I’m Abdel Adim Oisfi aka smaury.Job: CEO, Security Researcher, Penetration Tester at Shielder.Passions: Hacking, hitchhiking, cliff jumping and skinned knees.
1-click RCE on Keybase
Keybase client allowed inject arbitrary links with arbitrary protocols. This caused a Remote Command Execution on Windows and MacOS.
Exploiting Apache Solr through OpenCMS
Exploiting a known XXE in Apache Solr through OpenCMS handleSolrSelect, to read arbitrary files from the OpenCMS' server.