@AmitaiCo@depthfirstlabs We did not request CVE identifiers. We reported the GitLab vulnerability to GitLab through its HackerOne vulnerability disclosure program. No separate CVE identifier was assigned to us for the GitLab-level exploit chain during that process.😂
We successfully achieved an RCE on GitLab in its default configuration.
Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab.
The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server.
@depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us!
Read more about this in the comment...
@lyq_sqsp@depthfirstlabs Thanks! You can give the LLM plenty of context and ask it to generate an SVG, which you can then convert into an “informative picture”.
Congrats to the 7 companies that will receive $1 million each to develop AI-enabled cyber reasoning systems that automatically find and fix software vulnerabilities as part of the #AIxCC Small Business Track! Full announcement: https://t.co/SC6yEFsooy.
My solution for `true_web_assembly` in the @hxpctf . 1. Upload an evil python file named `https://t.co/FsgTBXlu5b` to the bbs. 2. Make the bot visit the attachment link. 3. RCE triggered in the bot's docker container due to the automatic file download(`import re` in admin . py)
Cautious: A New Exploitation Method! No Pipe but as Nasty as Dirty Pipe | At this #BHUSA briefing, presenters will review a novel exploitation method pushing the dirty pipe to the next level. Learn more>> https://t.co/WyuoCYvq5w
@zwad3@RealWorldCTF I'm very sorry for the bad coding ...... I completed this challenge in a very short time, but only did a simple check. Thanks for exploring this solution! 👍