Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @bao7uo
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @bao7uo
-
Paul Taylor proslijedio/la je Tweet
The CVE-2019-18935 is a severe insecure deserialization vulnerability affecting
#Telerik UI. Understand its impact + learn to safely patch your software in this post from@noperator: https://hubs.ly/H0mf7L-0 (With thanks to@mwulftange +@bao7uo)pic.twitter.com/qHc5XoKywA
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Great blog post
@noperator and thanks for your input on my exploit too :-)https://twitter.com/noperator/status/1205534110212673548 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A great blog post by
@TheRealWover relevant to the Telerik .NET deserialization vulnerability discovered by@mwulftange https://thewover.github.io/Mixed-Assemblies/ … https://github.com/bao7uo/RAU_crypto/ …https://twitter.com/bao7uo/status/1197798249593294848 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I've recently added a bit more documentation to my RAU_crypto Telerik exploit for exploiting the .NET deserialization vulnerability discovered by
@mwulftangehttps://twitter.com/bao7uo/status/1140356531474640899 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Quick win to stop firefox putting out-of-scope requests through
#BurpSuite put this list in "No proxy for": localhost, 127.0.0.1,.mozilla.com,.mozilla.org,.mozilla.net,.firefox.com,.firefox.org,.firefox.net,.digicert.com,.openh264.org,http://safebrowsing.googleapis.com ,.pki.googpic.twitter.com/o5HEAOjmQ1
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Paul Taylor proslijedio/la je Tweet
Introducing the "JWT Attack Playbook" A deep dive methodology for practical JWT testing. Written alongside the MASSIVELY UPDATED jwt_tool https://github.com/ticarpi/jwt_tool/wiki …
#jwt#webapp#bugbountypic.twitter.com/XQ7HV7NtUn
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When you finish a PhD in computer science, they take you to a special room and explain that you must never use recursion in real life. Its only purpose is to make programming hard for undergrads.https://twitter.com/m4tt_lewis/status/1176946985229836293 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Updated Telerik exploit https://github.com/bao7uo/RAU_crypto … after
@mwulftange great article on@codewhitesec blog. Also updated to work with latest versions in case of custom keys discovery. Thanks to@irsdl@gingeleski for feature inspiration. Props to@straight_blast@pwntester@olekmiroshHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A while back I wrote this IIS webshell with a Bash Script console built with asymmetric+symmetric cryptography for opsec. Aims to provide authentication and protection against mitm/eavesdropping (even when original upload is non-TLS) and replay attacks.https://github.com/bao7uo/PKI_WebShell …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Here is a fun
#privesc POC for CVE-2018-19788 - should work on all polkit/systemd Linux (A flaw was found in#PolicyKit (aka#polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any#systemctl command)pic.twitter.com/blieUbmmUu
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
My latest
@Burp_Suite Extension is very useful if you are testing foreign language webs. Available in the BApp store now.#owasp#burp#burpsuite https://portswigger.net/bappstore/0902e34e38be4dfc82475d7b47774a48 …pic.twitter.com/TbWvNJmKLw
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CVE-2018-15771, CVE-2018-15772 https://seclists.org/fulldisclosure/2018/Nov/34 …
#RecoverPoint I am still chasing the vendor for an update on CVE-2018-15770 which is the more interesting one.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
All
@AskNationwide web services down just now with no prior warning. They now seem to have come back online.pic.twitter.com/mYLOjwnFD7
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Very convenient, should be added to
@kalilinuxhttps://twitter.com/ticarpi/status/1028719623083122689 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A great tutorial by
@CaptMeelo about using my dp_crypto exploit for CVE-2017-9248 / Telerik Web UI. Wish I'd thought of the name TeleWreck, nice one! :-)https://capt-meelo.github.io/pentest/2018/08/03/pwning-with-telerik.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Exploit for a remote root rce zero day I found in
#recoverpointhttps://twitter.com/ptracesecurity/status/1010908227142410240 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Paul Taylor proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
#RecoverPoint unauth login exploit.. remote and local PoCs for CVE-2018-1235 https://github.com/bao7uo/dell-emc_recoverpoint/blob/master/EMC_RPT_CVE-2018-1235-local.md … https://github.com/bao7uo/dell-emc_recoverpoint/blob/master/EMC_RPT_CVE-2018-1235-remote.md …pic.twitter.com/XyeP5Q4zTy
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Finding the limits of openssh on Windows. It just killed the connection.pic.twitter.com/P9RxbTElWV
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
