Jackin tor
ImageTragick
Own a printer, own a network with point and print drive-by
Printers present an interesting IoT example because they are far more powerful than other IoT devices, yet are not always considered real computers by most network administrators.
0xbade5dee: New post on triaging the exploitability of IE/EDGE crashes - ht
The Power of Wings | Abusing the Intent URL Scheme Redux
A Link to System Privilege | Keen Security Lab Blog
Essentials of a Successful Pwn of Microsoft Edge
ad-injection-at-scale-assessing-deceptive-advertisement-modifications.pdf
Inside SafetyNet - part 3 · John Kozyrakis ~ blog
This post is part of a series: Inside SafetyNet part 1 (Oct 2015) Inside SafetyNet part 2 (Feb 2016) Inside SafetyNet part 3 (Nov 2016) How to implement Attestation securely using server-side checks (my blog, Cigital blog) SafetyNet Playground (POC server-side implementation) Play Store - Android source - PHP source It’s been more than 8 months since my last blog post on Android’s SafetyNet. In that post I was describing an end-of-2015 version of the system (version code 2495818).
2015_SPSM_NJAS.pdf
How To Build A Password Cracking Rig
Why????? Why build a cracking rig? Because it's fun! This article will explain every step in building what I call a
sophron/wifiphisher: Automated victim-customized phishing attacks against W
wifiphisher - The Rogue Access Point Framework
SOP bypass / UXSS on IE11 htmlFile – Broken Browser
Today we are going to explore a feature that has been present on Internet Explorer almost since its
Simple domain fronting PoC with GAE C2 server - Security Art Work
In this entry we continue with domain fronting; on this occasion we will explore how to implement a simple PoC of a command and control and exfiltration server on Google App Engine (GAE), and we will see how to do the domain fronting from Windows, with a VBS or PowerShell script, to hide interactions with […]
AirBnb Bug Bounty: Turning Self-XSS into Good-XSS #2 | Geekboy | Security R
Latest Posts – Jack Whitton
Bug Bounty & Application Security
Pwnani: Use After Free in Google Hangouts ActiveX
Summary In 2015 I found a use-after free vulnerability in the "Google Talk ActiveX Plugin" that is used by Google Hangouts. The activeX is sitelocked, meaning it can only be invoked from certain whitelisted Google domains. To exploit this, an attacker would need an XSS bug on one of these domains. The bug was reported to Google and has since been fixed. ActiveX Details When installing Google Hangouts on IE, the control "Google Talk ActiveX Plugin" is installed. This control can be invoked from the browser and exports 5 methods. dispinterface GTalkPluginInterface { properties: met...
Loading a DLL from memory » ~magog/public
1040 - macOS: HelpViewer XSS leads to arbitrary file execution and arbitrar
Fortinet Blog
Google patched some Android security vulnerabilities in early August. One of them was a remote code execution vulnerability in Mediaserver (CVE-2016-3820), which was discovered by me. This vulnerab…
tiraniddo: Quick tutorial on how to go from a dead Windows process to EoP.
Posted by James Forshaw, your Friendly Neighbourhood Necromancer. It’s a bit late for Halloween but the ability to resurrect the dead (p...
Windows 10 Sharpens Browser Security With Microsoft Edge
Internet Explorer is possibly the most popular target for vulnerabilities around today. In 2014 alone, a total of 243 memory corruption vulnerabilities in Internet Explorer were disclosed and patched. Every Microsoft Patch Tuesday cycle contains one bulletin that covers multiple IE vulnerabilities – the monthly “Cumulative Security Update for Internet Explorer”, as it is called...
Analysis of MS16-104: .URL files Security Feature Bypass (CVE-2016-3353)
The Chakra Exploit and the Limitations of Modern Mitigation Techniques | En
Last November, Microsoft released a security update for Microsoft Edge which included patches for vulnerabilities CVE-2016-7200 and CVE-2016-7201, which were discovered by Google Project Zero.
How I found a $5,000 Google Maps XSS (by fiddling with Protobuf) – Medium
A few months ago, I used Google Maps. Or maybe Google Street View, I love Street View, it’s like a retrofuturistic way to teleport…
Airbnb – Ruby on Rails String Interpolation led to Remote Code Execution |
Out of Character: Use of Punycode and Homoglyph Attacks to Obfuscate URLs f
Places of Interest in Stealing NetNTLM Hashes | ?Blog of Osanda
One day me and @m3g9tr0n was discussing different places where we can use responder in stealing NetNTLM hashes. After experimenting I thought of writing this post along with some cool findings in t…
T nesb cv x
Disarming EMET 5.52: Controlling it all with a single write action | blog.r
The Enhanced Mitigation Experience Toolkit (EMET) is a software solution from Microsoft that aims at preventing the exploitation of – legacy – software. It is designed to “help prevent …
1121 - WebKit: UXSS via a synchronous page load - project-zero - Monorail
