/dev/posts/

Entering in Podman containers

Published:

Some commands for interacting with the namespaces of Podman containers.

Read more…

Switching from Docker to Podman

Published:

Some notes about using Podman instead of Docker, on Linux. This has been tested on Podman v3.4.7.

Read more…

Stable Diffusion on an AMD Ryzen 5 5600G

Published:

Executing the Stable Diffusion text-to-image model on an AMD Ryzen 5 5600G integrated GPU (iGPU).

Read more…

Extract the schema from a remote LDAP server

Published:

How to extract the schema from a remote LDAP server and use it on a OpenLDAP instance.

Read more…

Impact of the different Wifi security modes

Published:

Comparing the different Wifi/WPA authentication and key distribution methods (PSK, EAP, SEA).

Read more…

Browser-based attacks on WebDriver implementations

Published:

Some context and analysis about attacks on in WebDriver implementations.

Read more…

Lack of X.509 TLS certificate validation in OWASP ZAP

Published:

Lack of X.509 TLS certificate validation in OWASP ZAP (Zed Attack Proxy) could be used for man-in-the-middle attacks.

Read more…

DNS rebinding on ReadyMedia/minidlna v1.3.0 and below

Published:

A DNS rebinding vulnerability I found in ReadyMedia (formerly MiniDLNA) v1.3.0 and below. This is CVE-2022-26505.

Read more…

Introduction to TLS v1.3

Published:

Some notes about how TLS v1.3 works. This is a follow-up of the previous episode about TLS v1.2. As before, the goal is to have a high-level overview about how the protocol works, what is the role of the different messages and be able to understand (and debug) a network traffic dump.

Read more…

CSRF and DNS-rebinding to RCE in Selenium Server (Grid)

Published:

Vulnerabilities in found on the WebDriver endpoints of Selenium Server (Grid).

Read more…

Page 1 of 2 | | | JSON Feed | Atom Feed