#漏洞 Exploiting the Sudo Baron Samedit vulnerability (CVE-2021-3156) on VMWare vCenter Server 7.0
https://research.nccgroup.com/2021/07/06/exploiting-the-sudo-baron-samedit-vulnerability-cve-2021-3156-on-vmware-vcenter-server-7-0/
https://research.nccgroup.com/2021/07/06/exploiting-the-sudo-baron-samedit-vulnerability-cve-2021-3156-on-vmware-vcenter-server-7-0/
#漏洞 Technical Advisory – Arbitrary File Read in Dell Wyse Management Suite (CVE-2021-21586, CVE-2021-21587)
https://research.nccgroup.com/2021/07/06/technical-advisory-arbitrary-file-read-in-dell-wyse-management-suite-cve-2021-21586-cve-2021-21587/
https://research.nccgroup.com/2021/07/06/technical-advisory-arbitrary-file-read-in-dell-wyse-management-suite-cve-2021-21586-cve-2021-21587/
NCC Group Research Blog
Technical Advisory – Arbitrary File Read in Dell Wyse Management Suite (CVE-2021-21586, CVE-2021-21587)
Vendor: Dell Vendor URL: Versions affected: Prior to version 3.3 Systems Affected: Any Author: Stephen Tomkinson stephen.tomkinson@nccgroup.com Advisory URL / CVE Identifier: CVE-2021-21586, CVE-20…
#漏洞 PoC for SSRF in IBM QRadar SIEM (CVE-2020-4786)
https://twitter.com/ptswarm/status/1412775355530764291
https://twitter.com/ptswarm/status/1412775355530764291
Twitter
PT SWARM
✨PoC for SSRF in IBM QRadar SIEM (CVE-2020-4786)✨ GET /console/chartServer?output=image&data=http://127.0.0.1:8080
#漏洞 CVE-2021-31800 impacket smbserver 目录遍历漏洞
https://www.checkmarx.com/blog/cve-2021-31800-how-we-used-impacket-to-hack-itself/
https://www.checkmarx.com/blog/cve-2021-31800-how-we-used-impacket-to-hack-itself/
Checkmarx
CVE-2021-31800: How We Used Impacket to Hack Itself
After investigating Impacket, the Checkmarx Security Research Team discovered a Path Traversal vulnerability, which could allow an attacker to write malicious files to any path on the target and achieve Remote Code Execution (RCE).
#漏洞 Solarwinds Serv-U 15.2.3 XSS漏洞(CVE-2021-32604)
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/solarwinds-serv-u-1523-share-url-xss-cve-2021-32604/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/solarwinds-serv-u-1523-share-url-xss-cve-2021-32604/
Trustwave
Solarwinds Serv-U 15.2.3 Share URL XSS (CVE-2021-32604)
Sometimes when pen-testing a large network you come across a few exposed web hosts running out-of-the-box software.
攻防日报(Daily safety) 每日推送地址变更为:https://forum.ywhack.com/forum-59-1.html
Ywhack
[~]#棱角 ::Edge.Forum*
棱角社区攻防日报推送
2022-7-11 10:0:0 星期一
标题:滥用本机 Windows 函数执行 shellcode
地址:http://ropgadget.com/posts/abusing_win_functions.html
标签:技术
-----------------------
标题:强制 Windows 机器向攻击者控制的机器进行身份验证的方法列表
地址:https://github.com/p0dalirius/windows-coerced-authentication-methods
标签:技术
-----------------------
标题:170万个澳大利亚域名存在162万个SPF和DMARC电子邮件的安全问题
地址:https://caniphish.com/phishing-resources/blog/australian-spf-scan
标签:漏洞
-----------------------
标题:从一文中了解SSRF的各种绕过姿势及攻击思路
地址:https://tttang.com/archive/1648/
标签:技术
-----------------------
标题:CVE-2022-26377: Apache HTTPd AJP Request Smuggling
地址:http://noahblog.360.cn/apache-httpd-ajp-request-smuggling/
标签:漏洞
-----------------------
2022-7-11 10:0:0 星期一
标题:滥用本机 Windows 函数执行 shellcode
地址:http://ropgadget.com/posts/abusing_win_functions.html
标签:技术
-----------------------
标题:强制 Windows 机器向攻击者控制的机器进行身份验证的方法列表
地址:https://github.com/p0dalirius/windows-coerced-authentication-methods
标签:技术
-----------------------
标题:170万个澳大利亚域名存在162万个SPF和DMARC电子邮件的安全问题
地址:https://caniphish.com/phishing-resources/blog/australian-spf-scan
标签:漏洞
-----------------------
标题:从一文中了解SSRF的各种绕过姿势及攻击思路
地址:https://tttang.com/archive/1648/
标签:技术
-----------------------
标题:CVE-2022-26377: Apache HTTPd AJP Request Smuggling
地址:http://noahblog.360.cn/apache-httpd-ajp-request-smuggling/
标签:漏洞
-----------------------
GitHub
GitHub - p0dalirius/windows-coerced-authentication-methods: A list of methods to coerce a windows machine to authenticate to an…
A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols. - p0dalirius/windows-coerced-authentic...
📢 棱角社区攻防日报推送
🔗 棱角社区: https://forum.ywhack.com
🕙 2023/10/12 16:05:28 · 星期四
🎈 [漏洞] cURL 漏洞 CVE-2023-38545 分析:并非世界末日的威胁
🎉 [漏洞] 微软内核流媒体服务漏洞:临界接近 0day 的深度分析与利用
💡 [漏洞] Squid Caching Proxy 安全审计:揭露 55 个漏洞及 35 个 0day
🍀 [漏洞] Ghostscript 安全概览:攻击者视角下的漏洞与利用
🔧 [漏洞] Cosmos SDK 中的远程代码执行漏洞分析
🔗 棱角社区: https://forum.ywhack.com
🕙 2023/10/12 16:05:28 · 星期四
🎈 [漏洞] cURL 漏洞 CVE-2023-38545 分析:并非世界末日的威胁
🎉 [漏洞] 微软内核流媒体服务漏洞:临界接近 0day 的深度分析与利用
💡 [漏洞] Squid Caching Proxy 安全审计:揭露 55 个漏洞及 35 个 0day
🍀 [漏洞] Ghostscript 安全概览:攻击者视角下的漏洞与利用
🔧 [漏洞] Cosmos SDK 中的远程代码执行漏洞分析