Found 1481 bookmarks
Newest
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
Given my interest in SCM and CI systems I was a little keen to see how this is done at Mozilla as part of their bug bounty program. Thanks to freddy I was granted Level 1 access to Mozilla’s SCM at hg.mozilla.org in late 2022. As Mozilla is a pretty transparent company I found the version-control-tools repository which contains the code and configuration behind hg.mozilla.org. I spent a couple of hours to a very few days looking at this code, setting up a simplified test system, and popping shells on the infrastructure around Christmas 2022.
·0day.click·
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
r-tec Blog | When Hackers hack the Hackers
r-tec Blog | When Hackers hack the Hackers
Last year, our experts had the opportunity to observe the execution of non-standard processes in a sandbox-like, isolated virtual machine (VM). Further analysis of these processes revealed Command & Control (C2) connections using Discord for communication. As we continued to analyse the C2 agent, we also gained access to the attacker's Discord channel and were able to take a look at all the commands and modules executed for many more compromised systems. This attacker/group was very different to the ones we typically see while doing Incident Response for our customers in terms of the motivation and goals. It seemed, that this attacker was mainly compromising Malware developers and or Offensive Security related people to steal and sell code from the target systems. In this post, the malware analysis process, as well as attacker activities and Indicators of Compromise (IoCs) are presented.
csproj
·r-tec.net·
r-tec Blog | When Hackers hack the Hackers
oбуч джой Bing
oбуч джой Bing
Сразу скажу будет немного воды ну это для тех кто вообще не что это такое и с трактовкой понял ===============ЗАПУСК С ЛОГОВ=========== = = == Момент загрузки сессии я пропускаю, как всегда не бывает, не меняется
·telegra.ph·
oбуч джой Bing
CVE-2022-41352 | AttackerKB
CVE-2022-41352 | AttackerKB
On September 25, 2022, CVE-2022-41352 was filed for Zimbra Collaboration Suite. The vulnerability is a remote code execution flaw that arises from unsafe usage…
·attackerkb.com·
CVE-2022-41352 | AttackerKB
Disabling ClamAV as an Unprivileged User
Disabling ClamAV as an Unprivileged User
About The Project ClamAV is an Open Source antivirus engine that is widely used on mail servers to scan incoming messages. On February 15, 2023 ClamAV published a security advisory detailing a potential remote code execution vulnerability in its HFS+ file parser. This vulnerability was given the CVE identifier of CVE-2023-20032. While reading about this vulnerability, I stumbled across an open pull request indicating that its possible for non-privileged users to disable clamav.
·archcloudlabs.com·
Disabling ClamAV as an Unprivileged User
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
TeamFiltration is self-defined as a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts. In this article, we will look at its capabilities and how we can potentially detect related events in Azure AD and Microsoft 365 logs. While the article focuses on TeamFiltration, the learnings apply to any similar toolset.
·guillaumeben.xyz·
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
Hacking the World with HTML | 🔐Blog of Osanda
Hacking the World with HTML | 🔐Blog of Osanda
In my previous article Exploring the MS-DOS Stub I stated that after experimenting, the Windows loader only cares about the e_magic and the e_lfanew members from the _IMAGE_DOS_HEADER. Because the …
·osandamalith.com·
Hacking the World with HTML | 🔐Blog of Osanda
Till REcollapse - 0xacb
Till REcollapse - 0xacb
Welcome back to my blog. In this post, I’ll explain the REcollapse technique. I’ve been researching it for the last couple of years to discover weirdly simpl...
·0xacb.com·
Till REcollapse - 0xacb
Second Order XXE Exploitation
Second Order XXE Exploitation
A writeup about my finding on Synack that was an XXE that allowed me to read local files stored on the web server.
·kuldeep.io·
Second Order XXE Exploitation