|
You are here |
knight.sc | ||
| | | | |
sektioneins.de
|
|
| | | | | SektionEins organises an OS X and iOS Kernel Internals for Security Researcher Training in Frankfurt in October 2015. .red {color:red; font-weight: bold;} .bold {font-weight: bold;} Instructor: St | |
| | | | |
m417z.com
|
|
| | | | | This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in December's Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or otherwise inaccessible process, allowing for privilege escalation. The vulnerability is caused by a lack of security checks in the InitializeXamlDiagnosticsEx API, which is used for inspecting applications that use Extensible Application Markup Language (XAML) for their UI. XAML is the recommended way to build user interfaces in new Windows applications, and is used by more and more built-in applications, including Task Manager and Windows Terminal. | |
| | | | |
www.wired.com
|
|
| | | | | Plus: Apple shuts down a Flipper Zero Attack, Microsoft patches more than 30 vulnerabilities, and more critical updates for the last month of 2023. | |
| | | | |
pentesterlab.com
|
|
| | | Learn how the OWASP Top 10 serves as a vital awareness tool for web developers but falls short for thorough penetration testing and code review. Discover what lies beyond these foundational risks and why researchers must dig deeper for real security. | ||