#漏洞 Universal “netmask” npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote file inclusion, local file inclusion, and more (CVE-2021-28918)
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Universal "netmask" npm package, used by 270,000+ projects, vulnerable to octal input data: server-side request forgery, remote…
The following research outlines a vulnerability discovered in netmask npm package that is currently used by 278,722+ other projects. The vulnerability has been present for 9 years. Since this package is so incredibly widespread, I would suggest every nodejs…
#情报 PHP的Git服务器被黑客入侵以向PHP源代码添加后门
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
https://www.bleepingcomputer.com/news/security/phps-git-server-hacked-to-add-backdoors-to-php-source-code/
BleepingComputer
PHP's Git server hacked to add backdoors to PHP source code
In the latest software supply chain attack, the official PHP Git repository was hacked and tampered with. Yesterday, two malicious commits were pushed to the php-src Git repository maintained by the PHP team on their git.php.net server. The threat actors…
#漏洞 Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
#漏洞 POC for CVE-2021-1656, an information disclosure in tpm.sys.
https://github.com/waleedassar/CVE-2021-1656
https://github.com/waleedassar/CVE-2021-1656
GitHub
GitHub - waleedassar/CVE-2021-1656
Contribute to waleedassar/CVE-2021-1656 development by creating an account on GitHub.
#漏洞 DD-WRT 缓冲区溢出漏洞(CVE-2021-27137)
https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
SSD Secure Disclosure
SSD Advisory – DD-WRT UPNP Buffer Overflow - SSD Secure Disclosure
TL;DR Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability. Vulnerability Summary DD-WRT is “is Linux-based firmware for wireless routers and access…
#漏洞 北京致远G6政务协同系统V6.1SP1 反射性xss漏洞 CVE-2020-20545
https://note.youdao.com/ynoteshare1/index.html?id=29f908204968a79233c1c0c80a59f8ff&type=note
https://note.youdao.com/ynoteshare1/index.html?id=29f908204968a79233c1c0c80a59f8ff&type=note
#漏洞 VMware vRealize Operations Manager API SSRF漏洞 (CVE-2021-21975)
https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-21975.yaml
https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-21975.yaml
GitHub
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities. - projectdiscovery/nuclei-templates
#漏洞 POC for CVE-2021-24098, a Denial Of Service bug in condrv.sys.
https://github.com/waleedassar/CVE-2021-24098
https://github.com/waleedassar/CVE-2021-24098
GitHub
GitHub - waleedassar/CVE-2021-24098: POC for CVE-2021-24098
POC for CVE-2021-24098. Contribute to waleedassar/CVE-2021-24098 development by creating an account on GitHub.