Code Fighters
Lab
Na Conviso, nós acreditamos que o conhecimento é mais potente quando é compartilhado. Nosso Code Fighters Lab é composto pelo nosso time de Pesquisa e Desenvolvimento - pesquisadores de Segurança de Informação dedicados a estudar AppSec de forma contínua para trazer informação e desenvolvimento para a comunidade. A cultura de AppSec é um ideal que nos inspira. Nossos profissionais trabalham diariamente com o objetivo de trazer soluções inovadoras para os desafios de appsec - compartilhando suas descobertas e experiências e colaborando com a comunidade.
Explore nossas descobertas recentesConviso Code Fighters
Pesquisa, Colaboração e Inovação
Nossos estudos, análises e pesquisas mais populares
CVE: 2021–3311 October CMS Token Reactivation
Many bounties and many pieces of researches emerge just by looking at the right amount of code at the right path number and them BOOM!
A case study on: CVE-2021-22204 – Exiftool RCE
Recently, the researcher wcbowling found a vulnerability in the Exiftool tool, that enabled a malicious actor to perform a Remote code Execution attack.
CVE-2022-21831: Overview of the security issues we found in Rails’s image processing API
During a security auditing of the Ruby on Rails source and its dependencies, we discovered two ways to exploit ActiveStorage’s image…
Why are nonces important on CTR mode ciphers
This article: “Why are nonces important on CTR mode ciphers” was written 3 years ago, and is available again on our blog.
Bank malware mitigations
Malware (Bank malware mitigations) is the name for a program designed to mistreat its users.
Veracode API: Getting things done with AWS Lambda and AWS API Gateway
Every day at Conviso both dev and sre teams are working together facing challenges to make Conviso Platform a more complete solution.