⤷ Title: Tryhackme | OWASP Top Ten — 2017 | Day — 8 Insecure Deserialization | walkthrough
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Fri, 16 May 2025 12:06:03 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #tryhackme #tryhackme_walkthrough #owasp_top_10 #tryhackme_writeup
════════════════════════
𐀪 Author: Sudarshan Patel
════════════════════════
ⴵ Time: Fri, 16 May 2025 12:06:03 GMT
════════════════════════
⌗ Tags: #insecure_deserialization #tryhackme #tryhackme_walkthrough #owasp_top_10 #tryhackme_writeup
Medium
Tryhackme | OWASP Top Ten — 2017 | Day — 8 Insecure Deserialization | walkthrough
Hey there, fellow hackers! Ready to dive into Day 8 of TryHackMe’s OWASP Top 10 2017 adventure? Today, our mission is to unravel the…
⤷ Title: TOMCAT RCE(CVE-2025–24813)
════════════════════════
𐀪 Author: Taha Hisoglu
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 00:14:27 GMT
════════════════════════
⌗ Tags: #tomcat #cve_2025_24813 #insecure_deserialization #rce_vulnerability #cybersecurity
════════════════════════
𐀪 Author: Taha Hisoglu
════════════════════════
ⴵ Time: Thu, 12 Jun 2025 00:14:27 GMT
════════════════════════
⌗ Tags: #tomcat #cve_2025_24813 #insecure_deserialization #rce_vulnerability #cybersecurity
Medium
TOMCAT RCE(CVE-2025–24813)
Yakın geçmişteki zafiyetleri incelerken Tomcat’de bulunan CVE-2025–24813 gözüme çarptı ve incelemeye karar verdim. Zafiyet CVSS skoru 9.8…
⤷ Title: Insecure Deserialization in Symfony: A Real Threat
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 08:50:37 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #symfony #insecure_deserialization #cybersecurity
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 08:50:37 GMT
════════════════════════
⌗ Tags: #vulnerability #penetration_testing #symfony #insecure_deserialization #cybersecurity
Medium
Insecure Deserialization in Symfony: A Real Threat
Symfony, a widely adopted PHP framework, offers powerful features and flexibility for web applications. However, like many complex…
⤷ Title: SAP’s July 2025 Patch Day Brings 27 New Notes, Multiple Critical RCE & Deserialization Flaws (CVSS 10.0)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 07:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2025_30009 #CVE_2025_42967 #Enterprise Portal #Insecure Deserialization #Live Auction Cockpit #NetWeaver #rce #Remote Code Execution #S/4HANA #SAP #security patch #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 08 Jul 2025 07:40:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authorization Bypass #CVE_2025_30009 #CVE_2025_42967 #Enterprise Portal #Insecure Deserialization #Live Auction Cockpit #NetWeaver #rce #Remote Code Execution #S/4HANA #SAP #security patch #Vulnerability
Daily CyberSecurity
SAP's July 2025 Patch Day Brings 27 New Notes, Multiple Critical RCE & Deserialization Flaws (CVSS 10.0)
SAP's July 2025 Patch Day fixes 27 vulnerabilities, including critical RCE (CVSS 10.0) in Live Auction Cockpit and multiple insecure deserialization flaws (CVSS 9.1) across NetWeaver components.
⤷ Title: Symantec Endpoint Management Alert: Critical Flaw Allows Unauthenticated RCE, PoC Releases
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 10:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Altiris #cybersecurity #Endpoint Management #Insecure Deserialization #rce #Remote Code Execution #Symantec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 14 Jul 2025 10:58:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #Altiris #cybersecurity #Endpoint Management #Insecure Deserialization #rce #Remote Code Execution #Symantec
Daily CyberSecurity
Symantec Endpoint Management Alert: Critical Flaw Allows Unauthenticated RCE, PoC Releases
A critical RCE flaw (CVE-2025-5333) in Symantec Endpoint Management (Altiris) allows unauthenticated attackers to execute arbitrary code via insecure .NET Remoting deserialization.
⤷ Title: High-Severity Vault Flaw (CVE-2025-13357) Allows Unauthenticated Access via LDAP Null Bind Insecure Default
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:36:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13357 #HashiCorp Vault #Insecure Default #LDAP #Terraform Provider
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 00:36:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2025_13357 #HashiCorp Vault #Insecure Default #LDAP #Terraform Provider
Daily CyberSecurity
High-Severity Vault Flaw (CVE-2025-13357) Allows Unauthenticated Access via LDAP Null Bind Insecure Default
A High-severity flaw (CVE-2025-13357, CVSS 7.4) in the Vault Terraform Provider allows unauthenticated access via LDAP null binds due to an insecure deny_null_bind default setting. Update to v5.5.0.
