You are here |
0xboku.com | ||
| | | |
thatsn0tmy.site
|
|
| | | | Hi folks! I recently read about a few vulnerabilities on Terramaster which were basically stolen from me heavily inspired by my previous ones, so I decided to look into Terramaster again, just to find a few more. Ah. This time I didn't spend much time reasearching, and I couldn't find an auth bypass so you will need valid credentials to reach the RCEs. Don't worry tho, you ransomware operators can still get the admin hashes and username. Some assembly hashcat required. | |
| | | |
highon.coffee
|
|
| | | | LFI Explained and the techniques to leverage a shell from a local file inclusion vulnerability. How to get a shell from LFI | |
| | | |
danaepp.com
|
|
| | | | Learn how to write exploits that take advantage of blind command injection vulnerabilities using a time-delayed boolean oracle attack. | |
| | | |
www.komodosec.com
|
|
| | How a failing red-team engagement led us to find a silly zero day. And why "insecure by default" is still an issue in 2024. |