Technical insights from Blaze Labs
Blaze Labs is the R&D group of Blaze Information Security.

LLM pentest: Leveraging agent integration for RCE
This post describes a case study of a recent LLM pentest engagement that allowed to exploit the LLM agent for remote code execution.
All Articles

Fuzzing proprietary protocols with Scapy, radamsa and a handful of PCAPs
Introduction As security consultants, we act as hired guns by our clients to perform black-box security testing of applications. Oftentimes we have to assess the

Security advisory: Porteus Kiosk security restrictions bypass
Advisory information Title: Porteus Kiosk security restrictions bypass Advisory reference: BLAZE-01-2017 Product: Porteus Kiosk Disclosure mode: Coordinated disclosure Product description Porteus Kiosk is a popular

Practical attacks against GSM networks (Part 1/3): Impersonation
Introduction The Global System for Mobile Communications (GSM) is a mobile technology and the most popular standard for mobile phones worldwide. Originally known as Groupe

Turning Burp Scanner vulnerabilities into Splunk events
Introduction Splunk is a fully featured, powerful platform for collecting, searching, monitoring, and analyzing machine data. It is widely used by Security Operation Center (SOC)

A survey on the usage of HTTP security headers in Brazil and Estonia
Introduction In recent years a number of security-oriented client-side controls for web browsers appeared in the scene in form of security headers. These headers can

Leveraging Telegram as a command & control platform
Introduction At Blaze, we are always looking for new ways to further improve our engagements. As every penetration tester knows, post-exploitation is a crucial step
