiring.
1
0
67
@infosec_au
shubs
30 days
I won the Most Valuable Hacker award for the Salesforce H1-6102 live hacking event in Sydney (my hometown)! I enjoyed working with some very talented hackers, including @ryotkak, @Geluchat, and @kevin_mizu. This is my third MVH award, and I'm grateful to be able to compete.
89
36
766
@infosec_au
shubs
1 month
This issue isn't just limited to ingress, but also egress traffic out. So next time you have an SSRF or out of bands based attack, give this technique a go! We plan to present this in more detail in the future. (end thread).
1
1
13
@infosec_au
shubs
1 month
One reason this issue is widespread is that vendors and SaaS platforms ask you to broadly whitelist ranges. For example, Gitlab's official advice is to whitelist the entire GCP region that their shared runners are in, and doing so leaves you exposed.
1
2
12
@infosec_au
shubs
1 month
From a single scan, we found around 7000 instances where traffic was different when coming from us-east-1, as compared to outside of us-east-1/AWS. Some of the largest companies in the world have borked their IP whitelisting rules.
1
2
12
@infosec_au
shubs
1 month
We scanned 18,206,880 (us-east-1 AWS) hosts from outside of us-east-1 AWS on port 443, using masscan. This returned 2,574,114 hosts with port 443 open. We used zgrab2 to issue HTTP requests to all assets on port 443 (TLS) from outside AWS and inside AWS (us-east-1).
2
4
28
@infosec_au
shubs
1 month
404 not found? Not when you’re coming from AWS
Tweet media one
Tweet media two
1
1
11
@infosec_au
shubs
1 month
Mutual TLS? Not when you’re coming from AWS
Tweet media one
Tweet media two
2
2
21
@infosec_au
shubs
1 month
Newtowner allows you to quickly spin up a GitHub action, Gitlab CI pipeline, Bitbucket pipeline, AWS API Gateway, or AWS EC2 instance to check a diff between your home connection and the remote connection for one or more URLs.
Tweet media one
1
2
14
@infosec_au
shubs
1 month
IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue:
14
235
865