收集的一些在线工具列表:https://forum.ywhack.com/bountytips.php?tools
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
一些好用的在线字典系列:https://forum.ywhack.com/wordlists.php
反弹shell在线命令生成:https://forum.ywhack.com/shell.php
文件下载快捷命令生成:https://forum.ywhack.com/bountytips.php?download
工具合集/安全资料/漏洞情报:https://forum.ywhack.com/center.php
各种技巧,赏金姿势、工具等:https://forum.ywhack.com/bountytips.php
Ywhack
[~]#棱角 ::Edge.Forum*
#漏洞 Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE-2021-32824
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
GitHub Security Lab
GHSL-2021-034_043: Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE…
Multiple vulnerabilities have been found in Apache Dubbo enabling attackers to compromise and run arbitrary system commands on both Dubbo consumers and providers.
#漏洞 CVE-2021-1497: CISCO HYPERFLEX HX AUTH HANDLING REMOTE COMMAND EXECUTION
https://www.zerodayinitiative.com/blog/2021/6/23/cve-2021-1497-cisco-hyperflex-hx-auth-handling-remote-command-execution
https://www.zerodayinitiative.com/blog/2021/6/23/cve-2021-1497-cisco-hyperflex-hx-auth-handling-remote-command-execution
Zero Day Initiative
Zero Day Initiative — CVE-2021-1497: Cisco HyperFlex HX Auth Handling Remote Command Execution
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Kc Udonsi and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in the Cisco HyperFlex HX Data Platform. The bug was originally discovered…
#漏洞 CVE-2021-24084 An unpatched information disclosure in Microsoft Windows
https://halove23.blogspot.com/2021/06/CVE-2021-24084-Unpatched-ID.html
https://halove23.blogspot.com/2021/06/CVE-2021-24084-Unpatched-ID.html
#漏洞 A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.
https://github.com/kahla-sec/CVE-2021-27850_POC
https://github.com/kahla-sec/CVE-2021-27850_POC
GitHub
GitHub - kahla-sec/CVE-2021-27850_POC: A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated…
A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution. - kahla-sec/CVE-2021-27850_POC
#漏洞 How We Are Able To Hack Any Company By Sending Message - $20,000 Bounty [CVE-2021–34506]
https://cyberxplore.medium.com/how-we-are-able-to-hack-any-company-by-sending-message-including-facebook-google-microsoft-b7773626e447
https://cyberxplore.medium.com/how-we-are-able-to-hack-any-company-by-sending-message-including-facebook-google-microsoft-b7773626e447
Medium
How We Are Able To Hack Any Company By Sending Message - $20,000 Bounty [CVE-2021–34506]
Hello Folks , I hope everyone is doing well in this pandemic & making full use of it for learning new stuff in their daily life . so this a…
#漏洞 Analysis of a Heap Buffer-Overflow Vulnerability in Adobe Acrobat Reader DC
https://blog.exodusintel.com/2021/06/28/analysis-of-a-heap-buffer-overflow-vulnerability-in-adobe-acrobat-reader-dc/
https://blog.exodusintel.com/2021/06/28/analysis-of-a-heap-buffer-overflow-vulnerability-in-adobe-acrobat-reader-dc/
Exodus Intelligence
Analysis of a Heap Buffer-Overflow Vulnerability in Adobe Acrobat Reader DC - Exodus Intelligence
By Sergi Martinez This post analyzes and exploits CVE-2021-21017, a heap buffer overflow reported in Adobe Acrobat Reader DC prior to versions 2021.001.20135. This vulnerability was anonymously reported to Adobe and patched on February 9th, 2021. A publicly…
#漏洞 Adobe Experience Manager 身份验证绕过 0Day 漏洞
https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/
https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/
Labs Detectify
Undocumented authentication bypass issue in AEM Package Manager [Blog updated]
Detectify Crowdsource ethical hackers found an undocumented authentication bypass in Adobe Experience Manager. Comments from Adobe added.
#漏洞 PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service
https://github.com/hhlxf/PrintNightmare
https://github.com/hhlxf/PrintNightmare
#漏洞 Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
McAfee Blog
Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+ | McAfee Blog
Introduction Microsoft Windows Graphics Device Interface+, also known as GDI+, allows various applications to use different graphics functionality on
#漏洞 ForgeRock AM远程代码执行漏洞(CVE-2021-35464)
https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464
https://portswigger.net/research/pre-auth-rce-in-forgerock-openam-cve-2021-35464
PortSwigger Research
Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)
While participating in one private bug bounty program, I discovered a pre-auth RCE in ForgeRock OpenAM server - a popular access management solution for web applications. In this blog post, I'm going
#漏洞 CVE-2021-26892: AN AUTHORIZATION BYPASS ON THE MICROSOFT WINDOWS EFI SYSTEM PARTITION
https://www.zerodayinitiative.com/blog/2021/6/30/cve-2021-26892-an-authorization-bypass-on-the-microsoft-windows-efi-system-partition
https://www.zerodayinitiative.com/blog/2021/6/30/cve-2021-26892-an-authorization-bypass-on-the-microsoft-windows-efi-system-partition
Zero Day Initiative
Zero Day Initiative — CVE-2021-26892: An Authorization Bypass on the Microsoft Windows EFI System Partition
In October 2020, researcher Abdelhamid Naceri, also known as halov, submitted a unique vulnerability to the ZDI. This vulnerability in Windows 10 allows a low-privileged user to wipe out arbitrary files needed for UEFI boot. The attack can even be conducted…