When I was waiting for the results of "Night Fuzzing Session" I tried to chill a bit searching for some other bugs. That's how I found one of them (CVE-2020-13160) described here and that's how in the end I landed in GNOME. ;) Details about it you will find below. Here we go...
czwartek, 26 maja 2022
poniedziałek, 25 kwietnia 2022
Night fuzzing session - IdaPro 6.6
According to previous adventures few days ago I decided to continue 'night fuzzing session' and this time I tried to run a quick check for Ida Pro (version 6.6). Below you'll find more details about it. Here we go...
piątek, 15 kwietnia 2022
See you when I see you
Few months ago during some pentest project I found that inside the "Client's Network" we have an access to the IPCam-network. Few more details about it - you'll find below. Here we go...
wtorek, 12 kwietnia 2022
Fuzzing FreeBSD 12.3
sobota, 9 kwietnia 2022
Escape from the Secret Garden
środa, 6 kwietnia 2022
Pentesting Pentesters with MSF Jump Host
Let's think about the scenario for a pentest/redteam project during which we are using 'our dedicated jump host'. "What if" someone will takeover this host? This time we'll try to check the potential results of this kind of attack. Here we go...
poniedziałek, 4 kwietnia 2022
Ansible - Quick Shot
I decided to create this small document to collect few basic ideas about Ansible and how it can be used during a ‘day-to-day’ scenarios for pentest and red team projects. If you’re already familiar with Ansible – this document more likely will be a small ‘cheat sheet’ if you’d like to use Ansible to perform some actions during the projects. Anyhow… Enjoy and have fun! ;) Here we go...
piątek, 1 kwietnia 2022
Postauth XSS bugs in Juniper 12.x
Last time we talked about XSS bugs in Junos Space 21.x. This time we'll talk a bit about few XSS bugs I found in Juniper 12.x. Here we go...
czwartek, 24 marca 2022
Another one SAST to bytes
During one of the last evenings I decided to read and learn more about static source code review. In the past I had a pleasure to create (more or less) 'automated' tools to do it. This time I decided to not to start "from the beginning" but instead of: to learn more about SAST and SonarQube scanning scenarios. Here we go...
niedziela, 20 lutego 2022
Space for XSS in Junos
"Space: the final frontier." Well... I'm not sure if it's even a half (of the journey) with Junos - but - let's find some "Space" to inject additional (JS/HTML) code. Get some "Space" and here we go...