@Paupu_95 Profile picture

Paolo Cavaglià

@Paupu_95

Penetration Tester @ShielderSec | Bachelor's Degree in Computer Engineering | IT and Cyber Security lover!

Similar User
BrunoZero photo

@BrunoModificato

smaury photo

@smaury92

Shielder photo

@ShielderSec

zi0Black photo

@zi0Black

maitai photo

@MaitaiThe

Goten photo

@ila_marco_

Raffaele Sabato photo

@syrion89

Severus photo

@Sev1rus

Francesco Giordano photo

@0xakuma

Mindless photo

@Mindlaess_

Urb4nz photo

@Urb4nz

Her0 photo

@Her0_IT

Carlo Pelliccioni photo

@cpelliccioni

Gerardo Di Giacomo photo

@gedigi

phosphore photo

@lorenzostella

Paolo Cavaglià Reposted

Cheers -- here in beautiful Bali 🏖️ for #theSAS2024 conference! If you happen to be here, please reach out and let's have a chat 🍻

Tweet Image 1
Tweet Image 2
Tweet Image 3

Paolo Cavaglià Reposted

Attending @TheSAScon in the beautiful Bali🏝️? Make sure not to miss @suidpit's talk about his novel research on the macOS 🍎 sandbox and how to bypass it. 🗓️ Wednesday, October 23 - 15:10

Tweet Image 1
Tweet Image 2

Paolo Cavaglià Reposted

It's always cool to contribute to free and open-source projects 🎉 ★★★★★ - Would recommend!

We wanted to give a shout out to @smaury92, who found a ReDoS security issue with Thunderbird Appointment. This resulted in us fixing the issue and removing deprecated urls! It's fantastic community contributions like this that makes Thunderbird so much more than the sum of its…



Paolo Cavaglià Reposted

🧵 1. @IrpiMedia Un filo manco troppo sottile collega l'hacker che ha messo la tenda dentro il ministero della Giustizia ai mercati neri dove si comprano armi e droga sul web. Con @SimoneOlivelli risaliamo il corso del fiume fino a una vecchia conoscenza irpimedia.irpi.eu/carmelo-miano-…


Paolo Cavaglià Reposted

New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate. Full disclosure: samcurry.net/hacking-kia


Paolo Cavaglià Reposted

For the weekend, we gift you with not one, but TWO ways to escalate `sudo iptables` (+ a couple other boring preconditions) into a r00t shell - read how @smaury92 and @suidpit managed to climb your friendly neighborhood 🔥wall! shielder.com/blog/2024/09/a…


Paolo Cavaglià Reposted

It's a pleasure to sponsor once again @cybersaiyanIT for #RomHack2024! We are looking forward to meet y'all in Rome next week. ICYMI we're #hiring, you can find the job post here: romhack.io/job-opportunit…

#RomHack2024 is 9 days away and today we want to thank our #sponsors! This edition was sponsored by 20 companies and you can have a look to the full list here romhack.io/#sponsor Take your time to visit their website, without their support RomHack could not be organized ⬇️

Tweet Image 1


Paolo Cavaglià Reposted

lua interpreters something something fakeobj addrof something something wasm something deda.lol/posts/2024-09-…

Tweet Image 1

Paolo Cavaglià Reposted

We're excited to announce one of our giveaways thanks to "@CaidoIO" 🎉 We will pick 5 winners to win a 1-year Caido Pro license! To enter: 1️⃣ Follow us @BugBountyDefcon and @CaidoIO 2️⃣ Like this post ❤️ 3️⃣ Retweet this post 🔁 You have time to participate until Friday (9/13)!


Paolo Cavaglià Reposted

🍎 With many #macOS security mechanisms at work, one might wonder how malware manages to bypass them. Get ready for a deep dive into macOS security architecture and novel evasion techniques during Pietro Tirenna's (@suidpit) talk at #TheSAS2024. 🚀 Secure your seat:…

Tweet Image 1

Paolo Cavaglià Reposted

During a recent engagement @Mindlaess_ hacked his way through @vtigercrm which led to discover a privilege escalation and a SQL injection. Learn more in the dedicated advisories: - CVE-2024-42994 #sqli shielder.com/advisories/vti… - CVE-2024-42995 #privesc shielder.com/advisories/vti…

Tweet Image 1

Paolo Cavaglià Reposted

Back in December 2023 our researchers @Th3Zer0 @suidpit and @Mindlaess_ performed an audit sponsored by @awscloud and facilitated by @OSTIFofficial on boost. It resulted in 7 findings and 15 new fuzzers. The report is now public, check the details here: shielder.com/blog/2024/05/b…


Paolo Cavaglià Reposted

In early 2023 we (@Th3Zer0 & @smaury92) collaborated with @SecureDrop to start designing and prototyping the #E2EE messaging protocol for a future version of SecureDrop. 📄 blog post: securedrop.org/news/introduci… 💻 poc code: github.com/freedomofpress…

Today, we’re publishing a proposed end-to-end encrypted messaging protocol for a future version of SecureDrop. Seeking feedback from cryptographers and protocol designers! securedrop.org/news/introduci…



Paolo Cavaglià Reposted

Exciting news! We've just released a new blog post on mobile app security, where @suidpit and @Th3Zer0 used their intent-fu to discover vulnerabilities (CVE-2024-26131, CVE-2024-26132) in @element_hq, a @matrixdotorg client for Android. #writeup #CVE shielder.com/blog/2024/04/e…


Paolo Cavaglià Reposted

Our audit with @ShielderSec, @brefphp, was published today! Thanks to @awscloud for their sponsorship of this work, and @matthieunapoli for his contributions to bref and this audit. Read more at ostif.org/bref-audit-com…

Tweet Image 1

Paolo Cavaglià Reposted

We recently partnered with @OSTIFofficial to perform a security audit sponsored by @awscloud on @brefphp The audit resulted in 5 findings promptly addresses by @matthieunapoli The report is now public, check the details here: shielder.com/blog/2024/03/b…


Paolo Cavaglià Reposted

This year @nullcon was a blast full of great talks! Our team had much fun and even managed to score the 🥇 (@smaury92) and 🥈 (@suidpit) place in the @intigriti Live Hacking Event. Thanks @antriksh_s, @intidc, @RoadRunnerHacks, et al!

Tweet Image 1

Paolo Cavaglià Reposted

During a recent Red Team Assessment @Th3Zer0 and @smaury92 discovered a vulnerability in @PostgreSQL's #PgAdmin which in the worst case allows unauthenticated attackers to run arbitrary server-side code. Check out the #RCE advisory and patch now! shielder.com/advisories/pga…


Paolo Cavaglià Reposted

🎁 Source Code Disclosure in IIS 10.0! Almost. There is a method to reveal the source code of some .NET apps. Here's how it works. 👉 swarm.ptsecurity.com/source-code-di…

Tweet Image 1

Paolo Cavaglià Reposted

TL;DR Product security folks: do not blindly trust the attack requirements shared by the researchers. Security researchers: when testing embedded devices make sure to mimic correctly all their configurations (i.e. the NVRAM content). 7/7


Loading...

Something went wrong.


Something went wrong.