Last time I described few XSS bugs for latest Nagios (5.6.9). During the research and code review I found a possibility for RCE. Below you will find the details from the journey. Here we go...
wtorek, 31 grudnia 2019
poniedziałek, 30 grudnia 2019
Multiple XSS bugs in Nagios 5.6.9
This time I decided to check latest version of Nagios (5.6.9). Below you'll find few details from few hours of testing. Here we go...
sobota, 28 grudnia 2019
Testing SSRF in LiquiFireOS
During one bugbounty I found that the target webapp is presenting some 'interesting errors' in responses. ;) As this is always a nice and cool 'hint' to see during pentests/ctfs I decided to dig a little bit more. Below you will find the details for SSRF found in LiquiFireOS. Here we go...
piątek, 27 grudnia 2019
Testing Android apps - mini lab
Last time when we talked about Android apps on the blog we tried to play "Assasin's Creed". Today I decided to build a small lab to prepare it for future projects. Below you'll find few notes about it. Here we go...
piątek, 29 listopada 2019
From 0 to 0day - quick fuzzing lesson
In most time the question(s) you're asking me via blog or twitter is: "how to prepare a fuzzing lab" or "how to perform an analysis of the crash we found". I decided to spent last few days for preparing a small example for you to give you the answer(s) for both of the questions. Below you will find the details. Here we go...
czwartek, 28 listopada 2019
XSS in Oracle EPMS
I was asked to help during the webapp pentest of Oracle EMPS. I decided to share one found XSS bug with you. Below you will find the details. Here we go...
wtorek, 19 listopada 2019
Reading spam for a breakfast
Today I woke up at 5:00 AM and I decided that this is a great moment to read some SPAM. ;) Coffee is ready so here we go...
sobota, 16 listopada 2019
Quick memory review - extracting secrets from Hikivision iVMS-4200
Last time I tried to use Sysinternals to check few things in Windows 10. This time I tried to get some more details (read: passwords;)) to use it during lateral movement (if needed). Below you will find the details of this scenario. Here we go...
sobota, 9 listopada 2019
Sysinternals Suite - quick review for Windows 10
Sometimes during the project at the Client's office you can see that environment there is mostly hardened well (so for example we can not install new soft, we can not open new ports or add users and we can not connect our laptop to the network, etc). In that scenario I decided to check some tools from Sysinternals Suite. Below you'll find few notes. Here we go...
czwartek, 7 listopada 2019
Crashing EximiousSoft Logo Designer
Last time I tried to crash HoneyView and Better JPEG. This time I decided to check Logo Designer 3.82. Below you will find the details. Here we go...
wtorek, 5 listopada 2019
Fool-AV-riend - Windows 10
Few days ago I was reading one of the tutorials related to 'pentesting AD'. They are all pretty cool. You can learn a lot from the content presented by the authors. But my question is...
Crashing HoneyView 5.31
During last week I was looking for some new soft to fuzz. This time I tried Honeyview (v. 5.31). Below you will find the details. Here we go...
Crashing Better JPEG
Last week I tried to fuzz few 'new' soft I found somewhere online. Below you will find the details about one image viewer called Better JPEG (v.3.0.3.0). Here we go...
sobota, 26 października 2019
Responding to Windows 10
I decided to prepare a small Windows-based VM to check few cases related to 'workstation security'. Below you will find the details about Windows 10 I used against Kali Linux. Here we go...
wtorek, 22 października 2019
Random bytes in VLC 3.0.8
Last time we had some fun with previous versions of VLC. This time I decided to run VLC 3.0.8 on Windows 7 (32bit) and prepare a fuzzer to help. Below you will find some results. Here we go...
poniedziałek, 14 października 2019
PicoCTF 2014 - both overflow challenges
In this post I decided to describe a quick way to exploit both overflow challenges from PicoCTF 2014. Below you will find the details. Here we go...
PicoCTF 2014 - execute
This time I tried to execute (a challenge from PicoCTF 2014). Below you will find quick details. Here we go...
PicoCTF 2014 - format
Last time I tried best shell from PicoCTF 2014. Today I tried to solve the format challenge. Below you will find the details. Here we go...
Protostar CTF - format2
In the meantime I decided to try next format-challenge from Protostar CTF - format2. Below you will find the details. Here we go...
środa, 9 października 2019
PicoCTF 2014 - best shell
Last time I tried to solve few challenges from Pico CTF 2013. This time I decided to check few cases from next edition - 2014. Below we will try to solve "best shell" . Here we go...
niedziela, 6 października 2019
Testing DVNA
I was looking for example vulnerable webapps based on NodeJS and that's how I found Damn Vulnerable NodeJS Application. I decided to check it. Below you will find the details. Here we go...
