#漏洞 [CVE-2021-21123] Google Chrome Bug Bounty $5.000 File System Access API - vulnerabilities
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
GitHub
GitHub - Puliczek/CVE-2021-21123-PoC-Google-Chrome: 🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by…
🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123 and 5 more... - Puliczek/CVE-2021-21123-PoC-Google-Ch...
#漏洞 MobileIron MDM Contains Static Key Allowing Account Enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
https://www.optiv.com/explore-optiv-insights/source-zero/mobileiron-mdm-contains-static-key-allowing-account-enumeration
Optiv
MobileIron MDM Contains Static Key Allowing Account Enumeration
MobileIron MDM exposes account enumeration and SFA to unauthenticated attacks. This analysis details how to mitigate this vulnerability.
#漏洞 CVE-2021-1732: win32kfull xxxCreateWindowEx callback out-of-bounds
https://iamelli0t.github.io/2021/03/25/CVE-2021-1732.html
https://iamelli0t.github.io/2021/03/25/CVE-2021-1732.html
iamelli0t’s blog
CVE-2021-1732: win32kfull xxxCreateWindowEx callback out-of-bounds
CVE-2021-1732 is a 0-Day vulnerability exploited by the BITTER APT organization in one operation which was disclosed in February this year[1][2][3]. This vulnerability exploits a user mode callback opportunity in win32kfull module to break the normal execution…
Hidden OAuth attack vectors
https://portswigger.net/research/hidden-oauth-attack-vectors
https://portswigger.net/research/hidden-oauth-attack-vectors
PortSwigger Research
Hidden OAuth attack vectors
Intro The OAuth2 authorization protocol has been under fire for the past ten years. You've probably already heard about plenty of "return_uri" tricks, token leakages, CSRF-style attacks on clients, an
#工具 OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
从Github或Gitlab配置文件中获取信息,并查找提交时泄露的用户电子邮件地址。
https://github.com/GONZOsint/gitrecon
GitHub
GitHub - GONZOsint/gitrecon: OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked…
OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits. - GONZOsint/gitrecon
#漏洞 Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
https://github.com/xiaopan233/Mybb-XSS_SQL_RCE-POC
GitHub
GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc - GitHub - xiaopan233/Mybb-XSS_SQL_RCE-POC: Mybb associate CVE-2021-27890 & CVE-2021-27889 to RCE poc
#漏洞 Two Vulnerabilities Patched in Facebook for WordPress Plugin
https://www.wordfence.com/blog/2021/03/two-vulnerabilities-patched-in-facebook-for-wordpress-plugin/
https://www.wordfence.com/blog/2021/03/two-vulnerabilities-patched-in-facebook-for-wordpress-plugin/
Wordfence
Two Vulnerabilities Patched in Facebook for WordPress Plugin
On December 22, 2020, our Threat Intelligence team responsibly disclosed a vulnerability in Facebook for WordPress, formerly known as Official Facebook Pixel, a WordPress plugin installed on over 500,000 sites. This flaw made it possible for unauthenticated…