Is there a good reason not to restrict Host-Headers inside the webapp itself? #Nextcloud for example has a configurable whitelist called "trusted_domains". Or should the config be done by nginx/apache? Is it even a serious security risk if the header is not validated at all?
๐คฏ The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!
I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! ๐ง #infosec #xz
Rebooting doesn't resolve the issue. In linux I'd just check journalctl/dmesg, no idea what to do in windows - would be fun to find a 0day if I had a clue what to do
I got a file which is crashing explorer.exe when triggering the context menu "Open With" or opening the file properties. How would you analyze the issue further?
OOPArtDB from #HackTheBox was recently retired, an insane #WEB challenge by @strellic - learned some amazing attack techniques.
Going to present the exploitation path soon. My slides for the upcoming presentation can now be found online: https://t.co/4kmlDTg0lw
I wrote this to try to bring some reality to people trying to break into cyber. People will disagree with some (all) of it but hopefully somebody benefits from what I saw when I worked as a pentester.
https://t.co/LJaa7aA1Ty