środa, 25 września 2019
Crashing WebAccess/HMI Designer 2.1.9.31
During last week one of the cases was to run fuzzer with some new software to find some new bugs. This time I decided to check WebAccess/HMI Designer (version 2.1.9.31). Below you will find the details...
piątek, 13 września 2019
Crashing FortiGate VM 6.2.1 - httpd
After (some about) 6-8 months today I finally found a moment to go back to the idea I discussed with a friend ('Ścisła Dieta Homarowa' aka. 'Tylko homary Team' ;)) and "check those VM image(s) for (few) popular 'network appliances'". That's how I tried to play with my good old friend - Fortinet. :) Here we go...
poniedziałek, 9 września 2019
Crashing DCISoft - 1.21
Last time I tried to run a quick fuzz against DCISoft. This time I'll try to achieve similar results for latest version - 1.21. Here we go...
Crashing Omegon Fluid Technology 2
This time I decided to check the software called "Omegon Fluid Technology". Below you will find few quick results...
niedziela, 1 września 2019
PicoCTF 2013 - rop3
This time I tried to solve rop3 challenge from PicoCTF 2013. Below you will find the details...
sobota, 24 sierpnia 2019
ECTF 2014 - the-beginner challenge
After a while I decided to check challenge from ETF 2014 called the-beginner. Below you will find the details. Here we go...
środa, 21 sierpnia 2019
ret2libc1 challenge
This time we will check ret2libc1 challenge. "Practice, practice, practice..." Here we go...
ret2shellcode challenge
I like this kind of challenges so I decided to do another one - ret2shellcode. Here we go...
stackoverflow-intro challenge
This time I decided to check one simple challenge found somewhere between other challenges found at github. We will check stackoverflow-intro (pretty similar to few cases from Protostar CTF). Here we go...
wtorek, 20 sierpnia 2019
blind_fmt_stack challenge
Below we'll check another challenge from CTF games I found somewhere on the github. This time we will try to solve blind_fmt_stack challenge. Here we go...
PicoCTF 2013 - rop2
This time I decided to check next challenge from Pico CTF (2013) called rop2. Below you will find the details...
Bulldog2 CTF
This time I decided to check Bulldog:2 CTF from VulnHub prepared by Nick Frichette. Below you will find the details. Here we go...
PicoCTF 2013 - rop1
Next level from PicoCTF 2013 I tried was related to ROP exploitation. Let's see the details...
poniedziałek, 19 sierpnia 2019
PicoCTF 2013 - overflow5
This time I tried overflow5 from Pico CTF 2013. Below you will find the details...
Creating evil module for Wordpress
Last time when I created 'evil module' we talked about web based on Drupal. Today we will try to achieve similar results for Wordpress. Here we go...
PicoCTF 2013 - overflow3
Let's move directly to part3 of the "overflow's challenges" from Pico 2013 - overflo3. Here we go...
PicoCTF 2013 - overflow2
Last time we tried to exploit overflow1. Today we will check next challenge - overflow2. Here we go...
PicoCTF 2013 - overflow1
First overflow1 challenge from PicoCTF 2013. Old but (still) good for a practice. ;) Let's do it...
Escalate_Linux:1 CTF
This time I decided to check one the latest VM available at VulnHub called Escalate_Linux:1 (by Manish Gupta). Let's go...
środa, 7 sierpnia 2019
Protostar CTF - format0
Today we will start format string part of the Protostar CTF. Below very first part - format0. Here we go...
Protostar CTF - stack7
Today we will try to solve the last part of the Protostar CTF related to stack overflows - stack7.
Here we go...
Here we go...
środa, 31 lipca 2019
wtorek, 23 lipca 2019
Protostar CTF - Stack5
Today we will try to solve next part of the Protostar CTF - stack5. Below you will find the details. Here we go...
niedziela, 21 lipca 2019
Protostar CTF - Stack4
Now[0, 1, 2, 3] we are finaly here :) and we want to solve the Stack4 challenge.
Let’s do it! Now...
sobota, 20 lipca 2019
Protostar CTF - Stack2
I think it is a good time to start stack2 challenge from Protostar CTF. Below you will find the details. Here we go...
Protostar CTF - Stack1
Just like last time we will start directly from the new challenge - this time we will check stack1. Here we go...
piątek, 19 lipca 2019
Protostar CTF - Stack0
I decided to check one old CTF called Protostar (again;)). This time we will try to solve some 'stack challenges'. Let's start from the beginning...
czwartek, 18 lipca 2019
XSS in Zurmo CRM
XSS in TestLink 1.9.19
Last time we talked about automating Burp scans to find few more low-hanging fruits during bug hunting. Today we will try to achieve similar results - this time for latest TestLink (1.9.19 available at Bitnami). Here we go...
XSS in DokuWiki
środa, 19 czerwca 2019
Basic protocol fuzzing
Below you will find few notes related to basic protocol fuzzing. Here we go...
poniedziałek, 17 czerwca 2019
Unquoted path for CA Deploy Agents
niedziela, 9 czerwca 2019
Few more quick tests
piątek, 31 maja 2019
Lazy Enlil
sobota, 18 maja 2019
Reading Kibana
In the meantime I decided to check one of the webapp we can find during internal infrastructure pentests - Kibana. Below you will find the details.
czwartek, 9 maja 2019
Crashing DeviceNet Builder
Below you will find few details from just another fuzzing session - this time I tried DeviceNet Builder (2.04) from DeltaElectronics. Here we go...
