Udayveer Singh
m4lici0u5.com
Udayveer Singh
@m4lici0u5.com
Offensive Security | Red Teamer | Learning MalDev | OSEP | CRTL | OSWP | CRTO | CRTE | CRTP | CESP-ADCS | eJPT

http://m4lici0u5.com
Reposted by Udayveer Singh
COFFing out the Night Soil

aff-wg.org/2025/09/10/c...

A COFF-focused Crystal Palace update:

* internal COFF normalization & section group merging
* Crystal Palace can now export COFF
* I added COFF merging to the spec language too

Linker stuff.
COFFing out the Night Soil
I’m back with another update to the Tradecraft Garden project. Again, this release is focused on the Crystal Palace linker. My priority in this young project is to build the foundation first, then …
aff-wg.org
September 10, 2025 at 9:37 PM
Reposted by Udayveer Singh
Defenders use cross-origin requests through CSS url() or injected JS to leak your phishing URL in the HTTP Referer header.

Today, I've been reminded about the excellent post by Keanu Nys, which contains a lot of great evasion ideas!

insights.spotit.be/2024/06/03/c...
Clipping the Canary’s wings: Bypassing AiTM Phishing Detections | Spotit insights
insights.spotit.be
November 18, 2024 at 11:29 AM
Reposted by Udayveer Singh
Evilginx Pro Update:

Tool is ready and awaits release.

I'm now creating an online shop engine, because why not 😜

I hope one day it becomes Steam for cybersecurity tools with Evilginx Pro its first release, like Half-Life 2 on Steam exactly 20 years ago.

Red team tools unite!
November 19, 2024 at 4:57 PM