We are releasing the first wave of vulnerabilities targeting @paxtechnology PAX Android POS terminals.
The list includes pre-auth RCE on the root account by exploiting a hidden bootloader functionality via USB.
You can expect more POS CVEs soon™ :)
https://t.co/7DjDTxZ3EU
Our pentesters Stanisław Koza and Jakub Sajniak (@kubolos231) found another high vuln in the Cisco product. It was marked CVE-2023-20211 and it allows any auth user to extract any info from the Cisco Unified Communications Manager using SQLi. Our PoC: https://t.co/qwCsfv0HGC
Get ready, set, hack! https://t.co/q8OOuOigww just hit the ground! ⏰ Less than 24hrs to uncover flags, conquer snacks & tackle tricky AI challenges 🤖. This year we replaced all boring crypto puzzles with 2 zajebiste tasks.
Third time's a charm! Once again @p4_team and @DragonSectorCTF have joined forces as the Poland Can Into Space team to conquer space 🇵🇱🚀🌌 and this time we did🏆! We won @hack_a_sat, the space security competition! Thanks to🥈SpaceBitsRUs and🥉@solarwine_ctf for a fierce fight!
The best feature of the decompiler is one that spawns random processes and gives you a heart attack.
Check out our story on how to do RCE in JEB decompiler - @jebdec - running on Java 18: https://t.co/SITHd0w0gf
Poniżej zamieszczamy częściowe wyniki konkursu CYBERSEC CTF by HackingDept #CS22_EXPO
Zwycięzcom i wszystkim uczestnikom gratulujemy 💪 Mamy nadzieję, że zobaczymy się na kolejnej edycji.
Na koniec pierwszego dnia konferencji rozstrzygnęliśmy konkurs #cybersecurity CYBERSEC CTF by @hacking_dept.
Gratulujemy wszystkim, którzy podjęli wyzwanie, a szczególnie zwycięzcom #cyber zmagań 💪🏻👏🏻🎊
Nasz CTF startuje za niecałe 30 min, jeżeli chcesz zgarnąć nasze gadżety spróbuj swoich sił na:
https://t.co/kv03GVJkgM
A jeżeli jesteś na @CYBERSECEU#CS22_EXPO wpadnij i się przywitaj :)
Jeżeli jesteś studentem spróbuj swoich sił!
Mija ostatnia szansa aby się zarejestrować i wziąć udział w konkursie i konferencji.
Jeżeli nie możesz przyjechać, a chcesz zmierzyć się z zadaniami, nic straconego, zarejestruj się na wydarzenie online.
Ostatnia szansa, by się zapisać i wziąć udział w konkursie #cybersecurity❗️
15 zadań,
nagrody pieniężne,
okazja do sprawdzenia swoich zdolności z zakresu cyberbezpieczeństwa.
Wydarzenie ma miejsce podczas CYBERSEC Forum/EXPO #CS22_EXPO.
Dołącz do nas❗️
https://t.co/XlfWpbWrsb
Last weekend, p4 representation flew to Saudi Arabia for our first onsite CTF since the COVID-19 breakout. The visit was fruitful - 3rd place and 100k SR (almost 27k USD) reward. Thanks to @athackcon for the invitation, awesome CTF, and your outstanding hospitality.
Our research on @IBM Password Sync Plugin for Windows AD was recognized in their Security Bulletin https://t.co/oRQEP6VPMn
PoCs for our findings:
LDAP Injection/account takeover
https://t.co/8kDOsnhopX
Memory corruption - stack/heap
https://t.co/S9DQHPYxMG
https://t.co/VTo9O8N1wH
Last weekend we had the pleasure 😀 of hosting our friends from @p4_team who participated in the #GoogleCTF challenge⌨🧠. Congratulations on your 8th position in the competition ✊🦾✊. Our new office has survived a trial by fire🥷.
Once again, we have teamed up with @DragonSectorCTF to participate in the @hack_a_sat, a space security CTF contest. This year we continue to prove that Poland Can Into Space and now we won the qualifications 🥇. Wish us luck in the finals! 🇵🇱🚀🌌
https://t.co/2tpygWyyNr
As every year, we organise a #CTF for you to play. This time, @OMHconf is our host and @PolskaHuawei is our sponsor. Everyone will have fun - expect tough challenges for elite hackers, and easier tasks for beginners. Register at https://t.co/OFyIHLdxqt. CTF starts in 9 days!
Our friend from STM Solutions @_mzer0 has released a cool open source tool for searching and pwning Java RMI.
It seems to work really nice :)
https://t.co/5qgaYkUyLH
As we promised we have a surprise for you. We present a tool made by
@_mzer0 RmiTaste allows security professionals to detect, enumerate, interact and attack RMI services by calling remote methods with gadgets from ysoserial, and more... https://t.co/leL4QIKxnD
#RMI#Java
We still don't know how the final scoreboard looks like, but our on-orbit challenge payload/plan was the best and it's going to be executed tonight on a real satellite making a photo of the moon :).
We can now definitely say that #PolandCanIntoSpace 🇵🇱🚀🌌🌙