|
You are here |
itm4n.github.io | ||
| | | | |
googleprojectzero.blogspot.com
|
|
| | | | | Posted by James Forshaw, Project Zero Previously I presented a technique to exploit arbitrary directory creation vulnerabilities on Wi... | |
| | | | |
parsiya.net
|
|
| | | | | [AI summary] A security engineer explains why 'style points' like unquoted service paths or 404 injection are not real vulnerabilities and clarifies the distinction between code injection at current privilege levels versus actual privilege escalation. | |
| | | | |
neodyme.io
|
|
| | | | | In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all relevant background information, describe our approach to reverse engineering the products' internals, and explain how we finally exploited the vulnerabilities. We hope to shed some light on this undervalued attack surface. | |
| | | | |
unit42.paloaltonetworks.com
|
|
| | | RCE vulnerability CVE-2023-3519 affects Citrix NetScaler products. This threat brief examines the current evidence, attack scope and interim guidance. | ||