cKure Red
2.5K subscribers
71 photos
46 videos
21 files
458 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
cKure Red pinned «Remote Code Execution in Exchange PowerShell Backend. https://www.zerodayinitiative.com/blog/2022/11/14/control-your-types-or-get-pwned-remote-code-execution-in-exchange-powershell-backend»
🔧 Tool: Femtobrowser. A really basic web browser written in ~500 lines of V using only the integrated vlib library. It was not designed to be fast or efficient, but rather to be a simple example of how to use the vlib library to create a web browser. Made in few hours to mess around with V.

https://github.com/SheatNoisette/femtobrowser
cKure Red pinned «RCE (remote account / vehicle takeover) using CRLF, chained bugs. Interesting thread. https://twitter.com/samwcyo/status/1597695281881296897»
GitHub dorks.
● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates.

This is not the official def. Will wait for researcher to share details.
cKure Red pinned «● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details.»
cKure Red
● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details.
Impact of the Zero-Day (mentioned here: https://t.me/ckuRED/231).

Enrollment: An adversary can issue a certificate from the CA and later use that for hosting fake websites that all the clients of that firm under attack will automatically trust.

Revocation: An adversary can bring down any website /application by just getting the public certificate of that application.

Optionally, if you have to plan big, discover all applications, download the public certificate, and at once revoke all.