I just released an Exploit for CVE-2019-15858!
Unauthenticated RCE at Woody Ad Snippets
"WordPress Plugin with 90k Active Installation"
You can find the usage and the demonstration here:
https://t.co/SOGgS6cXsB
#BugBounty#GeneralEG
Este fin de semana estaré en @DragonJARCon mostrando porqué las ventanas en Windows son tan peligrosas como mear contra el viento [con gráficos y colorines].
Yay, I was awarded a $1,200 bounty on @Hacker0x01 for tricky privilege escalation !
“ If API endpoint /api/path/ep throwing 401 try to go with /api/path/ep.json “ and it will fetch out json data without checking access control ! #bugbountytip
Join Sheila A. Berta (@UnaPibaGeek) for #BlackHat Webcast “Backdooring Hardware Devices by Injecting Malicious Payloads on Microcontrollers” on Thursday, August 22 at 11:00 PT. Learn more and sign up for free here: https://t.co/pjmvmppSc1
#redteam quick tip: if you want to execute stuff via WMI (local/remote) without bringing much attention, stage your scripts, payloads etc. in c:\windows\ccmcache\<number>\ folder and you will be fine, below a live legit exec on my laptop (and I see this a lot in # env)
If you want to learn how to pwn browsers like this: we just announced a second advanced browser exploitation training that I will be leading this fall
Come learn a crazy amount about JavaScript internals and exploitation techniques!
https://t.co/OQgfGJV9V6
Im releasing PurpleSpray, an adversary simulation tool that can help defenders build and test the resilience of password spraying detection analytics
https://t.co/kYcAZkTV0u
Registros abiertos para el Latam Tour de OWASP en la Patagonia.
Inscribirse aquí: https://t.co/sDvq5hZoPY
Fecha: 26 de abril - Inicia: 9:00hs
Lugar: Aula Magna - Universidad del Comahue, Neuquén