Pokazywanie postów oznaczonych etykietą fuzz. Pokaż wszystkie posty
Pokazywanie postów oznaczonych etykietą fuzz. Pokaż wszystkie posty

wtorek, 24 czerwca 2025

Living Long Doing Pentests

Some time ago, I was searching online for information about vulnerabilities in popular networking devices. One of the links I came across concerned the CVE-2025-0116 vulnerability related to the handling of the LLDP (Link Layer Discovery Protocol) by Palo Alto devices." Intrigued by the description, I decided to check how it looks on my own device in a home lab environment. Below you'll find some details about it. Here w go...

sobota, 14 czerwca 2025

Palo Alto PostAuth CLI memory corruption bug - Metasploit module

Few days ago I posted some notes about the bug found in January in Palo Alto VM. Today you'll find some details about a working poc for Metasploit created for this bug. Here we go...

piątek, 30 maja 2025

WatchGuard 12.11 (Firebox) PostAuth CLI memory corruption bug

In one of the latest pentests projects I had a pleasure to play a bit with latest WatchGuard. Below you'll find some details about it. Here we go...

sobota, 24 maja 2025

Palo Alto PostAuth CLI memory corruption bug

Hi, it's been a while. Long story short: below you'll find few details about the postauth bug I found in Palo Alto CLI. Here we go...

środa, 6 grudnia 2023

The Hack Summit 2023 - Online presentation

This year I had a pleasure to present few of the topics from my research during The Hack Summit Conference in Poland[1, 2, 3]. This time we (mostly;)) talked about one preauth RCE bug I found in ConQuest DICOM server (1.5.0d). Below you'll find more details about it. Here we go...

poniedziałek, 4 grudnia 2023

sobota, 2 grudnia 2023

Monitoring SUFF

Few months ago we talked about Simple Universal Fortigate Fuzzer. Small script created in Python to mutate commands we'd like to send to Forti CLI. Today we'll check how to grab few "log details" for our future analysis. Here we go... 

niedziela, 14 maja 2023

Simple Universal Fortigate Fuzzer

Today we'll finish the topic started few months ago: Simple Universal Fortigate Fuzzer. Below youl'l find the details about it. Here we go...

sobota, 29 kwietnia 2023

sobota, 22 kwietnia 2023

Protocols Mutiny

From time to time I'm posting here some of the bugs I found in the past during my (file format) fuzzing adventures. This time we'll (again) try to focus a bit more on the protocol fuzzing scenarios. To continue - we will use Mutiny Fuzzing Framework. Here we go...

czwartek, 20 kwietnia 2023

Postauth SQL injection in ZoneMinder 1.34.25

Few weeks ago I was looking for some (web) apps related to RTSP. Somehow I landed in TurnKeyLinux page where I found a VM with ZoneMinder (1.34.25).  Below you will find the details about the (postauth SQLi) bug I was able to spot. Here we go...

środa, 19 kwietnia 2023

Fuzzing DICOM - Crashing PaxeraHealth Viewer

After checking few other apps I found for fuzzing DICOM files I tried PaxeraHealth Viewer. Below you will find the details about it. Here we go...

Fuzzing DICOM - Crashing AMIDE

Similar to previous cases related to fuzzing DICOM software I used the same approach and decided to check the application called AMIDE. Few details about it you can find below. Here we go...

Fuzzing DICOM - Crashing MicroDicom

Just like before I found an application that was able to handle my fuzzing scenario so I decided to give it a try. Details from another 'night fuzzing session' you will find below. Here we go...

Fuzzing DICOM - (Local) Crashing Sante PACS Server

Few months ago I decided to fuzz a software related to DICOM file format. Quick local buffer overflow found in one of them - Sante PACS Server - is presented in the details below. Here we go... 

czwartek, 29 września 2022

Simple SQL fuzzing for Junior Pentesters

Some time ago I was asked to pentest some network and identify possibly vulnerable network services there. One of them was SQL database. More details about it - you'll find below. Here we go...

niedziela, 17 lipca 2022

Crashing GNOME shell again

Last time we talked about a crash in GNOME based on AnyDesk. This time I found a similar bug using LibreOffice for Ubuntu. Below you'll find more details. Here we go...

piątek, 3 czerwca 2022

Night fuzzing session - IdaPro 6.6 - part 2

Last time during one of the "Night Fuzzing Sessions" I found few bugs in IdaPro 6.6. I decided to continue this adventure but with a 'new approach'. So I changed my input files. ;) Below you will find the details about it. Here we go... 

czwartek, 26 maja 2022

Crashing GNOME shell

When I was waiting for the results of "Night Fuzzing Session" I tried to chill a bit searching for some other bugs. That's how I found one of them (CVE-2020-13160) described here and that's how in the end I landed in GNOME. ;) Details about it you will find below. Here we go...

poniedziałek, 25 kwietnia 2022

Night fuzzing session - IdaPro 6.6

According to previous adventures few days ago I decided to continue 'night fuzzing session' and this time I tried to run a quick check for Ida Pro (version 6.6). Below you'll find more details about it. Here we go...