Unquoted path in ActiveFax Server 6.70
Found last week during some 'Windows 7 exercises'... Few details you'll find below...
Unquoted path in Softros LAN Messenger
Found last week during some 'Windows 10 exercises'... Few details you'll find below...
Crashing Edraw Max
Below you will find few details from just another fuzzing session - this time I tried Edraw Max (7.9.3). Here we go...
piątek, 29 marca 2019
Born2Root 2 CTF
czwartek, 28 marca 2019
FourAndSix:2 CTF
Last time when I tried CTF from series prepared by Fred Wemeijer it was "4n6 - part 1". This time we will check 2nd VM - FourAndSix:2. Here we go...
FourAndSix:1 CTF
This time I tried 1st VM from the series called FourAndSix by Fred Wemeijer. Below you will find the details...
poniedziałek, 25 marca 2019
Stack Overflows for Beginners - CTF - part 1
When I was searching for some 'new VM' at VulnHub I saw that there is a "Stack Overflows for Beginners: 1" CTF. I decided to try it...
RootThis CTF
Next CTF I tried was RootThis CTF from VulnHub prepared by Fred Wemeijer. Below you will find few details from the journey...
Creating evil module for Drupal
sobota, 23 marca 2019
LazySysAdmin CTF
This time I tried to solve CTF called LazySysAdmin prepared by @TogieMcdogie. You can find it here thanks to VulnHub. Here we go...
czwartek, 21 marca 2019
Crashing XnView 2.48
wtorek, 19 marca 2019
DLL Injection - part 2
Last time when DLL injection was mentioned on the blog was related to exploiting 7zip by replacing DLL files. This time we will try something else...
środa, 13 marca 2019
DC-1:1 CTF
wtorek, 12 marca 2019
Temple Of Doom1 CTF
This time I tried "Temple Of Doom CTF" from Vulnhub. Below you will find few details...
niedziela, 10 marca 2019
MinU:1 CTF
This time I tried MinU:1 CTF from VulnHub resources, prepared by 8bitsec. Below you will find the details...
piątek, 8 marca 2019
Fowsniff CTF
czwartek, 7 marca 2019
niedziela, 3 marca 2019
SolidState CTF
This time I decided to check SolidState CTF prepared by ch33z_plz. Below you will find the details...
niedziela, 24 lutego 2019
sobota, 23 lutego 2019
Reading ActiveMQ
Last time (I tried to scan some ports and) I followed the Rabbit. This time we will try to be the last in the line... to get some info from ActiveMQ server. Here we go...
niedziela, 17 lutego 2019
Go! RabbitMQ, go!
After a while I decided to check few other machines available on Bitnami (and/or TurnKeyLinux). This time - just like before - I used Ubuntu 18 server to re-create environment and install 'application' from the scratch. Today we will try RabbitMQ.
Sleepy - CTF
I woke up again at 3 AM so it was... a good time to finish one of the CTF(s) I started few weeks ago - this one is called Sleepy ;) . Machine you can find online thanks to VulnHub Team. Below few details from the journey...
sobota, 9 lutego 2019
RCE in Enterprise VA MAX
Just like few times before I was looking for some new VM appliance to check. This time I found "Enterprise VA MAX" prepared by loadbalancer.org. Below you will find few details about the bug I found in version v8.3.4 (afaik 'latest' one). Here we go...
czwartek, 31 stycznia 2019
RCE in ZenLoad Balancer
Last time we had a pleasure to check some RCE(s) in Artica. This time I decided to try ZenLoad Balancer. Below you will find few details...
wtorek, 29 stycznia 2019
RCE in Artica
Last time somewhere online I found Kaspersky Proxy Server ISO. It was a little surprise for me when I saw that this 'appliance' is based on Artica Proxy. Below you will find few details from the journey...
poniedziałek, 28 stycznia 2019
Reading TrendMicro - OfficeScan
When I was googling for some 'new software' (to check it during my simple fuzzing) I found an old installer of TrendMicro OfficeScan. It occurred that we can 'crash the agent app'... Below you will find few more details...
środa, 16 stycznia 2019
Exploiting BlazeDVD
I wasn't very satisfied after my last case so I decided to check another software. This time I tried to exploit BlazeDVD. Below you will find few details about it. Here we go...
wtorek, 15 stycznia 2019
Exploiting VUPlayer
sobota, 12 stycznia 2019
Crashing Zelio Soft 2
Yesterday I found the software called Zelio Soft 2. I decided to fuzz it a little bit. Below you will find few results from the night (24h fuzzing with 1 sample). Here we go...
środa, 9 stycznia 2019
Jarbas CTF
Below you will find few details about "Jarbas" - CTF prepared by Tiago Tavares. Thanks to the VulnHub - VM is waiting for you here. Let's go...
DerpNStink CTF
Today we will try CTF prepared by Bryan Smith called DerpNStink: 1. You can find it available here. Let's try it...
wtorek, 8 stycznia 2019
poniedziałek, 7 stycznia 2019
Subskrybuj:
Posty (Atom)