After a bit of research it came out that it's possible to leverage Teams functionalities for a better phishing scenario. The idea is using it as an alternative way of initial access. Hope it can help some red team guys out there!
https://t.co/PrUQwDNHsW
Here is my RCE exploit code and writeup for (CVE-2021-21974) VMware ESXi OpenSLP heap-overflow discovered by @_wmliang_. Thank you again for your write-up.
[PoC] https://t.co/MCf3TV6IjH
[writeup] https://t.co/LoKlsYVyAJ
I developed a Remote Code Execution PoC exploit for the Exim Use-After-Free that was recently disclosed (as part of @qualys 21Nails advisory). Tested just on Exim 4.92. PoC available: https://t.co/Su55rIZpgj
Just published a remote shellcode loader I've been working on to show why we shouldn't rely solely on real-time injection alerting. Writeup in a few days :)
My C sucks so it's a "PoC".
https://t.co/JVr4aRNhtz
After several weeks of work, it's finally there!🔥
Introducing PPLdump, a tool for dumping PPL processes with a Userland exploit!😈
👉Post 1: https://t.co/r51JDfwtAw
👉Post 2: https://t.co/FUCjMVnPW6
👉Tool: https://t.co/5TJsxKxMMT
Credit goes to @tiraniddo for the technique.
Hey all! first blog post. Are the popular fuzzers just for binary exploitation? In this blog post I outline how you can find logic issues in web-related regular expressions using differential fuzzing. (spoiler: 29 lines of python using Google Atheris)
https://t.co/f4QBztaro0
High-level approaches for finding vulnerabilities < a very well written vulnerability research primer written by @jackson_t in 2017 (but still 100% relevant today)
https://t.co/dVH9bP3IRq
My first ever blog post: Anatomy of an Exploit: RCE CVE-2020-1350 #SIGRed. RCE PoC included, for research purposes. This was my first userland Windows heap exploit and I hope a deep dive into the process will help others. Patch or apply the workaround. https://t.co/CFRTs7Wdvs
A short post to address an exploit chain I did in last year. Both slides and YouTube video are online now - A Journey Combining Web Hacking and Binary Exploitation in Real World! https://t.co/zuM3y93wQC