@Luke_like@wireditalia Ottimo articolo, per qualche dettaglio un po più tecnico ho pubblicato qualcosa qui: https://t.co/mUmH3jdsWj a fine Maggio.
Spero possa tornare utile più in là
[IT] Dopo 11 mesi dalla nostra prima segnalazione ad Aton Storage (@aton_storage), i dettagli della vulnerabilità dei loro accumulatori smart è stata pubblicata.
https://t.co/gxJabzcfFl
To all (non-public) Tor OnionShare service operators: update to 2.4 to fix CVE-2021-41867 and CVE-2021-41868
Technical writeup: https://t.co/0MZpUgSo9d
@portcullislabs@ciscoctf Of course, the flag format was also part of the plaintext. Great, got it, and finally completed the Preview Level.
Thanks for the fun ;)
@portcullislabs cc: @ciscoctf
Is "Crack me" challenge (#13) really using a weak password that we can find in common dictionaries?
Already tried with crackstation and rockyou.
Also, are the weird usernames in the login attempts important?
Ty
My first OoB Heap Read (leading to DoS) CVE
PoC:
GET /%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%A%00 HTTP/1.1
CVE-2020-26566 A Denial of Service condition in Motion-Project Motion 3.2 through 4.3.1 allows remote unauthenticated users to cause a webu.c segmentation fault and kill the main process via a crafted HTTP request. https://t.co/A44eHv05VA
We just disclosed SIGRed (CVE-2020-1350): Critical Vulnerability in all Windows DNS Servers (by @sagitz_).
Bonus: can also be triggered using the browser through a malicious link. #SIGRed
https://t.co/MMnjPwIUAp