Android malware (.apk) can be spread through a fake PDF document by manipulating the file extension in the WhatsApp application. I showed how it is done in the video below.
#Microsoft#Exchange#Vulnerabilites
Recently, a presentation by a researcher named Orange Tsai was released at the Blackhat 2021 conference that introduces the vulnerabilities of ProxyLogon, Proxyshell and ProxyOracle
In Figure 3, you can see the process of this Proxying request, which is copied from the Header and Cookies, and in the Proxy Section, the Authenticate and Authotize process takes place.
Since the Exchange server is widely used in government organizations, these vulnerabilities can be significant. It is a service
Figure 1 shows the process of service evolution. In 2016/2019 versions, a module called Client Access Service was added.
#Unauthenticated#Weblogic#RCE
For many years, Weblogic services on different platforms have led to RCE attacks that are the result of various vulnerabilities, so the discovery of vulnerabilities as WhiteBox in these services is very important
the java.beans.XMLDecoder class, and with an html encoding the input command to the exploit. Put it in command_filtered and call the start method as void and RCE happens just as easily,Friends, do not ignore the discussion of Weblogic Pentest,