rpc2socks is a client-server solution developed by LEXFO that allows to drop and remotely run a custom RPC + SOCKS-through-SMB server application on a #Windows target, from a Unix or Windows host. The tool is open source and available here : https://t.co/ZiL8b4fK7k
That’s all pentester /redteamer have to do before exploiting any vulnerability , know impact on the system ! Thanks @_dirkjan to clarify this point, its really didactic
New advisory is now out!
Find out how an independent Security Researcher, Charles Fol (@cfreal_) used a UAF vulnerability in PHP to allow attackers that are able to run PHP code to escape disable_functions restrictions.
https://t.co/Lrd5Z38IJC
We are proud to announce that @cfreal_, from @lexfo's pentest team, will present "finding vBulletin 0-days through poor man's symbolic execution" at @sstic 2020. More information about the talk here: https://t.co/7CpOE3hV8E
A penetration tester from Lexfo found and exploited a subtle bug during an assessment on a French Banking FTP service. Here is the story of this 0-day vulnerability research : https://t.co/hfJUChZNjb
#binaryexploitation#0day
The Lazarus Constellation, a study on North-Korean malware
In this Whitepaper, Lexfo analyses Lazarus Malware, from their Motives, to their detection and mitigation, through their techniques, tactics, procedures : https://t.co/jzja2qmAtr
#threatintelligence#malware#Lazarus
We are proud to announce @LexfoSecurite as our sponsor – thank you for helping us! You will be able to meet them at the #conferences and the trainings – don't miss them! #thc20#infosec
You can purchase your tickets here 👇
https://t.co/R5O8Y5TwrQ
SSRF? in a pdf? Oh yeah!
My boy @NahamSec accidentally found a pretty sick bug and breaks down his and @daeken bug that landed then a @defcon talk last year in this video, if you’re into breaking pdf renders this ones for you!
https://t.co/K5hfwb4lvS
#bugbounty#Pentesting