Posts
2521
Following
647
Followers
1462
"I'm interested in all kinds of astronomy."
repeated
@jerry thanks, it's already better actually
1
0
0
repeated

We've updated our blog on abusing file deletes to escalate privileges. We've also released PoC to demonstrate this. The exploit offers a high degree of reliability and eliminates all race conditions. It has been tested on the latest Windows 11 Enterprise. https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks

2
6
0
repeated

D-Link is warning that four remote code execution (RCE) flaws impacting all hardware and firmware versions of its DIR-846W router will not be fixed as the products are no longer supported.

https://www.bleepingcomputer.com/news/security/d-link-says-it-is-not-fixing-four-rce-flaws-in-dir-846w-routers/

2
5
0
CVE-2024-45310: runc can be tricked into creating empty files/directories on host

https://seclists.org/oss-sec/2024/q3/237
0
0
1
repeated

SecureLayer7: CVE-2024-37084: Spring Cloud Remote Code Execution
SecureLayer7 has been churning out zero-day vulnerabilities (publicly releasing information about vulnerabilities without a coordinated vulnerability disclosure with the impacted vendor or assigning CVEs) and proofs of concepts for vulnerabilities. According to Spring.io, Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing platform deployed in Cloud Foundry and Kubernetes. CVE-2024-37084 (9.8 CRITICAL) is an arbitrary file write. SecureLayer7 used patch diffing to determine that it’s an insecure deserialization vulnerability that leads to remote code execution, and provides a proof of concept for it.

0
1
0
repeated
Edited 10 months ago

Mozilla Foundation security advisories:

  • 2024-39 Security Vulnerabilities fixed in Firefox 130
  • 2024-40 Security Vulnerabilities fixed in Firefox ESR 128.2
  • 2024-41 Security Vulnerabilities fixed in Firefox ESR 115.15
  • 2024-42Security Vulnerabilities fixed in Focus for iOS 130

No mention of Firefox for iOS or Thunderbird (which would arrive in 2 separate advisories). Expect future advisories likely later today. No mention of exploitation.

Edited to include late advisory for Focus for iOS 130.

1
1
0
@jerry Hi! infosec.place throwing 504's again for the main timeline :( Could you please take a look?
1
0
0
repeated

The recording of our @WEareTROOPERS presentation is now online, enjoy!

- IBM i for Wintel Hackers

https://www.youtube.com/watch?v=t4fUvfzgUbY

0
1
0
repeated

Analysis of CVE-2024-37084: Spring Cloud Remote Code Execution https://blog.securelayer7.net/spring-cloud-skipper-vulnerability/

0
1
0
repeated

AI slide for the talk (work in progress):

AI does not save us

AI fools researchers think they found problems

AI assisted reports take longer to debunk

AI is an added burden for maintainers

3
2
0
@pancake @nanochess @travisgoodspeed I actually feel tempted build something with this, sounds awesome!
0
0
1
Off-by-One 2024 Day 1 - Keynote : Breaking Into Vulnerability Research: Dr Silvio Cesare

https://www.youtube.com/watch?v=tAmjkfO3-Ow
0
3
3
:O

"The TMS9900 is bonkers. Big endian, has no stack pointer, and there's an instruction to execute the contents of a register as if it were an instruction in memory." - @travisgoodspeed

"Mike Brent (tursilion) made an awesome TMS9900 code generator for CVBasic, so now it can target TI-99/4A computers. The picture shows Viboritas running in the Classic99 emulator." - @nanochess

https://github.com/nanochess/cvbasic
2
3
10
CVE-2023-41111: Samsung Baseband RLC Data Re-Assembly Buffer Overflow

https://labs.taszk.io/blog/post/93_rlc_bof/
0
0
3
repeated

Traceeshark: Deep Linux runtime visibility meets Wireshark https://github.com/aquasecurity/traceeshark

0
1
0
Show older