Microsoft Exchange Autodiscover bug leaks hundreds of thousands of domain credentials
Security researchers have discovered a design flaw in a feature of the Microsoft Exchange email server that can be abused to harvest Windows domain and app credentials from users across the world.
Introduction One of the first steps when looking to gain access to a host, system, or application is to enumerate usernames. Once usernames are guessed or enumerated targeted password based attacks…
At the beginning of this month, GitLab released a security patch for versions 14-15. Interestingly in the advisory, there was a mention of a post-auth RCE bug with CVSS 9.9.
The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally, when I rummaged in the author’s h1 profile. I discovered that four months ago, he also found a bug in the import project feature:
Initially, I thought it was tempting after seeing the bounty, so I started learning Rails and debugged this bug!
Turn any Linux computer into a SOCKS5 proxy with one command
I thought I'd write a shorter article this time. It goes hand in hand with my upcoming article series on 100% technical guide to anonymity and it's much easier to write larger articles by splitting them into smaller pieces. I can then just edit them together and produce the final article. This article will be...
The seventh way to call a JavaScript function without parentheses
I thought I knew all the ways to call functions without parentheses: alert`1337` throw onerror=alert,1337 Function`x${'alert\x281337\x29'}x``` 'alert\x281337\x29'instanceof{[Symbol['hasInstance']]:eva
It's been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
CVE-2022-28219 is an unauthenticated remote code execution vulnerability affecting Zoho ManageEngine ADAudit Plus, a compliance tool used by enterprises to monitor changes to Active Directory. The vulnerability comprises several issues: untrusted Java deserialization, path traversal, and a blind XML External Entities (XXE) injection. This is a vulnerability that NodeZero, our autonomous pentesting product, has exploited […]
Office Documents: May the XLL technique change the threat Landscape in 2022? - Yoroi
Introduction Contrasting the malware delivery is hard. Cyber attackers evolve their techniques frequently, but a major trend remained constant: Microsoft Office and Excel documents represent the favorite delivery method many cyber criminals use to inoculate malware into private and public companies. This technique is extremely flexible and both opportunistic and APT actors abuse it. In the last months, we monitored with particular attention several attack waves adopting a new delivery technique: binary libraries directly loaded by Microsoft Excel, just in one click. This emergent delivery technique leverages XLL files, a particular file type containing a Microsoft Excel application ready to be loaded. […]
On May 10, 2022, Zimbra released versions 9.0.0 patch 24 and 8.8.15 patch 31 to address multiple vulnerabilities in Zimbra Collaboration Suite, including CVE-2…
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)
– by TheGrandPew and s1r1us
We all know, VSCode is one of the most used Electron App. As a part of our research on hacking electron apps, we thought it would be cool to pwn VSCode and we were able to pwn it. We were able to achieve RCE on VSCode without getting to use any of our new fancy stuff.
TL; DR Remote Code execution can be achieved when a victim opens a markdown file in a maliciously crafted VSCode Project or a folder even in VSCode Restricted Mode.
$50 миллионов, помогая компаниям с email-рассылками — маркетолог поделился 4-мя шаблонами писем, которые на 30% увеличивают доход e-commerce сайтов
Как создать воронку email-писем, которая зацепит вашу аудиторию? Делимся рекомендациями Чейза Даймонда — маркетолога, который заработал более $50 миллионов, помогая крупным компаниям с email-рассылками.
OneNote is one of the Office suite components which is often overlooked when RedTeaming. Though OneNote cannot execute VBA Macros, it has an important potential for phishing as an initial vector.
Background AMP is most commonly used as a framework to develop fast-loading content on the web. One of AMP's projects, AMP4Email has been adopted in recent years by many of the leading mail services as a way to provide Dynamic Emails (essentially a subset of regular HTML with a few default components to handle things like layouts, templates, forms, and such). When I first heard about this feature a few years ago, my initial reaction (like many of you I’m sure) was “This can’t be secured! How did
On May 6, 2022, Rarlab released version 6.17, which addresses CVE-2022-30333, a path traversal vulnerability reported to them by Sonar, who posted a write-up a…
Phân tích lỗ hổng Zimbra pre auth rce CVE-2022-30333
Tổng quan
* Tháng 5/2022, Rarlab công bố lỗ hổng CVE-2022-30333 của phần mềm unrar các phiên bản trước 6.12 hoặc trước 6.1.7 chạy trên hệ điều hành Linux hoặc UNIX. Lỗ hổng trên cho phép attacker có thể ghi file ra các thư mục tùy ý