We implemented an exploit for RediShell (CVE-2025-49844). While doing so, we discovered that the publicly available PoC incorrectly uses loadstring to trigger the Redis UAF.
Kudos to @wiz_io for the interesting findings!
No longer hiring junior or even mid-level software engineers.
Our tokens per codebase:
Gumroad: 2M
Flexile: 800K
Helper: 500K
Iffy: 200K
Shortest: 100K
Both Claude 3.5 Sonnet and o3-mini have context windows of 200K tokens, meaning they can now write 100% of our Iffy and
🧵[1/9] Time to publish the solution to this challenge! The goal of this challenge was to find an XSS while avoiding it being blocked by the CSP sent by the PHP header() function. Let's dive into it!
This Friday, I'm presenting a novel technique as part of my talk "Secret web hacking knowledge - CTF authors hate these simple tricks".
I've made a challenge about it, will you be able to pop an alert on pilv.ar ? The whole source code is in the screens below :)
Here is a 72-byte alphanum MD5 collision with 1-byte difference for fun:
md5("TEXTCOLLBYfGiJUETHQ4hAcKSMd5zYpgqf1YRDhkmxHkhPWptrkoyz28wnI9V0aHeAuaKnak")
=
md5("TEXTCOLLBYfGiJUETHQ4hEcKSMd5zYpgqf1YRDhkmxHkhPWptrkoyz28wnI9V0aHeAuaKnak")
2K Followers 722 Following@CloudNativeFdn Ambassador, @Microsoft MVP, PyCon China & KCD Beijing organizer.🥑Open Source + Cloud Native + AI Infra. Working at @Kong . Opinions are my own
20K Followers 2K FollowingSystem in Rust, Application in AI.
Slow down. Have fun. Live well.
INTJ-A. No ism.
Lifelong Programmer and Writer.
Study in Public, Building in Public.
🦀 保命
1K Followers 2 FollowingJazz is an open-source DB that runs right in your frontend, containers and workers — with auth, permissions, files, multiplayer, E2EE & more.
19K Followers 276 FollowingChip Architect (2013-Present) | Bitcoin Enthusiast since 2011. Open source developer: https://t.co/fHv2ksd3xJ Views are my own.
20K Followers 687 FollowingBuilding OpenCLI & https://t.co/1aJnnxFTbI & Maka Agent
AI enthusiast ! Love open source! ExDatabaseer.
Apache Arrow/Datafusion/Doris PMC member & Committer
10K Followers 660 Followingfounder of https://t.co/D80NEueS92 @raft_hq | former author of Kimi CLI @Kimi_Moonshot | ex-database kernel engineer @RisingWaveLabs
249K Followers 30 FollowingManus from @Meta is the general AI agent that bridges minds and actions: it doesn't just think, it delivers results.
Telegram: https://t.co/kdHdNxZ6xF
120K Followers 261 FollowingThe AI Lab behind GLM models, dedicated to inspiring the development of AGI to benefit humanity.
https://t.co/7a5aSCUNcZ
https://t.co/x14hb3klXm
3K Followers 932 FollowingOperating systems, build systems, and programming languages. Mostly Unix, Bazel, and Rust. Author of Blog System/5. Creator of EndBASIC, and more.
3K Followers 109 FollowingBuilding @AmpCode
Ghostty Terminal subsystem maintainer
Author of TUI libraries in zig and go
Don’t tell me something can’t be done