Ok. Here we go again... During last few days after I had a pleasure to received some 'results' from CVE Team (1,2,3). I decided that it should be good ('enough';]) idea to create a small 'poc script' (again) to automate a little bit the process of 'finding bugs' (for example: like those mentioned in CVE's reference(s)). Below you will find few details collected after few days of 'research' and pinging the Vendors...
czwartek, 30 listopada 2017
poniedziałek, 20 listopada 2017
RCE via XSS - Horde 5.2.19
This time I
decided to sit for a while with Horde Groupware (5.2.19). “Ready to go” virtual
machine we can find at Bitnami’s webpage (big thanks!) so using for example
VirtualBox – you can set all things up very quickly. Below you will find few
publicly disclosed bugs found during last few days...
piątek, 17 listopada 2017
Friday surprise from Kali.org
Standard friday evening... checking some twitter and news at net... and then I found...
czwartek, 16 listopada 2017
More SQL Injections in ManageEngine Applications Manager 13
Last time we saw few bugs found in latest ManageEngine Applications Manager 13. Today I decided to publish another 6 (so called ;] '0day') exploits (found between 6-7.11.2017). Details below...
niedziela, 5 listopada 2017
SQL Injection in ManageEngine Applications Manager 13
This morning I decided to start some new "challenge" related to webapp pentesting. That's how I found latest version of ManageEngine Applications Manager.(You can grab a copy here.) Below you will find some 'results'...
niedziela, 29 października 2017
Microsoft Outlook 2016 - RW/RA Crash
środa, 25 października 2017
Night fuzzing session - Kaspersky10 on Windows 10 - part 2
In the middle of time, just like before I was playling a little bit with Kaspersky Endpoint Security 10 for Windows 10. New results from the 'night fuzzing session' you will find below...
Patch your Fortinet - CVE-2017-14182
Few weeks ago during some pentest I found that tested Fortinet-appliance is sometime restarting... I wasn't sure about the reason so I decided to contact directly with the Fortinet's PSIRT. Patch is ready so below you will find few details about it. Enjoy...
poniedziałek, 23 października 2017
ZBX-11023 quick autopsy
When I was reading descriptions of bugs at VulDB I found that there is an SQL injection vulnerability in Zabbix (<2.2.13 and <3.0.4). I decided that it will be a good exercise to write a small proof-of-concept for that bug. Below you'll find results...
Protostart CTF - format0 - walkthrough
Next challenge from Protostar CTF. This time we will check format0. Let's get to work!
Subskrybuj:
Posty (Atom)