Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Konica Minolta bizhub MFP Printer Terminal Sandbox Escape
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
Multiple Konica Minolta bizhub MFP printer terminals suffer from a sandbox escape with root access and have clear-text password vulnerabilities.
SHA-256 |
Download
Source:packetstormsecurity.com
Konica Minolta bizhub MFP Printer Terminal Sandbox Escape
https://4.bp.blogspot.com/-gp6vAY2GXMM/WWlvG3cWkQI/AAAAAAAAILY/aMDesAGFEocqJU-7SaIaO870_Bbf2ZUHACLcBGAs/s1600/h139.png
Multiple Konica Minolta bizhub MFP printer terminals suffer from a sandbox escape with root access and have clear-text password vulnerabilities.
SHA-256 |
57e210f71bf42a3b11e36e7813fbbb82fccbd07555cd2d876285ea9c410da45cDownload
Source:packetstormsecurity.com
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
COOPER: Testing The Binding Code Of Scripting Languages With Cooperative Mutation
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
Scripting languages like JavaScript are being integrated into commercial software to support easy file modification. For example, Adobe Acrobat accepts JavaScript to dynamically manipulate PDF files. To bridge the gap between the high-level scripts and the low-level languages (like C/C++) used to implement the software, a binding layer is necessary to transfer data and transform representations. However, due to the complexity of two sides, the binding code is prone to inconsistent semantics and security holes, which lead to severe vulnerabilities. Existing efforts for testing binding code merely focus on the script side, and thus miss bugs that require special program native inputs. In this paper, the researchers propose cooperative mutation, which modifies both the script code and the program native input to trigger bugs in binding code.
SHA-256 |
Download
Source:packetstormsecurity.com
COOPER: Testing The Binding Code Of Scripting Languages With Cooperative Mutation
https://4.bp.blogspot.com/-gQsa2Au6OFw/WWlvKe9cGFI/AAAAAAAAIME/7MuhuX3Jqy0CeEu0oyVXmXST8BDpKvIGgCLcBGAs/s1600/h15.png
Scripting languages like JavaScript are being integrated into commercial software to support easy file modification. For example, Adobe Acrobat accepts JavaScript to dynamically manipulate PDF files. To bridge the gap between the high-level scripts and the low-level languages (like C/C++) used to implement the software, a binding layer is necessary to transfer data and transform representations. However, due to the complexity of two sides, the binding code is prone to inconsistent semantics and security holes, which lead to severe vulnerabilities. Existing efforts for testing binding code merely focus on the script side, and thus miss bugs that require special program native inputs. In this paper, the researchers propose cooperative mutation, which modifies both the script code and the program native input to trigger bugs in binding code.
SHA-256 |
5f9d0ad09e9e62d12e246894db4172788cd3662fb32d618c99f88dda19d6b911Download
Source:packetstormsecurity.com
Phoenix — HackTheBox — Web App Penetration Testing — Writeup
https://0x1rootjkqsta.medium.com/phoenix-hackthebox-web-app-penetration-testing-writeup-ebc53d573629?source=rss------bug_bounty-5
https://0x1rootjkqsta.medium.com/phoenix-hackthebox-web-app-penetration-testing-writeup-ebc53d573629?source=rss------bug_bounty-5
Hello guys I am back to posting another writeup. So let’s start talking instead of wasting our time.Continue reading on Medium » (https://0x1rootjkqsta.medium.com/phoenix-hackthebox-web-app-penetration-testing-writeup-ebc53d573629?source=rss------bug_bounty-5)
Phoenix — HackTheBox — Web App Penetration Testing — Writeup
Hello guys I am back to posting another writeup. So let’s start talking instead of wasting our time.Continue reading on Medium »
Read more...
Hello guys I am back to posting another writeup. So let’s start talking instead of wasting our time.Continue reading on Medium »
Read more...
Docker Containers Security Series
https://www.reddit.com/r/redteamsec/comments/up09ly/docker_containers_security_series/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/docker-containers-security/) [comments] (https://www.reddit.com/r/redteamsec/comments/up09ly/docker_containers_security_series/)
https://www.reddit.com/r/redteamsec/comments/up09ly/docker_containers_security_series/
submitted by /u/tbhaxor (https://www.reddit.com/user/tbhaxor)
[link] (https://tbhaxor.com/docker-containers-security/) [comments] (https://www.reddit.com/r/redteamsec/comments/up09ly/docker_containers_security_series/)
Dark Reading: Attacks/Breaches
CISO Shares Top Strategies to Communicate Security's Value to the Biz
In a keynote address at Black Hat Asia in Singapore this week, CISO and former NASA security engineer George Do discussed his go-to model for measuring security effectiveness – and getting others in the organization to listen.
CISO Shares Top Strategies to Communicate Security's Value to the Biz
In a keynote address at Black Hat Asia in Singapore this week, CISO and former NASA security engineer George Do discussed his go-to model for measuring security effectiveness – and getting others in the organization to listen.
Dark Reading: Attacks/Breaches
Black Hat Asia: Democracy's Survival Depends on Taming Technology
The conference opens with stark outlook on the future of global democracy — currently squeezed between Silicon Valley and China.
Black Hat Asia: Democracy's Survival Depends on Taming Technology
The conference opens with stark outlook on the future of global democracy — currently squeezed between Silicon Valley and China.
Dark Reading
Black Hat Asia: Democracy's Survival Depends on Taming Technology
The conference opens with stark outlook on the future of global democracy — currently squeezed between Silicon Valley and China.