The Viettel Cyber Security (@vcslab) team ends their run with a collision. They use 2 bugs to exploit the TrueNAS Mini X. They still earn $20,000 and 2 Master of Pwn points. #Pwn2Own#P2OIreland
Confirmed! The @vcslab team combined 4 bugs - 2 in the router & 2 in the NAS - to going from the QNAP QHora-322 to the TrueNAS Mini X. Their combination of SQL injections and missing auth/exposed function bugs earn them $50K and 10 Master of Pwn points. #Pwn2Own#P2OIreland
SAML ShowStopper from our researcher @_l0gg. Any software not only Manageengine that uses old version of xmlsec and xalan should take care it seriously. @_l0gg will show a technique by using DocumentHandler to defeat xslt transformer. #CVE-2022-47966 https://t.co/vlbERGVNi4
This was really a cool 2-bug chain which lead to RCE on Microsoft Exchange Server:
- https://t.co/WuEdu9dWVZ
- https://t.co/jsJplHfpaE
We also rced Exchange Online.
Great work from @rskvp93 <3 Follow him for upcoming blogs
#tabshell
It's Black Friday! 🎉
Get FREE recurring API credits if you like + retweet this tweet (must be following @securitytrails).
If we get up to 100 RTs everyone gets 100 recurring monthly API credits. If we get over 100 RTs, everyone gets the # of API credits in the amount of RTs.
Excited to open-source "Route Sixty-Sink" today, a static analysis tool I've been working on to find elusive vulnerabilities in .NET applications.
Blog: https://t.co/vRWRcgQZeh
GitHub Repo: https://t.co/h4zS5volki
As promised,
Here is the detail and a part of PoC about the OAM Pre-Auth RCE (CVE-2021-35587)
It may require more work to get fully functional PoC,
Have fun with it!
cc @peterjson
https://t.co/N7zSCUOvWt
Hacking the Cloud has a pretty big update! We're using a better static site generator that will allow me to spend more time making content. Plus, it looks great!
https://t.co/WWAnsqdb5c
Just published detailed analysis of Microsoft Exchange Deserialization to RCE (CVE-2021-42321), which's also found exploited in Tianfu Cup.
English version from @peterjson
PoC is not provided,
Have fun!
https://t.co/H9Q2Q5Gbpw
Our Pre-Auth RCE exploit for Atlassian Confluence (CVE-2021–26084) was leaked after reporting it to @VMware. They have refused to admit the leak and ignored our emails.
https://t.co/cwainPWv9y
A New Attack Surface on Microsoft Exchange! The series covers most of my Black Hat USA and DEFCON talks (with slides and video inside). More articles and vulnerabilities are coming soon!
https://t.co/lkup5hdyz9
Inspired by @garethheyes' CSP bypass in PayPal, for the first time in 4 years, I found again that JS resources added by CloudFlare could introduce a CSP bypass.
https://t.co/lKccCfTo8a