#漏洞 CVE-2021-27076: A REPLAY-STYLE DESERIALIZATION ATTACK AGAINST SHAREPOINT
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
https://www.thezdi.com/blog/2021/3/17/cve-2021-27076-a-replay-style-deserialization-attack-against-sharepoint
Zero Day Initiative
Zero Day Initiative — CVE-2021-27076: A Replay-Style Deserialization Attack Against SharePoint
An attacker is frequently in the position of having to find a technique to evade some data integrity measure implemented by a target. One instructive example of a data integrity measure is a message authentication check. Generally, message authentication…
#bountytip Hunting in the Sysmon Call Trace
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
https://www.lares.com/blog/hunting-in-the-sysmon-call-trace/
Lares
Hunting in the Sysmon Call Trace
Intro The Sysmon ProcessAccess event has been used in threat hunting and detection efforts in order to alert on techniques such as process injection and credential access. According to the…
#漏洞 MyBB Remote Code Execution Chain (CVE-2021-27889, CVE-2021-27890)
https://blog.sonarsource.com/mybb-remote-code-execution-chain
https://blog.sonarsource.com/mybb-remote-code-execution-chain
Sonarsource
MyBB Remote Code Execution Chain
Today SonarSource is pleased to share a guest contribution to our Code Security blog series about learnings from a chain of serious vulnerabilities in MyBB.
#漏洞 RCE Exploit in BIG-IP.
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
CVE-2021-22986, CVE-2021-22987
python f5_rce.py -u https://ip_target
python f5_rce.py -f ip_list.txt
python f5_rce.py -c "$commend"
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP
GitHub
GitHub - h4x0r-dz/RCE-Exploit-in-BIG-IP
Contribute to h4x0r-dz/RCE-Exploit-in-BIG-IP development by creating an account on GitHub.
#工具 Lazyrecon是一个子域发现工具,可发现并解析有效的子域并执行SSRF / LFI / SQLi模糊测试。它具有简单的模块化体系结构,并针对与Wayback机器一起使用时的速度进行了优化。
https://github.com/storenth/lazyrecon/
https://github.com/storenth/lazyrecon/
GitHub
GitHub - storenth/lazyrecon: Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.
Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion. - storenth/lazyrecon