betan - Ghostbin
Phishing Against Protected View – Posts By SpecterOps Team Members
Microsoft Office has a security feature called Protected View.
Guest Blog: Don’t Leave your Grid Wide Open
Our guest blogger and Detectify Crowdsource hacker Peter Jaric explains how Selenium Grid could be exploited to read files on the server.
Hack Patch!: PWA - Progressive Web Attack
Today, I'm going to blog about PWA (Progressive Web Apps)🙂 These days, web is getting bit secure by the help of CSP, which turns XSS i...
The Absurdly Underestimated Dangers of CSV Injection
GitHub - Bo0oM/CVE-2017-7089: Safari 10 exploit (CVE-2017-7089)
Webkit uxss exploit (CVE-2017-7089)
Mac OS X Local Javascript Quarantine Bypass | segment
Как работает Android, часть 1
В этой серии статей я расскажу о внутреннем устройстве Android — о процессе загрузки, о содержимом файловой системы, о Binder и Android Runtime, о том, из...
GitHub - vysec/CVE-2017-8759: CVE-2017-8759 - A vulnerability in the SOAP W
CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
DIY Spy Program: Abusing Apple's Call Relay Protocol - Martin Vigo
Finding, exploiting and leveraging vulnerabilities in Apple's Call Relay protocol to build a spy program. CVE: 2016-4635, 2016-4721, 2016-4722, 2016-7577
Mousejacking | To Shell And Back: Adventures In Pentesting
On internal engagements, poisoning name resolution requests on the local network (à la Responder) is one of the tried and true methods of obtaining that coveted set of initial Domain credentials. While this approach has worked on many clients, what if Link Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NTB-NS) protocols are configured securely or disabled? Or, what if Responder was so successful that you now want to prove other means of gaining that initial foothold? There are a multitude of attacks a penetration tester can leverage when conducting physical walkthrough...
A Forgotten HTTP Invisibility Cloak
This presentation illustrates a number of techniques to smuggle and reshape HTTP requests using features such as HTTP Pipelining that are not normally used by …
Sniffly2
CVE to Exploit - CVE-2017-[0037 and 0059]
CVE-2017-[0037 and 0059] Internet Explorer 11 Following the last 2 blog posts for both CVE-2017-0037 and CVE-2017-0059 here's a full working exploit for IE11 <= 11.0.37 for Windows 7 (32 and 64 bit). I tested it only on two (not too) different machines so please if you
CVE to PoC - CVE-2017-0059
CVE-2017-0059 Internet Explorer “There is an use-after-free bug in IE which can lead to info leak / memory disclosure. The bug was confirmed on Internet Explorer version 11.0.9600.18537 (update version 11.0.38). [...] The root cause of a bug is actually a use-after-free on the textarea text value,
Автоматизация рыбной ловли для World of Warcraft / Хабрахабр
Познакомился с World of Warcraft очень давно и люблю его весь, но одна вещь больше всего не давала мне покоя — рыбная ловля. Это нудное повторяющееся действие,...
DEF CON 25 Hacker Conference
Modern Alchemy: Turning XSS into RCE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Make your own USB Rubber Ducky using a normal USB stick |
Проникновение через субтитры. Полный разбор нашумевших атак на PopcornTime,
В мае этого года исследователи Check Point Software Technologies обнаружили совершенно новый вектор атак — атаки через субтитры. Злоумышленники могут использовать файлы субтитров для получения контроля над компьютерами пользователей, при этом избегая обнаружения. В этой статье мы расскажем, как это у них получилось (обязательно запасись кофе – статья вышла большая :) – прим. ред.)
Security Blog By @rakeshmane10: Xssing Web Part - 2
Security Blog
DEF CON 25 Hacker Conference
GitHub - denysdovhan/wtfjs: A list of funny and tricky JavaScript examples
wtfjs - A list of funny and tricky JavaScript examples
How we invented the Tesla DOM DOOM XSS
Many have seen the video where vexal modifies his Porsche 911 to run DOOM. It is the same guy who used a toaster to control a PC game a few years ago. How technically accurate these videos are can be discussed, but the underlying creativity is hard to question. Naturally, when we saw the video, we did not want to lag behind, but what is the best way to respond to something like this? Inventing the DOM DOOM XSS, of course!
Analyzing CVE-2017-0190: WMF Flaws Can Lead to Data Theft, Code Execution |
CVE-2017-0190 is a recently patched vulnerability related to Windows metafiles (WMFs), a portable image format mainly used by 16-bit Windows applications. Recently we have seen an increase in the number of vulnerabilities related to WMFs and EMFs (enhanced metafiles) in the GDI32 library. Most often, these
Execute a DLL via .xll files and the Excel.Application object's RegisterXLL
Execute a DLL via .xll files and the Excel.Application object's RegisterXLL() method · GitHub
How i Hacked into a PayPal's Server - Unrestricted File Upload to Remote Co
PowerPoint Presentation
How the Twitter App Bypasses Paywalls | Elaine's Idle Mind
by Isoroku Yamamoto Wall Street Journal ended its practice of allowing special access for search engines. This means that a human visitor can no longer bypass the paywall by spoofing Google’s HTTP …
Haifei's random thoughts: "Bypassing" Microsoft's Patch for CVE-2017-0199
Background If you have followed my research on the infamous CVE-2017-0199 zero-day attack, you may know we (w/ my colleague Bing) did a p...
