#漏洞 VoIPmonitor advisories: buffer overflow leading to RCE + XSS vulnerabilities
https://www.rtcsec.com/post/2021/03/voipmonitor-advisories-buffer-overflow-leading-to-rce-xss-vulnerabilities/
https://www.rtcsec.com/post/2021/03/voipmonitor-advisories-buffer-overflow-leading-to-rce-xss-vulnerabilities/
#工具 Lending a hand to the community – Covenant v0.7 Updates
https://research.nccgroup.com/2021/03/16/lending-a-hand-to-the-community-covenant-v0-7-updates/
https://research.nccgroup.com/2021/03/16/lending-a-hand-to-the-community-covenant-v0-7-updates/
NCC Group Research Blog
Lending a hand to the community – Covenant v0.7 Updates
Introduction Covenant [1] is an open source .NET command and control framework to support Red Team operations, similar in many ways to the well-known Cobalt Strike threat emulation software. Covena…
#漏洞 BIG-IP/ BIG-IQ iControl REST 未经身份验证的RCE (CVE-2021-22986)
https://attackerkb.com/topics/J6pWeg5saG/k03009991-icontrol-rest-unauthenticated-remote-command-execution-vulnerability-cve-2021-22986
https://attackerkb.com/topics/J6pWeg5saG/k03009991-icontrol-rest-unauthenticated-remote-command-execution-vulnerability-cve-2021-22986
AttackerKB
K03009991: iControl REST unauthenticated remote command execution vulnerability CVE-2021-22986 | AttackerKB
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x …
#bountytip Chrome sandbox escape
https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx
https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx
#漏洞 CVE-2021-27076: A REPLAY-STYLE DESERIALIZATION ATTACK AGAINST SHAREPOINT
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
Zero Day Initiative
Zero Day Initiative — CVE-2021-27076: A Replay-Style Deserialization Attack Against SharePoint
An attacker is frequently in the position of having to find a technique to evade some data integrity measure implemented by a target. One instructive example of a data integrity measure is a message authentication check. Generally, message authentication…
#bountytip Hunting in the Sysmon Call Trace
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
Lares
Hunting in the Sysmon Call Trace
Intro The Sysmon ProcessAccess event has been used in threat hunting and detection efforts in order to alert on techniques such as process injection and credential access. According to the…