CosmicSting & JFIF Evasion: How Magento Webshells Hide Inside Image Files
How attackers exploit CVE-2024-34102 to deploy PHP webshells disguised as JPEG images, evading scanners that filter by file extension.
Read ArticleI specialize in identifying, analyzing, and mitigating threats in server environments with a focus on ensuring system security and implementing robust preventive measures.
Get In TouchCommunicative, compliant team player with a supportive nature, passionate about cybersecurity and technology.
Athens, Greece
info@kbourdakos.gr
CloudLinux
I specialize in identifying, analyzing, and mitigating threats in server environments. My role focuses on ensuring system security by detecting malicious activities, removing malware, and implementing robust preventive measures.
Leveraging cutting-edge tools and techniques, I work to safeguard web hosting platforms and enterprise environments against evolving cyber threats.
CloudLinux
Providing consulting services of technical support for Imunify360 security products, a next-generation security solution built for Linux servers.
team.blue Group of Companies
Applying state of the art Web Hosting technologies while ensuring the deliverability of our services in a client oriented ecosystem.
OTE Group of Companies (HTO)
System Administration & Operations of Hellenic Telecommunications Organization SA as part of Deutsche Telekom Group Of Companies. Accounts Involved t-Albania, t-Romania, TMNL, Coca-Cola & OTE Core.
KBourdakos Computer Systems
Duties Involved: Building OEM Systems, Contracts of Support, Sales/Retail, Imports/Exports (EU/USA), In-House Custom App Development, Web Hosting, Customer Support.
Piraeus University of Applied Sciences
University of Cambridge
Queen Mary's College, Basingstoke
How attackers exploit CVE-2024-34102 to deploy PHP webshells disguised as JPEG images, evading scanners that filter by file extension.
Read ArticleHow a WordPress backdoor survives complete file deletion by storing its payload in the database and regenerating itself on every HTTP request.
Read Article
Analysis of the recent surge in CVE-2017-9841 exploitation attempts targeting PHPUnit's eval-stdin.php for remote code execution.
Read ArticleAnalysis of a dangerous WordPress plugin that creates hidden admin users and maintains backdoor access.
Read Article