You won't believe you don't need to see those horrible ads on the web
This #1 trick ad companies don't want you to know!
View ArticleTool call execution through user prompt injection (CSRF) of the llama-server...
A user prompt injection vulnerability (CSRF) in the llama-server (llama.cpp) Web UI (Reprompt-like) allows attackers to inject arbitrary user prompt with query parameter (?q=...), potentially leading...
View ArticleUser prompt injection (CSRF) on Le Chat and Grok
An user prompt injection vulnerability (CSRF) both in in the e Chat (Mistral) and Grok (Reprompt-style) allows attackers to inject user prompt with query parameter (?q=...) potentially leading data...
View Articlellama.cpp quickstart (part 2)
How to quickly use llama.cpp for LLM inference (part 2). This is a follow-up of a previous post on the same topic.
View ArticleMalleability of ECDSA (and DSA) signatures, JWTs, etc.
This blog posts explains that ECDSA and DSA signatures are malleable, that JWTs can be malleable as well and how this can be used to bypass some broken implementations of JWT deny lists (for revocation...
View ArticleRisk of reflected cross site scripting and Content-Security-Policy bypass in...
I was reading the WebSub specification (formerly PubSubHubbub) when I found that there was a risk of reflected browser-side code injection (reflected cross site scripting, reflected XSS) in the WebSub...
View ArticleComputer security guidelines and references
A list of computer security guidelines and references.
View ArticleAuthority Ambiguity Vulnerabilities in NGINX and Debian’s proxy_params
Two related authority-ambiguity vulnerabilities in NGINX and Debian's proxy_params configuration snippet.
View ArticleCryptography formats
If you are trying to understand the difference between the different cryptography-related formats (PKS#12, PKCS#8, PEM, X.509 certificate, DER, JWK, BEGIN ENCRYPTED PRIVATE KEY??? 🤯), you will...
View ArticleAsymmetric keys and Siths
Some (not so serious) cryptographic wisdom from a long time ago…
View ArticleReinforcement Learning formulas cheat sheet
Cheat sheet for (some) reinforcement learning mathematical formulas and algorithms.
View ArticleConcealing XSS payloads
PortSwigger “Concealing payloads in URL credentials” talks about concealing XSS payloads in URL credentials. The nice thing is that this makes the payload invisible to WAFs and other server-side XSS...
View ArticleCodingame Spring Challenge 2025
My experience from the Codingame Spring Challenge 2025.
View ArticleTesting Unicode Tag Smuggling in chatbots
Testing ASCII smuggling using Unicode Tags on LLMs/chatbots. Nothing new here. Just a short summary.
View ArticleBooks I have read in 2024
Books I read in 2024. Tries to avoid spoiling as much as possible and therefore does not contain a very deep analysis or review of most books.
View ArticleInvasion of Czechoslovakia in 1968
On August 20 1968, Czechoslovakia was invaded by the armies of Warsaw Pact.
View Article