A discovery about CVE-2019-16891 that allows exploiting this vulnerability on Liferay Portal without authentication as everyone knows.
#CVE#bugbounty#RCE#0day
https://t.co/KNNMICKMMY
@sagitz_ Great research!
But regarding the .so file loading via fd in /tmp, doesn’t www-data lack permissions to read arbitrary FDs due to Ingress NGINX restrictions? Wouldn’t this limit exploitation unless additional conditions are met?
I’d love to hear your thoughts on this!
@nirohfeld@sagitz_@ronenshh@hillai@kubernetesio Great research! But regarding the .so file loading via fd in /tmp, doesn’t www-data lack permissions to read arbitrary FDs due to default Ingress NGINX restrictions? Wouldn’t this limit exploitation unless additional conditions are met?
You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.
https://t.co/Ywj2Y7rkIu
A huge thank you to the security community and researchers for helping us strengthen our platform. We'll keep investing in security to ensure a safer, more reliable experience for everyone.
ShopBase 's Vulnerability Disclosure & Reward Program: https://t.co/cAvsgIJSoA
After a period of development, I'm excited share Eagle with you. This tool is designed to simplify your asset & attack surface management and boost your workflow efficiency.
Here's Eagle's major features 🧵👇
Shodan Integration for deeper visibility into exposed hosts. Instantly retrieve critical information about your assets' exposure on the internet, helping you identify and fix potential vulnerabilities before they’re exploited.
🚨 BREAKING: Wiz Research discovers a massive 38TB data leak by Microsoft AI researchers, including 30,000+ internal Teams messages.
Here's what you need to know 🧵