Quantcast
Channel: /dev/posts/
Browsing index pages (123 articles)

You won't believe you don't need to see those horrible ads on the web

This #1 trick ad companies don't want you to know!

View Article


Tool call execution through user prompt injection (CSRF) of the llama-server...

A user prompt injection vulnerability (CSRF) in the llama-server (llama.cpp) Web UI (Reprompt-like) allows attackers to inject arbitrary user prompt with query parameter (?q=...), potentially leading...

View Article


User prompt injection (CSRF) on Le Chat and Grok

An user prompt injection vulnerability (CSRF) both in in the e Chat (Mistral) and Grok (Reprompt-style) allows attackers to inject user prompt with query parameter (?q=...) potentially leading data...

View Article

llama.cpp quickstart (part 2)

How to quickly use llama.cpp for LLM inference (part 2). This is a follow-up of a previous post on the same topic.

View Article

Malleability of ECDSA (and DSA) signatures, JWTs, etc.

This blog posts explains that ECDSA and DSA signatures are malleable, that JWTs can be malleable as well and how this can be used to bypass some broken implementations of JWT deny lists (for revocation...

View Article


Risk of reflected cross site scripting and Content-Security-Policy bypass in...

I was reading the WebSub specification (formerly PubSubHubbub) when I found that there was a risk of reflected browser-side code injection (reflected cross site scripting, reflected XSS) in the WebSub...

View Article

Computer security guidelines and references

A list of computer security guidelines and references.

View Article

Authority Ambiguity Vulnerabilities in NGINX and Debian’s proxy_params

Two related authority-ambiguity vulnerabilities in NGINX and Debian's proxy_params configuration snippet.

View Article


Cryptography formats

If you are trying to understand the difference between the different cryptography-related formats (PKS#12, PKCS#8, PEM, X.509 certificate, DER, JWK, BEGIN ENCRYPTED PRIVATE KEY??? 🤯), you will...

View Article


Books I have read in 2025

Books I have read in 2025. Should be mostly spoiler free.

View Article

Asymmetric keys and Siths

Some (not so serious) cryptographic wisdom from a long time ago…

View Article

Reinforcement Learning formulas cheat sheet

Cheat sheet for (some) reinforcement learning mathematical formulas and algorithms.

View Article

Concealing XSS payloads

PortSwigger “Concealing payloads in URL credentials” talks about concealing XSS payloads in URL credentials. The nice thing is that this makes the payload invisible to WAFs and other server-side XSS...

View Article


Codingame Spring Challenge 2025

My experience from the Codingame Spring Challenge 2025.

View Article

Testing Unicode Tag Smuggling in chatbots

Testing ASCII smuggling using Unicode Tags on LLMs/chatbots. Nothing new here. Just a short summary.

View Article


Books I have read in 2024

Books I read in 2024. Tries to avoid spoiling as much as possible and therefore does not contain a very deep analysis or review of most books.

View Article

Keycloak UMA vulnerabilities

Keycloak UMA's implementation seems tricky to me.

View Article


llama.cpp quickstart

How to quickly use llama.cpp for LLM inference (no GPU needed).

View Article

vLLM quickstart

How to quickly use vLLM for LLM inference using CPU.

View Article

Invasion of Czechoslovakia in 1968

On August 20 1968, Czechoslovakia was invaded by the armies of Warsaw Pact.

View Article
Browsing index pages (123 articles)


Latest Images