/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

positive.security
| | zero.lol
3.9 parsecs away

Travel
| | [AI summary] A technical article detailing an arbitrary code execution exploit against EA's Origin client through malicious custom URI schemes and Windows shortcut files.
| | devco.re
3.4 parsecs away

Travel
| | The research unveils a new attack surface in Windows by exploiting Best-Fit, an internal charset conversion feature. Through our work, we successfully transformed this feature into several practical attacks, including Path Traversal, Argument Injection, and even RCE, affecting numerous well-known applications!
| | itm4n.github.io
4.8 parsecs away

Travel
| | Whenever a "new" DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. "It's not a vulnerability!" or "There is a lot of hijackable DLLs on Windows..." are the most common reactions. Though, people often don't really speak about the same thing, hence the overall confusion which leads us nowhere. I don't pretend to know the ultimate truth but I felt the need to write this post in order to hopefully clarify some points.
| | blog.darkwolfsolutions.com
20.1 parsecs away

Travel
| September 26, 2024 Episode 15 CVE-2024-45623: Unauthenticated RCE in D-Link DAP-2310 Authors: Hahna Kane Latonick and Jonathan Waterman Dark Wolf Solutions recently disclosed a vulnerability to D-Link that results in unauthenticated remote code execution (RCE) in their DAP-2310 REV-A Wireless