Found 1481 bookmarks
Newest
Как мы в Selectel нашли уязвимость в Mailcow, или немного о безопасности в open source
Как мы в Selectel нашли уязвимость в Mailcow, или немного о безопасности в open source
У коммерческих решений есть очевидные плюсы: профессиональная поддержка, регулярные аудиты, соответствие стандартам и сертификация. Open source — бесплатен, гибо...
·habr.com·
Как мы в Selectel нашли уязвимость в Mailcow, или немного о безопасности в open source
Trends
Trends
Trends Description
·dbugs.ptsecurity.com·
Trends
Historical Analysis of Reflected Vulnerabilities: The Evolution of Windows Defender Defenses
Historical Analysis of Reflected Vulnerabilities: The Evolution of Windows Defender Defenses
This report analyzes a historical class of security flaws known as “reflected vulnerabilities,”which were once potent zero-day attack vectors targeting early Windows versions and antivirussoftware. We examine classic exploitation techniques, such as parser attacks, packet fragmen-tation, and syscall abuse, which could lead to remote code execution (RCE) or privilege esca-lation. The objective is educational, demonstrating how modern defenses in Windows 11 andWindows Defender—such as Address Space Layout Randomization (ASLR), Data ExecutionPrevention (DEP), Control Flow Guard (CFG), and hardened parsers—have rendered this classof vulnerabilities obsolete. Proof-of-concept (PoC) code is provided solely to illustrate histor-ical concepts and is non-functional on modern systems, ensuring compliance with responsibledisclosure principles.
·zenodo.org·
Historical Analysis of Reflected Vulnerabilities: The Evolution of Windows Defender Defenses
s1r1us (@S1r1u5_) on X
s1r1us (@S1r1u5_) on X
Mutation-Based XSS + V8 type confusion + V8 sandbox escape = RCE on Basecamp. Disclosed it on Hackerone: https://t.co/slsv3j4jXx go read the comments if you wanna see what a week of exploit dev pain looks like.
·x.com·
s1r1us (@S1r1u5_) on X
XS-Leaks through Speculation-Rules - SECCON CTF 13 Author's Writeup ( Tanuki Udon ) - Satoooonの物置
XS-Leaks through Speculation-Rules - SECCON CTF 13 Author's Writeup ( Tanuki Udon ) - Satoooonの物置
JP (Translated by ChatGPT) In this article, I'll explain the intended solution for the "Tanuki Udon" challenge presented in SECCON CTF 13. TL;DR An XS-Leaks attack using Speculation Rules can be performed when the following conditions are met: The attacker can inject Speculation Rules into the victi…
·satoooon1024.hatenablog.com·
XS-Leaks through Speculation-Rules - SECCON CTF 13 Author's Writeup ( Tanuki Udon ) - Satoooonの物置