⤷ Title: Broken Object Level Authorization (BOLA): The API Vulnerability Bankrupting Companies
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 12:01:25 GMT
════════════════════════
⌗ Tags: #api_security #owasp_api_top_10 #insecure_object_reference #api_bola_attack #bola_vulnerability
════════════════════════
𐀪 Author: InstaTunnel
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 12:01:25 GMT
════════════════════════
⌗ Tags: #api_security #owasp_api_top_10 #insecure_object_reference #api_bola_attack #bola_vulnerability
Medium
Broken Object Level Authorization (BOLA): The API Vulnerability Bankrupting Companies 🔓
⤷ Title: Insecure Deserialization — Overview
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
════════════════════════
𐀪 Author: Yassin Khadrawy
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 21:30:10 GMT
════════════════════════
⌗ Tags: #penetration_testing #insecure_deserialization #pentesting #cybersecurity #insecurity
Medium
Insecure Deserialization — Overview
Serialization and deserialization are common operations in modern web applications. But when misused, they open the door to one of the…
⤷ Title: Windows Admin Center Flaw (CVE-2025-64669): How a Simple Folder Permission Opened the Door to SYSTEM Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:31:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_64669 #DLL hijacking #Insecure Permissions #LPE #privilege escalation #TOCTOU #WAC #Windows Admin Center
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 00:31:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_64669 #DLL hijacking #Insecure Permissions #LPE #privilege escalation #TOCTOU #WAC #Windows Admin Center
Daily CyberSecurity
Windows Admin Center Flaw (CVE-2025-64669): How a Simple Folder Permission Opened the Door to SYSTEM Access
A LPE flaw in Windows Admin Center allows any user to gain SYSTEM privileges. It exploits insecure directory permissions and a TOCTOU flaw to execute a DLL hijacking attack.
⤷ Title: AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:01:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #API security #CVE_2025_63387 #DevSecOps #Dify #Information Disclosure #Insecure Permissions #LLM #open_source #Vulnerability
Daily CyberSecurity
AI’s Exposed Side Door: Dify Flaw (CVE-2025-63387) Leaks System Configs to Anonymous Users
A High-severity flaw (CVE-2025-63387) in Dify v1.9.1 allows unauthenticated users to access sensitive system configurations via an unprotected API.
⤷ Title: Tryhackme: React2Shell
════════════════════════
𐀪 Author: sagar ujalambkar
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 06:12:16 GMT
════════════════════════
⌗ Tags: #reactjs #insecure_deserialization #cve_2025_55182 #tryhackme #websecurity_testing
════════════════════════
𐀪 Author: sagar ujalambkar
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 06:12:16 GMT
════════════════════════
⌗ Tags: #reactjs #insecure_deserialization #cve_2025_55182 #tryhackme #websecurity_testing
Medium
Tryhackme: React2Shell
What is React2Shell Vulnerability?
This vulnerability affects React Server Components (RSC) and the frameworks that implement them…
This vulnerability affects React Server Components (RSC) and the frameworks that implement them…
⤷ Title: The Complete Guide to ASP.NET ViewState Exploitation
════════════════════════
𐀪 Author: Dipesh Paul
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 14:45:10 GMT
════════════════════════
⌗ Tags: #rce #insecure_deserialization #cybersecurity #aspnetcore #hacking
════════════════════════
𐀪 Author: Dipesh Paul
════════════════════════
ⴵ Time: Thu, 15 Jan 2026 14:45:10 GMT
════════════════════════
⌗ Tags: #rce #insecure_deserialization #cybersecurity #aspnetcore #hacking
Medium
The Complete Guide to ASP.NET ViewState Exploitation
How I spent hours trying to exploit ViewState deserialization, failed spectacularly, and learned valuable lessons about ASP.NET security in…
⤷ Title: Insecure CaptchaVulnerability Analysis in DVWA (Low to Impossible)
════════════════════════
𐀪 Author: Narathama Firmansyah Putra
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 14:27:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #dvwa #insecure_captcha #cybersecurity #captcha
════════════════════════
𐀪 Author: Narathama Firmansyah Putra
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 14:27:37 GMT
════════════════════════
⌗ Tags: #penetration_testing #dvwa #insecure_captcha #cybersecurity #captcha
Medium
Insecure CaptchaVulnerability Analysis in DVWA (Low to Impossible)
Introduction Insecure Captcha adalah salah satu fitur latihan keamanan di Damn Vulnerable Web Application (DVWA) yang menunjukkan bagaimana…
⤷ Title: HTB: Outbound
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
Medium
HTB: Outbound
| Roundcube | PHP Deserialization | CVE-2025–49113 | 3DES Hash Decryption | Below | Symlink Attack |