Note on WordPress pre-auth RCE (CVE-2026-63030). There are SQLi poc's out there, but RCE PoC has not yet been exploited in the wild. Will only release our technical post if we have proof of exploitation. Our RCE payload does NOT require poorly configured MySQL.
🧵[1/9] Time to publish the solution to this challenge! https://t.co/rBuH8nEVMX The goal of this challenge was to find an XSS while avoiding it being blocked by the CSP sent by the PHP header() function. Let's dive into it!
I know there are lots of people waiting for the recent Microsoft Exchange pre-auth RCE on our side. This is a short advisory and detailed timeline. https://t.co/lgpW7AVZZJ
#proxylogon
Balsn CTF is back! This year, Balsn CTF 2020 will feature creative and interesting challenges. We cordially invite you to join the party. Don’t forget to mark it on your calendar!
Date: 14 Nov. 2020, 10:00 am (UTC+8) ~ 16 Nov. 2020, 10:00 am (UTC+8)
https://t.co/GFom6kDbuW