Archive

Archive

1481 bookmarks
Custom sorting
Exposed Jenkins to RCE on 8 Adobe Experience Managers
Exposed Jenkins to RCE on 8 Adobe Experience Managers
👋🏼 introduction: This is a short write-up of how I progressed from discovering a Jenkins instance to getting shells on 8 Adobe Experience Manager servers and gaining edit access to a company’s main …
·corben.io·
Exposed Jenkins to RCE on 8 Adobe Experience Managers
Virtual Machine Detection In The Browser
Virtual Machine Detection In The Browser
Virtual Machine (VM) detection is nothing new. Malware has been doing it for over a decade now. Over time the techniques have advanced as defenders learned new ways of avoiding VM detection. A while b…
·bannedit.github.io·
Virtual Machine Detection In The Browser
is private mode js
is private mode js
Detect if the browser is running in Private mode (Promise based) - is-private-mode.js
·gist.github.com·
is private mode js
Chrome 76 Released With Blocked Flash, Incognito Detection Fix
Chrome 76 Released With Blocked Flash, Incognito Detection Fix
Google has released Chrome 76 to the Stable desktop channel, with new features and 43 security fixes, with five of them being marked as High severity.
·bleepingcomputer.com·
Chrome 76 Released With Blocked Flash, Incognito Detection Fix
Glitching a PlayStation Vita hacking
Glitching a PlayStation Vita hacking
A few months ago, a contact reached out to me with an irresistible offer. I would be given the opportunity to experiment with an insanely rare, prototype development kit PlayStation Vita. The only ask…
·yifan.lu·
Glitching a PlayStation Vita hacking
Bo0oM/fuzz.txt
Bo0oM/fuzz.txt
Potentially dangerous files. Contribute to Bo0oM/fuzz.txt development by creating an account on GitHub.
·github.com·
Bo0oM/fuzz.txt
Double-Free RCE in VLC. A honggfuzz how-to
Double-Free RCE in VLC. A honggfuzz how-to
Introduction I spent three months working on VLC using Honggfuzz, tweaking it to suit the target. In the process, I found five vulnerabilities, one of which was
·pentestpartners.com·
Double-Free RCE in VLC. A honggfuzz how-to
DNS rebinding в 2k19, или как по-настоящему вспотеть, посетив порносайт
DNS rebinding в 2k19, или как по-настоящему вспотеть, посетив порносайт
Всем привет! Сегодня мы бы хотели рассказать об одной старой и почти всеми забытой атаке под названием DNS rebinding. Первые разговоры о ней начались еще в 2007...
·habr.com·
DNS rebinding в 2k19, или как по-настоящему вспотеть, посетив порносайт
Сканер портов в личном кабинете Ростелекома
Сканер портов в личном кабинете Ростелекома
Сегодня я совершенно случайно обнаружил, что личный кабинет Ростелекома занимается совершенно вредоносной деятельностью, а именно, сканирует локальные сервисы на...
·habr.com·
Сканер портов в личном кабинете Ростелекома
XSS on Samy.pl (Samy Kamkar)
XSS on Samy.pl (Samy Kamkar)
Security issue that I found on a "https://Samy.pl" which is famous within the information security researchers. Samy Kamkar is an American privacy and security researcher, computer hacker, entrepreneu…
·nirmaldahal.com.np·
XSS on Samy.pl (Samy Kamkar)
Office vulnerabilities from a macro perspective (2010-2018)
Office vulnerabilities from a macro perspective (2010-2018)
本文是对我在Bluehat Shanghai 2019演讲内容的一个拓展性总结。在本文中,我将总结2010年到2018年出现的Office相关0day/1day漏洞。我将对每种类型的漏洞做一次梳理,并对每个漏洞的相关分析文章进行引用和归类。
·anquanke.com·
Office vulnerabilities from a macro perspective (2010-2018)
0x01 Introduction
0x01 Introduction
Take a look into how custom URI schemes can be used to leverage underlying vulnerabilities in applications.
·zeropwn.github.io·
0x01 Introduction
Fuzz in sixty seconds
Fuzz in sixty seconds
Use publicly available tools to quickly start fuzzing browsers.
·bugid.skylined.nl·
Fuzz in sixty seconds