#bountytip Chrome sandbox escape
https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx
https://securitylab.github.com/research/one_day_short_of_a_fullchain_sbx
#漏洞 CVE-2021-27076: A REPLAY-STYLE DESERIALIZATION ATTACK AGAINST SHAREPOINT
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
Zero Day Initiative
Zero Day Initiative — CVE-2021-27076: A Replay-Style Deserialization Attack Against SharePoint
An attacker is frequently in the position of having to find a technique to evade some data integrity measure implemented by a target. One instructive example of a data integrity measure is a message authentication check. Generally, message authentication…
#bountytip Hunting in the Sysmon Call Trace
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
Lares
Hunting in the Sysmon Call Trace
Intro The Sysmon ProcessAccess event has been used in threat hunting and detection efforts in order to alert on techniques such as process injection and credential access. According to the…
#漏洞 MyBB Remote Code Execution Chain (CVE-2021-27889, CVE-2021-27890)
https://blog.sonarsource.com/mybb-remote-code-execution-chain
https://blog.sonarsource.com/mybb-remote-code-execution-chain
Sonarsource
MyBB Remote Code Execution Chain
Today SonarSource is pleased to share a guest contribution to our Code Security blog series about learnings from a chain of serious vulnerabilities in MyBB.
#漏洞 RCE Exploit in BIG-IP.
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
GitHub
GitHub - h4x0r-dz/RCE-Exploit-in-BIG-IP
Contribute to h4x0r-dz/RCE-Exploit-in-BIG-IP development by creating an account on GitHub.