HT3 was mid jestergooning when a group of Vendors came and spiked our Cortisol levels 😭
Is Ignoring the Vendors while munting and mogging printers more useful then RCE ghidrafishing in the Pwn2Own?
Writeups are literally just hastily written markdown files converted to HTML, so typos and weird grammar might exist.
Most importantly, they have full exploit code.
Confirmed! The folks from @ht3labs used a missing authentication bug combined with an OS command injection to exploit the Phoenix Contact CHARX. Their 2nd round win nets them $25,000 and 5 Master of Pwn points.
In their #Pwn2Own debut, the team from HT3 Labs (@ht3labs) exploited the Phoenix Contact CHARX SEC-3150. They were nice enough to make Zed an honorary member, too. They head off to the disclosure room to explain themselves. #P2OAuto