1. X
  2. Krypton
Log inSign up
Krypton
56 posts
Image
user avatar
Krypton
@kkrypt0nn
Cloud Engineer | Security enthusiast & researcher | Developer
$rax
krypton.ninja
Joined September 2018
47
Following
77
Followers
RepliesRepliesMediaMedia
  • user avatar
    Krypton
    @kkrypt0nn
    May 23
    Even sloppier.
    This post is from an account you blocked.
  • user avatar
    Krypton
    @kkrypt0nn
    May 19
    Tomorrow: ASLR for CVE-2026-42945 can be bypassed by having a host access primitive.. Jokes aside, still an interesting PoC
    user avatar
    Hamid Kashfi
    @hkashfi
    May 18
    Here's the PoC for Nginx CVE-2026-42945 which works against vanilla Ubuntu (and any other distro?) + Nginx with ASLR enabled. I have included all iterations of the PoC the LLM was kicked to improve. TL;DR: We can use an LFI/file-read primitive to leak enough details from
  • user avatar
    Krypton
    @kkrypt0nn
    May 13
    Don't disable ASLR
    user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    May 13
    NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at
    Image
    00:00
  • user avatar
    Krypton
    @kkrypt0nn
    May 8
    It's the Friday deployment time over at Discord
  • user avatar
    Krypton
    @kkrypt0nn
    Apr 30
    Hard to patch if there's no patch. It's a 0day, and thank you for that. Blocking the module has some more side-effects than the ones described, see openwall.com/lists/oss-secu… I call that irresponsible disclosure, change my mind.
    user avatar
    Xint
    @xint_official
    Apr 29
    Patch your Linux boxes! Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. Found by the teams at @theori_io and @xint_official More

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement