Bug exists in admin's panel. It's possible to exploit only when you have admin's credentials. Full details described below...
piątek, 16 września 2016
Tr0ll 1 - CTF
wtorek, 13 września 2016
niedziela, 11 września 2016
6Days Lab CTF
Friend of mine asked me if I know this CTF. I decided to check it during the weekened. Below quick review...
sobota, 10 września 2016
Local resource enumeration via XSS
Probably you all already know how to "Hack Intranet Websites from the Outside" (if not, google for Jeremiah Grossman and RSnake - you can start here - and read about some attacks from 2006 and 2007). ;) There you will find similar usage of JavaScript as you can find below:
DVL Warmup poc
Yesterday I was playing with an old ISO called Dam Vulnerable Linux. If you're learning some binary exploitation, a nice 'warmup exercise' can be found here:
piątek, 9 września 2016
Lord Of The Root - CTF
First of
all: big thanks for the author for preparing this CTF. Man, I had no
idea that Frodo is a hipster! ;D
poniedziałek, 5 września 2016
Bitbot CTF
In the middle of the other activities
and projects, I decide to sit down for a while and check another CTF. This time
I decided to try Bitbot. Found again on VulnHub – thank you guys. Also big
thanks for the author (bwall) for preparing this game! So… Let’s get to work.
poniedziałek, 22 sierpnia 2016
Testing SQL injections in com_virtuemart 3.0.14
Yesterday after I finally finished Jomlash module I decide to check the latest com_virtuemart component. The version I tried was 3.0.14. As far as I know, “the latest” one …
sobota, 20 sierpnia 2016
joomlash - new test in grabash.py
During couple of last few days I had a chance to check grabash
code again. I am aware that this is still not even 'first' final
version ;) so there is always something 'todo' or to fix to get better
results from the scan. So, yeah, any feedback is welcome.
Subskrybuj:
Posty (Atom)