Archive

Archive

1481 bookmarks
Custom sorting
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Zimbra, a widely used email and collaboration platform, recently released a critical security update addressing a severe vulnerability in its postjournal service. This vulnerability, identified as CVE-2024-45519, allows unauthenticated attackers to execute arbitrary commands on affected Zimbra installations. In this blog post, we delve into the nature of this vulnerability, our journey in analyzing the patch, and the steps we took to exploit it manually. We also discuss the potential impact and
·projectdiscovery.io·
Zimbra - Remote Command Execution (CVE-2024-45519) — ProjectDiscovery Blog
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security
I previously blogged about spoofing Microsoft 365 using the direct send feature enabled by default when creating a business 365 Exchange Online instance (https://www.blackhillsinfosec.com/spoofing-microsoft-365-like-its-1995/). Using the direct send feature, it […]
·blackhillsinfosec.com·
Spamming Microsoft 365 Like It’s 1995 - Black Hills Information Security
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
Given my interest in SCM and CI systems I was a little keen to see how this is done at Mozilla as part of their bug bounty program. Thanks to freddy I was granted Level 1 access to Mozilla’s SCM at hg.mozilla.org in late 2022. As Mozilla is a pretty transparent company I found the version-control-tools repository which contains the code and configuration behind hg.mozilla.org. I spent a couple of hours to a very few days looking at this code, setting up a simplified test system, and popping shells on the infrastructure around Christmas 2022.
·0day.click·
RCE via LDAP truncation on hg.mozilla.org :: 0day.click
r-tec Blog | When Hackers hack the Hackers
r-tec Blog | When Hackers hack the Hackers
Last year, our experts had the opportunity to observe the execution of non-standard processes in a sandbox-like, isolated virtual machine (VM). Further analysis of these processes revealed Command & Control (C2) connections using Discord for communication. As we continued to analyse the C2 agent, we also gained access to the attacker's Discord channel and were able to take a look at all the commands and modules executed for many more compromised systems. This attacker/group was very different to the ones we typically see while doing Incident Response for our customers in terms of the motivation and goals. It seemed, that this attacker was mainly compromising Malware developers and or Offensive Security related people to steal and sell code from the target systems. In this post, the malware analysis process, as well as attacker activities and Indicators of Compromise (IoCs) are presented.
csproj
·r-tec.net·
r-tec Blog | When Hackers hack the Hackers
oбуч джой Bing
oбуч джой Bing
Сразу скажу будет немного воды ну это для тех кто вообще не что это такое и с трактовкой понял ===============ЗАПУСК С ЛОГОВ=========== = = == Момент загрузки сессии я пропускаю, как всегда не бывает, не меняется
·telegra.ph·
oбуч джой Bing
CVE-2022-41352 | AttackerKB
CVE-2022-41352 | AttackerKB
On September 25, 2022, CVE-2022-41352 was filed for Zimbra Collaboration Suite. The vulnerability is a remote code execution flaw that arises from unsafe usage…
·attackerkb.com·
CVE-2022-41352 | AttackerKB
Disabling ClamAV as an Unprivileged User
Disabling ClamAV as an Unprivileged User
About The Project ClamAV is an Open Source antivirus engine that is widely used on mail servers to scan incoming messages. On February 15, 2023 ClamAV published a security advisory detailing a potential remote code execution vulnerability in its HFS+ file parser. This vulnerability was given the CVE identifier of CVE-2023-20032. While reading about this vulnerability, I stumbled across an open pull request indicating that its possible for non-privileged users to disable clamav.
·archcloudlabs.com·
Disabling ClamAV as an Unprivileged User
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
TeamFiltration is self-defined as a cross-platform framework for enumerating, spraying, exfiltrating, and backdooring O365 AAD accounts. In this article, we will look at its capabilities and how we can potentially detect related events in Azure AD and Microsoft 365 logs. While the article focuses on TeamFiltration, the learnings apply to any similar toolset.
·guillaumeben.xyz·
Microsoft 365 enumeration, spraying and exfiltration - TeamFiltration in the spotlight
Hacking the World with HTML | 🔐Blog of Osanda
Hacking the World with HTML | 🔐Blog of Osanda
In my previous article Exploring the MS-DOS Stub I stated that after experimenting, the Windows loader only cares about the e_magic and the e_lfanew members from the _IMAGE_DOS_HEADER. Because the …
·osandamalith.com·
Hacking the World with HTML | 🔐Blog of Osanda