Archive

Archive

1481 bookmarks
Custom sorting
Till REcollapse - 0xacb
Till REcollapse - 0xacb
Welcome back to my blog. In this post, I’ll explain the REcollapse technique. I’ve been researching it for the last couple of years to discover weirdly simpl...
·0xacb.com·
Till REcollapse - 0xacb
Second Order XXE Exploitation
Second Order XXE Exploitation
A writeup about my finding on Synack that was an XXE that allowed me to read local files stored on the web server.
·kuldeep.io·
Second Order XXE Exploitation
Username enumeration techniques and their value
Username enumeration techniques and their value
Introduction One of the first steps when looking to gain access to a host, system, or application is to enumerate usernames. Once usernames are guessed or enumerated targeted password based attacks…
·research.nccgroup.com·
Username enumeration techniques and their value
Gitlab Project Import RCE Analysis (CVE-2022-2185)
Gitlab Project Import RCE Analysis (CVE-2022-2185)
At the beginning of this month, GitLab released a security patch for versions 14-15. Interestingly in the advisory, there was a mention of a post-auth RCE bug with CVSS 9.9. The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally, when I rummaged in the author’s h1 profile. I discovered that four months ago, he also found a bug in the import project feature: Initially, I thought it was tempting after seeing the bounty, so I started learning Rails and debugged this bug!
·starlabs.sg·
Gitlab Project Import RCE Analysis (CVE-2022-2185)
Turn any Linux computer into a SOCKS5 proxy with one command
Turn any Linux computer into a SOCKS5 proxy with one command
I thought I'd write a shorter article this time. It goes hand in hand with my upcoming article series on 100% technical guide to anonymity and it's much easier to write larger articles by splitting them into smaller pieces. I can then just edit them together and produce the final article. This article will be...
·catonmat.net·
Turn any Linux computer into a SOCKS5 proxy with one command
The Long Tail of Log4Shell Exploitation
The Long Tail of Log4Shell Exploitation
It's been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.
·horizon3.ai·
The Long Tail of Log4Shell Exploitation
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
CVE-2022-28219 is an unauthenticated remote code execution vulnerability affecting Zoho ManageEngine ADAudit Plus, a compliance tool used by enterprises to monitor changes to Active Directory. The vulnerability comprises several issues: untrusted Java deserialization, path traversal, and a blind XML External Entities (XXE) injection. This is a vulnerability that NodeZero, our autonomous pentesting product, has exploited […]
·horizon3.ai·
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
Office Documents: May the XLL technique change the threat Landscape in 2022? - Yoroi
Office Documents: May the XLL technique change the threat Landscape in 2022? - Yoroi
Introduction  Contrasting the malware delivery is hard. Cyber attackers evolve their techniques frequently, but a major trend remained constant: Microsoft Office and Excel documents represent the favorite delivery method many cyber criminals use to inoculate malware into private and public companies. This technique is extremely flexible and both opportunistic and APT actors abuse it.  In the last months, we monitored with particular attention several attack waves adopting a new delivery technique: binary libraries directly loaded by Microsoft Excel, just in one click. This emergent delivery technique leverages XLL files, a particular file type containing a Microsoft Excel application ready to be loaded. […]
·yoroi.company·
Office Documents: May the XLL technique change the threat Landscape in 2022? - Yoroi
CVE-2022-27925 | AttackerKB
CVE-2022-27925 | AttackerKB
On May 10, 2022, Zimbra released versions 9.0.0 patch 24 and 8.8.15 patch 31 to address multiple vulnerabilities in Zimbra Collaboration Suite, including CVE-2…
·attackerkb.com·
CVE-2022-27925 | AttackerKB
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)
– by TheGrandPew and s1r1us We all know, VSCode is one of the most used Electron App. As a part of our research on hacking electron apps, we thought it would be cool to pwn VSCode and we were able to pwn it. We were able to achieve RCE on VSCode without getting to use any of our new fancy stuff. TL; DR Remote Code execution can be achieved when a victim opens a markdown file in a maliciously crafted VSCode Project or a folder even in VSCode Restricted Mode.
·blog.electrovolt.io·
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)
$50 миллионов, помогая компаниям с email-рассылками — маркетолог поделился 4-мя шаблонами писем, которые на 30% увеличивают доход e-commerce сайтов
$50 миллионов, помогая компаниям с email-рассылками — маркетолог поделился 4-мя шаблонами писем, которые на 30% увеличивают доход e-commerce сайтов
Как создать воронку email-писем, которая зацепит вашу аудиторию? Делимся рекомендациями Чейза Даймонда — маркетолога, который заработал более $50 миллионов, помогая крупным компаниям с email-рассылками.
·partnerkin.com·
$50 миллионов, помогая компаниям с email-рассылками — маркетолог поделился 4-мя шаблонами писем, которые на 30% увеличивают доход e-commerce сайтов
RedTeam With OneNote - Sevagas
RedTeam With OneNote - Sevagas
OneNote is one of the Office suite components which is often overlooked when RedTeaming. Though OneNote cannot execute VBA Macros, it has an important potential for phishing as an initial vector.
·blog.sevagas.com·
RedTeam With OneNote - Sevagas