Found 1481 bookmarks
Newest
Leaking IPs in Brave Tor Window & Chrome VPNs + Popunders + CSP Bypass
Leaking IPs in Brave Tor Window & Chrome VPNs + Popunders + CSP Bypass
This writeup details multiple IP leak vulnerabilities I discovered affecting Brave's Tor window and Chrome VPN extensions that allowed a malicious actor to leak the real IP address of any visitor to a remote host. Also covers a connect-src CSP bypass for DNS-based data exfiltration and two new Popunder techniques that work on Chrome, Firefox & Safari.
·0x999.net·
Leaking IPs in Brave Tor Window & Chrome VPNs + Popunders + CSP Bypass
Abusing Windows Audio for Local Privilege Escalation
Abusing Windows Audio for Local Privilege Escalation
While analyzing Windows Audio components, I discovered an interesting privilege escalation vector that exploits the Windows Audio architecture and can be used as a universal technique to exploit…
·medium.com·
Abusing Windows Audio for Local Privilege Escalation
Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign - Check Point Research
Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign - Check Point Research
Highlights Introduction While the abuse of vulnerable drivers has been around for a while, those that can terminate arbitrary processes have drawn increasing attention in recent years. As Windows security continues to evolve, it has become more challenging for attackers to execute malicious code without being detected. As a result, the attackers often aim to […]
·research.checkpoint.com·
Silent Killers: Unmasking a Large-Scale Legacy Driver Exploitation Campaign - Check Point Research
Privilege Escalation via a service account impersonation chain
Privilege Escalation via a service account impersonation chain
Table of Contents Preface TLDR Live Hacking Event 101 Getting invited Picking the target Why Google SecOps SOAR? Reading the docs Methodology SOAR Integrations Python execution environment aka RCE-as-a-Service IDE custom code validation bypass We are in, what next? Fetching the OAuth Access Token Access token introspection What is gke-init-python used for? Service Account impersonation Prior art What can gke-init-python do? Malachite enters the scene Revised architecture diagram Auth flow is complex Examining SOAR_SIGNED_JWT Connecting the dots Let’s sign our own JWTs! Vertical Privilege Escalation Full SSRF via the HTTPv2 integration Code Execution via SSTI in TemplateEngine PowerUp Full attack scenario The aftermath Remediation Closing Remarks Preface Link to heading This is a behind-the-scenes story of how I found a Service Account impersonation chain leading to vertical privilege escalation within Google SecOps SOAR.
·jdsec.cloud·
Privilege Escalation via a service account impersonation chain
Claude's Constitution
Claude's Constitution
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
·anthropic.com·
Claude's Constitution
Who’s on the Line? Exploiting RCE in Windows Telephony Service
Who’s on the Line? Exploiting RCE in Windows Telephony Service
Windows has supported computer telephony integration for decades, providing applications with the ability to manage phone devices, lines, and calls. While modern deployments increasingly rely on cloud-based telephony solutions, classic telephony services remain available out of the box in Windows and continue to be used in specialized environments. As a result, legacy telephony components still […]
·swarm.ptsecurity.com·
Who’s on the Line? Exploiting RCE in Windows Telephony Service