Archive

Archive

Jackin tor
Jackin tor
·packetstorm.foofus.com·
Jackin tor
PATCH ANALYSIS OF MS16-063 (JSCRIPT9.DLL) | THEORI
PATCH ANALYSIS OF MS16-063 (JSCRIPT9.DLL) | THEORI
Last week, Microsoft released the MS16-063 security bulletin for their monthly Patch Tuesday (June 2016) security updates. It addressed vulnerabilities that affected Internet Explorer. Among other things, the patch fixes a memory corruption vulnerability in jscript9.dll related to TypedArray and DataView.
·theori.io·
PATCH ANALYSIS OF MS16-063 (JSCRIPT9.DLL) | THEORI
RPO Gadgets
RPO Gadgets
If you are here because you thought the title meant Return Oriented Programming (ROP), then sorry for the clickbait. I wanted to introduce a techninque to help exploit Relative Path Overwrite (RPO) when XSS is not an option by chaining "gadgets". This will be the first part of
·blog.innerht.ml·
RPO Gadgets
Exploiting Internet Explorer’s MS15-106, Part I: VBScript Filter Type Confu
Exploiting Internet Explorer’s MS15-106, Part I: VBScript Filter Type Confu
In October 13, 2015 Microsoft published security bulletin MS15-106, addressing multiple vulnerabilities in Internet Explorer. Zero Day Initiative published advisory ZDI-15-521 for one of those vulnerabilities affecting IE: Microsoft Windows VBScript Filter Function Remote Code Execution Vulnerability (CVE-2015-6055), so I decided to take a shot at it. Quoting ZDI's advisory:
·blog.coresecurity.com·
Exploiting Internet Explorer’s MS15-106, Part I: VBScript Filter Type Confu
The avast! Series
The avast! Series
I spent some time quite a while ago looking into avast! and, after about a year, I am going to post about the issues that were found, and fi...
·expertmiami.blogspot.nl·
The avast! Series
Windows 10’s New Browser Microsoft Edge: Improved, But Also New Risks
Windows 10’s New Browser Microsoft Edge: Improved, But Also New Risks
Last week we discussed how Microsoft Edge, the new browser in Windows 10, represented a significant increase in the security over Internet Explorer. However, there are also new potential threat vectors that aren’t present in older versions. Integrated plug-ins Microsoft Edge has now integrated two widely used plug-ins into the browser itself: Adobe Flash and a PDF reader....
·bit.ly·
Windows 10’s New Browser Microsoft Edge: Improved, But Also New Risks
Server-Side Template Injection
Server-Side Template Injection
Template engines are widely used by web applications to present dynamic data via web pages and emails. Unsafely embedding user input in templates enables Server-Side Template Injection, a frequently c
·blog.portswigger.net·
Server-Side Template Injection
Exploit
Exploit
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation. CVE-2015-5602. Local exploit for Linux platform
·goo.gl·
Exploit
V v8c4b
V v8c4b
·goo.gl·
V v8c4b