zend-framework-XXE-vuln
Part 1 | Stack-based Buffer Overflow exploitation to shell by example ~ des
There are a lot of tutorials out there about exploitation of memory corruption bugs, but I struggled to find step-by-step ones, that would s...
Haifei's random thoughts: "Bypassing" Microsoft's Patch for CVE-2017-0199
Background If you have followed my research on the infamous CVE-2017-0199 zero-day attack, you may know we (w/ my colleague Bing) did a p...
How the Twitter App Bypasses Paywalls | Elaine's Idle Mind
by Isoroku Yamamoto Wall Street Journal ended its practice of allowing special access for search engines. This means that a human visitor can no longer bypass the paywall by spoofing Google’s HTTP …
PowerPoint Presentation
How i Hacked into a PayPal's Server - Unrestricted File Upload to Remote Co
Execute a DLL via .xll files and the Excel.Application object's RegisterXLL
Execute a DLL via .xll files and the Excel.Application object's RegisterXLL() method · GitHub
Analyzing CVE-2017-0190: WMF Flaws Can Lead to Data Theft, Code Execution |
CVE-2017-0190 is a recently patched vulnerability related to Windows metafiles (WMFs), a portable image format mainly used by 16-bit Windows applications. Recently we have seen an increase in the number of vulnerabilities related to WMFs and EMFs (enhanced metafiles) in the GDI32 library. Most often, these
How we invented the Tesla DOM DOOM XSS
Many have seen the video where vexal modifies his Porsche 911 to run DOOM. It is the same guy who used a toaster to control a PC game a few years ago. How technically accurate these videos are can be discussed, but the underlying creativity is hard to question. Naturally, when we saw the video, we did not want to lag behind, but what is the best way to respond to something like this? Inventing the DOM DOOM XSS, of course!
GitHub - denysdovhan/wtfjs: A list of funny and tricky JavaScript examples
wtfjs - A list of funny and tricky JavaScript examples
DEF CON 25 Hacker Conference
Security Blog By @rakeshmane10: Xssing Web Part - 2
Security Blog
Проникновение через субтитры. Полный разбор нашумевших атак на PopcornTime,
В мае этого года исследователи Check Point Software Technologies обнаружили совершенно новый вектор атак — атаки через субтитры. Злоумышленники могут использовать файлы субтитров для получения контроля над компьютерами пользователей, при этом избегая обнаружения. В этой статье мы расскажем, как это у них получилось (обязательно запасись кофе – статья вышла большая :) – прим. ред.)
Make your own USB Rubber Ducky using a normal USB stick |
Modern Alchemy: Turning XSS into RCE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
DEF CON 25 Hacker Conference
Автоматизация рыбной ловли для World of Warcraft / Хабрахабр
Познакомился с World of Warcraft очень давно и люблю его весь, но одна вещь больше всего не давала мне покоя — рыбная ловля. Это нудное повторяющееся действие,...
CVE to PoC - CVE-2017-0059
CVE-2017-0059 Internet Explorer “There is an use-after-free bug in IE which can lead to info leak / memory disclosure. The bug was confirmed on Internet Explorer version 11.0.9600.18537 (update version 11.0.38). [...] The root cause of a bug is actually a use-after-free on the textarea text value,
CVE to Exploit - CVE-2017-[0037 and 0059]
CVE-2017-[0037 and 0059] Internet Explorer 11 Following the last 2 blog posts for both CVE-2017-0037 and CVE-2017-0059 here's a full working exploit for IE11 <= 11.0.37 for Windows 7 (32 and 64 bit). I tested it only on two (not too) different machines so please if you
Sniffly2
A Forgotten HTTP Invisibility Cloak
This presentation illustrates a number of techniques to smuggle and reshape HTTP requests using features such as HTTP Pipelining that are not normally used by …
Mousejacking | To Shell And Back: Adventures In Pentesting
On internal engagements, poisoning name resolution requests on the local network (à la Responder) is one of the tried and true methods of obtaining that coveted set of initial Domain credentials. While this approach has worked on many clients, what if Link Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NTB-NS) protocols are configured securely or disabled? Or, what if Responder was so successful that you now want to prove other means of gaining that initial foothold? There are a multitude of attacks a penetration tester can leverage when conducting physical walkthrough...
DIY Spy Program: Abusing Apple's Call Relay Protocol - Martin Vigo
Finding, exploiting and leveraging vulnerabilities in Apple's Call Relay protocol to build a spy program. CVE: 2016-4635, 2016-4721, 2016-4722, 2016-7577
GitHub - vysec/CVE-2017-8759: CVE-2017-8759 - A vulnerability in the SOAP W
CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
Как работает Android, часть 1
В этой серии статей я расскажу о внутреннем устройстве Android — о процессе загрузки, о содержимом файловой системы, о Binder и Android Runtime, о том, из...
Mac OS X Local Javascript Quarantine Bypass | segment
GitHub - Bo0oM/CVE-2017-7089: Safari 10 exploit (CVE-2017-7089)
Webkit uxss exploit (CVE-2017-7089)
The Absurdly Underestimated Dangers of CSV Injection
Hack Patch!: PWA - Progressive Web Attack
Today, I'm going to blog about PWA (Progressive Web Apps)🙂 These days, web is getting bit secure by the help of CSP, which turns XSS i...
Guest Blog: Don’t Leave your Grid Wide Open
Our guest blogger and Detectify Crowdsource hacker Peter Jaric explains how Selenium Grid could be exploited to read files on the server.
