CVE-2019-10392 — Yet Another 2k19 Authenticated Remote Command Execution in Jenkins
read the blog post @ https://t.co/2IT8a7AVod
/cc @jenkinsci@TheHackersNews
Here we go! Chaining a Stored XSS and a SQL Injection to compromise an Uber Wordpress.
Bonus point: I've used a quiz 🙃 (and both are still 0-days)
https://t.co/ty8bQsNZPj #BugBounty#togetherwehitharder#h14420
I want to give another shout-out to @streaak for his amazing work on https://t.co/UPUP51Au5I. This is an excellent reference for anyone that wants to determine the security implications of a publicly-disclosed API key.
A handy and well-polished tool to enumerate permissions associated with AWS credentials you may have stumbled upon in the wild. It looks like it's released as part of a research that will be presented at BH this summer.
https://t.co/a7GXAkCD4p
I'm releasing all the slides (~800!) of my Mobile Security class: https://t.co/TAAnBMCBqB! They are not perfect, but students learned how to reverse apps, find&exploit real-world bugs, reason about threat modelling / system security, etc. Very proud of them :-) 👶 => 👨💻👩💻
Here is the whole exploit chain of Jenkins Unauthenticated RCE(and PoC video https://t.co/4ZW2AIrWGU)!
Hacking Jenkins Part 2 - Abusing Meta Programming for Unauthenticated RCE!
https://t.co/fqk8I7RWuO
Love Impacket? Ever land on a box and wanna run it, but either don't have Python2 installed or don't want to install new dependencies? I wrote a pipeline to statically build all the examples to Windows and Linux x64 binaries. Hope it helps! https://t.co/f4svA6uSlO
Frida Hooking Android
#MobileSecurity#AndroidSecurity@fridadotre by @11x256
Part 1: https://t.co/rsPTuWjIRU
Part 2: https://t.co/ELdhj8KeKF
Part 3: https://t.co/xyXoOgOCF6
Part 4: https://t.co/XuNcnffvRc
Part 5: https://t.co/oujNguHL9j
We've developed a new attack on WPA/WPA2. There's no more complete 4-way handshake recording required. Here's all details and tools you need: https://t.co/3f5eDXJLAe