Skip to main content

Thomas Wilson

Senior red team operator and penetration tester at Bishop Fox, co-host of the Initial Access podcast, with a background in mobile and cloud security.

Oct 2, 2026

2:16
Yeah.
2:16
And that they should probably, you know, in, do some form of interpretation on their string, uh, to make sure that the true intent of the string is being blocked.
2:25
Uh, because percent 50 is, uh, not that hard and, uh, to, to, to, to write into your browser.
2:32
And, uh, if that is the only thing stopping a person from exploiting a very critical all the way to RCE, uh, vulnerability, then, uh, I think you probably should take a few more seconds to implement, uh, a slightly better rule, uh, for, for your WAF.
2:45
Uh, but that's, uh, that's the, the core of what we're seeing here.
2:49
And it's very unfortunate.
2:51
I hope it was a little bit more complicated because I think this is, uh, we'll get to this a little bit later, but this was tied into their previous things of, of compromising the, uh, FBI's, you know, jobs.gov, whatever instance that-

25 MINS LATER

27:57
That's a very good point.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.