czwartek, 29 września 2022

Simple SQL fuzzing for Junior Pentesters

Some time ago I was asked to pentest some network and identify possibly vulnerable network services there. One of them was SQL database. More details about it - you'll find below. Here we go...

niedziela, 17 lipca 2022

Crashing GNOME shell again

Last time we talked about a crash in GNOME based on AnyDesk. This time I found a similar bug using LibreOffice for Ubuntu. Below you'll find more details. Here we go...

piątek, 3 czerwca 2022

Night fuzzing session - IdaPro 6.6 - part 2

Last time during one of the "Night Fuzzing Sessions" I found few bugs in IdaPro 6.6. I decided to continue this adventure but with a 'new approach'. So I changed my input files. ;) Below you will find the details about it. Here we go... 

czwartek, 26 maja 2022

Crashing GNOME shell

When I was waiting for the results of "Night Fuzzing Session" I tried to chill a bit searching for some other bugs. That's how I found one of them (CVE-2020-13160) described here and that's how in the end I landed in GNOME. ;) Details about it you will find below. Here we go...

poniedziałek, 25 kwietnia 2022

Night fuzzing session - IdaPro 6.6

According to previous adventures few days ago I decided to continue 'night fuzzing session' and this time I tried to run a quick check for Ida Pro (version 6.6). Below you'll find more details about it. Here we go...

piątek, 15 kwietnia 2022

See you when I see you

Few months ago during some pentest project I found that inside the "Client's Network" we have an access to the IPCam-network. Few more details about it - you'll find below. Here we go...

wtorek, 12 kwietnia 2022

Fuzzing FreeBSD 12.3

After last adventures with JunOS bugs I decided to learn more about FreeBSD - the base (afaik) OS for the "Juniper vSRX" I tested in the lab [1, 2]. I decided to start a quick fuzzing for the binaries inside this OS. Below you'll find few notes about it. Here we go...

sobota, 9 kwietnia 2022

Escape from the Secret Garden

Last time when we talked about Juniper/JunOS we focused mostly[1,2] on XSS bugs. Today we'll talk about postauth CLI access and how to extend it ;). Here we go...