Do It by Code
54 subscribers
713 photos
99 videos
15 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
MP3 to EXE (1999) (yeah, it's funny at 2024😂)
Article, Comments

The idea is to enable songs to be distributed with no concern whether the recipient will have an MP3 player installed (which was a valid concern in the late nineties. Certainly not a concern anymore for any modern operating system).
LLM pollution destroying the internet.
Try googling this:

yahoo_site_admin/credentials/db.conf
Do It by Code
Photo
All of them have some common patterns in them:

1. the web server is LiteSpeed (LSWS) (It is the 4th most popular web server, estimated to be used by 13.9% of websites as of September 2024)
2. the Content-Type header is text/x-config; which means the web server has recognized the type and is serving the correct type.
3. they are fucking indexable by Google (!)
4. all of them have "Directory Listing" mode enabled (hence why point3 happens), which is Directory Listing Vulnerability (CWE-548)
Do It by Code
All of them have some common patterns in them: 1. the web server is LiteSpeed (LSWS) (It is the 4th most popular web server, estimated to be used by 13.9% of websites as of September 2024) 2. the Content-Type header is text/x-config; which means the web server…
DO NOT FORGET PEOPLE:

1. DISABLE your webserver's Directory Listing feature (at the very least on prod)
2. DISABLE your swagger/openapi route (at the very least on prod); usually at /docs or /swagger (if it's generated automatically, like FastAPI framework does it).
3. RESTRICT access to *.config, *.conf, *.db, *.cfg, etc etc... if you are using an unknown or outdated webserver.

current versions of these webservers are known to be safe for "path traversal vulnerability" by default:
1. nginx
2. IIS
3. Apache

but make sure they are not misconfigured, otherwise (same as the examples above), they might leak sensitive information (resulting in a information disclosure vulnerability).

Helpful links and similar vulnerabilities:
1. CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
2. CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
3. CWE-23: Relative Path Traversal
4. CWE-24: Path Traversal: '../filedir' and CWE-25
5. CWE-34: Path Traversal: '....//' and CWE-35

6. And then there is CWE-36: Absolute Path Traversal which can sometimes literally cause a RCE vulnerability; such as CWE-40: Path Traversal: '\\UNC\share\name\' (Windows UNC Share)

All of these are decades old and no one believes there are still systems which are vulnerable to this; yet just a google search proves that they still do exist 🤦‍♂️
Do It by Code
Escaping the Chrome Sandbox Through DevTools (to run arbitrary code on client's device)
The person discovering and reporting this security bug to Google, received $20,000 as rewards
Today following the disclosure of a Call of Duty Ricochet vulnerability which allows the arbitrary banning of users, another researcher operating under the moniker "Timoxa5651" disclosed a method to arbitrarily banning users under the BattleEye anticheat

https://www.unknowncheats.me/forum/anti-cheat-bypass/667333-bannleeye-banning-arbitrary-players-using.html#post4228108

tldr: change the game name and ID on some battleye game server that's available (e.g. dayz), connect to it from the client, get detected, and the ban arrives on the account that you faked