گامهای اولیه در کشف باگ از سورس کد
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
#whitebox
#pentest
@sec_nerd
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
#whitebox
#pentest
@sec_nerd
ماژول متاسپلویت برای آسیب پذیری ssi در sharepoint
CVE-2020-16952
https://github.com/wvu-r7/metasploit-framework/blob/feature/sharepoint/modules/exploits/windows/http/sharepoint_ssi_viewstate.rb
جزییات بیشتر:
https://github.com/rapid7/metasploit-framework/pull/14265
#windows
#sharepoint
#ssi
@sec_nerd
CVE-2020-16952
https://github.com/wvu-r7/metasploit-framework/blob/feature/sharepoint/modules/exploits/windows/http/sharepoint_ssi_viewstate.rb
جزییات بیشتر:
https://github.com/rapid7/metasploit-framework/pull/14265
#windows
#sharepoint
#ssi
@sec_nerd
امنیت اطلاعات
چند اسکریپت اثبات آسیب پذیری کشف شده در yii https://github.com/Maskhe/CVE-2020-15148-bypasses #poi #rce #php @sec_nerd
باگ RCE در Pulse Secure پس از احراز هویت
https://www.gosecure.net/blog/2020/08/26/forget-your-perimeter-rce-in-pulse-connect-secure/
CVE-2020-8218
#rce
#pulse
#network
@sec_nerd
https://www.gosecure.net/blog/2020/08/26/forget-your-perimeter-rce-in-pulse-connect-secure/
CVE-2020-8218
#rce
#pulse
#network
@sec_nerd
توضیحات و اکسپلویت آسیب پذیری اخیر outlook 2019
https://github.com/0neb1n/CVE-2020-16947
#outlook
#windows
#rce
@sec_nerd
https://github.com/0neb1n/CVE-2020-16947
#outlook
#windows
#rce
@sec_nerd
GitHub
GitHub - 0neb1n/CVE-2020-16947: PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility)
PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility) - 0neb1n/CVE-2020-16947
توضیحات کامل یک محقق در خصوص آسیب پذیری استک tcp/ip در ویندوز که با نام bad neighbor (همسایه ی بد) شناخته میشود
cve-2020-16898
https://blog.pi3.com.pl/?p=780
کد اکسپلویت:
https://site.pi3.com.pl/exp/p_CVE-2020-16898.py
#windows
#tcpip
#rce
@sec_nerd
cve-2020-16898
https://blog.pi3.com.pl/?p=780
کد اکسپلویت:
https://site.pi3.com.pl/exp/p_CVE-2020-16898.py
#windows
#tcpip
#rce
@sec_nerd
https://twitter.com/MrDamanSingh/status/1317042176337932291?s=20
https://twitter.com/nullenc0de/status/1317195661377503232?s=20
#ssti
#pentest
@sec_nerd
https://twitter.com/nullenc0de/status/1317195661377503232?s=20
#ssti
#pentest
@sec_nerd
Twitter
Damanpreet Singh🇮🇳
Got RCE in 2 minutes via SSTI, ~waybackurls https://t.co/DC4dDq3TjO | qsreplace "daman{{9*9}}" > fuzz.txt ~ffuf -u FUZZ -w fuzz.txt -replay-proxy https://127.0.0.1:8080/ (captured requests in burp) searched: daman81 in burp, got 43 results from 1266 requests…
باگ RCE در اپلیکیشن discord
masatokinugawa.l0.cm/2020/10/discord-desktop-rce.html (日本語)
https://mksben.l0.cm/2020/10/discord-desktop-rce.html (English)
https://youtube.com/watch?v=0f3RrvC-zGI (DEMO)
#discord
#rce
@sec_nerd
masatokinugawa.l0.cm/2020/10/discord-desktop-rce.html (日本語)
https://mksben.l0.cm/2020/10/discord-desktop-rce.html (English)
https://youtube.com/watch?v=0f3RrvC-zGI (DEMO)
#discord
#rce
@sec_nerd
mksben.l0.cm
Discord Desktop app RCE
A few months ago, I discovered a remote code execution issue in the Discord desktop application and I reported it via their Bug Bounty Prog...
ورد لیست برای بروت فورس xxe
https://gist.github.com/honoki/d7035c3ccca1698ec7b541c77b9410cf
#xxe
#pentest
@sec_nerd
https://gist.github.com/honoki/d7035c3ccca1698ec7b541c77b9410cf
#xxe
#pentest
@sec_nerd
Gist
XXE bruteforce wordlist including local DTD payloads from https://github.com/GoSecure/dtd-finder
XXE bruteforce wordlist including local DTD payloads from https://github.com/GoSecure/dtd-finder - xxe-payloads.txt
رتبه بندی زبانهای برنامه نویسی بر اساس میزان برقی که مصرف میکنند!
https://thenewstack.io/which-programming-languages-use-the-least-electricity/
#programming
@sec_nerd
https://thenewstack.io/which-programming-languages-use-the-least-electricity/
#programming
@sec_nerd