Professional ethical hacking services

Budapest, Hungary
New research: pre-auth RCE in IBM Db2 Mirror for i, chained all the way to QSECOFR (IBM i's top privilege). A path-parameter auth bypass + a "skip validation" flag + a write primitive = JSP execution in the web app, then a native helper to QSECOFR. blog.silentsignal.eu/2026/09…
2
5
565
Pre-auth RCE as QSECOFR (IBM i root) via Management Central: the verify flag is client-controlled -> send verify=0, type=3, userId=QSECOFR and get a root shell without credentials. Affects V7R4 and earlier. blog.silentsignal.eu/2026/06… #IBMi #AS400 #infosec
6
16
1,327
Our newest blog post demonstrates once again that "attacks always get better, they never get worse" – and IBM i (AS/400) is no exception. Enjoy the next part of our journey along the trail of CVE-2023-30990: blog.silentsignal.eu/2025/09…
1
8
9
1,237
In our new blog post, we describe how we found an authentication bypass in Git hosting software Gitblit, what the root cause was, and what both attackers and developers can learn about the security impact of state machines. blog.silentsignal.eu/2025/06…
3
11
467
Story of a Pentester Recruitment 2025 blog.silentsignal.eu/2025/01…
8
241
In our new blogpost we guide you through the process of improving the tools available for pentesting #WCF services over the net.tcp binding: blog.silentsignal.eu/2024/10… #BurpSuite #KaitaiStruct #pentest
1
10
316
IBM issued a fix to CVE-2024-27275 that mitigates an #IBMi privilege escalation technique we published last year: 🥷blog.silentsignal.eu/2023/03… 🧑‍🏭ibm.com/support/pages/node/7… The PTF restricts the use of the ADDPFTRG command - this is a breaking change documented in the Memo to Users.
4
226
We're stoked we got to present about low-level #IBMi internals at @reconmtl! Here you can find our ... ...slides: silentsignal.hu/docs/S2-REco… ...and detailed writeup: silentsignal.github.io/Below…
4
6
1,137
It was an honor to present our #IBMi exploits at #TROOPERS24 today! You'll have to wait until @WEareTROOPERS releases the recordings for the full show (incl. live demos), until then you can find our slides here: silentsignal.hu/docs/S2-TROO…
7
13
1,946
We are glad to announce that our #IBMi research will be presented at multiple prestigious conferences this June 1/3
1
2
3
1,088
At @WEareTROOPERS we will show how pentesters can adopt their Windows/*nix experiences to the platform, and discover new vulnerabilities in native IBM i programs 2/3 troopers.de/troopers24/talks…
1
3
4
2,466
At @reconmtl will dive deep into the architecture to understand its security features and present foundational tools for low-level research 3/3 cfp.recon.cx/recon2024/talk/…
3
8
1,261
#IBMi is vulnerable to a local privilege escalation due to flaws in Management Central (CVE-2023-40685, CVE-2023-40686) Two more CVE's were assigned as the result of our reports. Management Central service doesn't need to run for exploitation. ibm.com/support/pages/node/7…
9
362
Join the live webinar to learn how the Silent Signal team discovers formerly unknown flaws in IBM i Systems, and how they can help organizations to secure existing IBM i infrastructures beyond compliance. When: 26 October 2023 at 5 PM CET Register: ibmi.silentsignal.eu/#demo
1
2
547
Another #IBMi privilege escalation reported by us was just fixed - this is CVE-2023-40375: "IBM i is vulnerable to a local privilege escalation due to a flaw in the base operating system code related to the Integrated application server for IBM i" ibm.com/support/pages/node/7…
2
4
1,247
Technical Details of CVE-2023-30988 - IBM Facsimile Support Privilege Escalation #IBMi blog.silentsignal.eu/2023/08…

ALT Jurassic Park GIF

4
6
1,309
IBM fixed multiple #IBMi LPE vulnerabilities reported by us: ibm.com/support/pages/node/7… ibm.com/support/pages/node/7… We'll publish technical details about these soon. Additionally, CVE-2023-30990 (DDM RCE) got its CVSS score raised: ibm.com/support/pages/node/7…
3
5
1,291
Technical Details of CVE-2023-30990 - Unauthenticated RCE in IBM i DDM Service #IBMi #AS400 blog.silentsignal.eu/2023/07…
8
26
4,538