Hardcoded consumer and secret key in an Android mobile application was fixed by AES/CBC encrypting it. However, the byte array generation function used to construct the decryption secret key was also hardcoded in the same java class 😂 #bugbountystories
Found a pretty neat SSRF on @snapchat and thanks to ideas from @daeken@bbuerhaus, we were able to escalate it a bit. Technical details will be included in our talk @defcon and @BSidesLV (if it gets approved). Enjoy!
Short blog and POC code for CVE-2019-1040 (patched last Tuesday). Combining this vulnerability with the SpoolService bug and Kerberos delegation means: any AD user to Domain Admin; RCE on unpatched hosts; possible over Forest trusts. https://t.co/OFgvn7pOrW TL;DR: GO PATCH!
#tool#ActiveDirectory Added a --privileged-users option to the great tool https://t.co/CuCXmcxukU by @ropnop:
Enumerate All privileged AD Users. Performs recursive lookups for nested members (avoid orphaned admin_count=1).
Tool Release: Sanitizer
A python script that filters, checks the validity, generates clickable link(s) of subdomain(s), and reports their status https://t.co/nwGlYDbka6
Here are our slides for #stratadata on the progress we've made on scalable vulnerability discovery with code property graphs: multi-layered, extensible and with support for multiple programming languages: https://t.co/qbgK5PM28m
Also, Alwin is gonna present "TypeMiner: Recovering Types in Binary Programs using Machine Learning" at @DIMVAConf. A preprint is available here: https://t.co/DaI5fcjkVb … CC: @hgascon@mlsec
Viewing Code as Property Graphs, Querying Property Graphs with Graph Databases. Can code be viewed as data, and if yes, what would it look like? What kind of data structure & database would that fit in? #graphdatabases Meetup in Berlin with @fabsx00
https://t.co/3ZLNzEOtD6