Implications of a Stealth Hard-Drive Backdoor
https://www.ibr.cs.tu-bs.de/users/kurmus/papers/acsac13.pdf
#Backdoor
https://www.ibr.cs.tu-bs.de/users/kurmus/papers/acsac13.pdf
#Backdoor
ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
Orange Tsai at DEFCON 29
https://www.youtube.com/watch?v=5mqid-7zp8k
Orange Tsai at DEFCON 29
https://www.youtube.com/watch?v=5mqid-7zp8k
YouTube
DEF CON 29 - Orange Tsai - ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
Microsoft Exchange Server is an email solution widely deployed within government and enterprises, and it is an integral part of both their daily operations and security. Needless to say, vulnerabilities in Exchange have long been the Holy Grail for attackers…
Chaining PHP Exploits with the help of Magic (and luck)
https://www.reddit.com/r/netsec/comments/p4dyuh/chaining_php_exploits_with_the_help_of_magic_and/
https://www.reddit.com/r/netsec/comments/p4dyuh/chaining_php_exploits_with_the_help_of_magic_and/
reddit
Chaining PHP Exploits with the help of Magic (and luck)
Posted in r/netsec by u/_creosote • 10 points and 6 comments
Zero-Day | RCE: The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month.
https://threatpost.com/unpatched-fortinet-bug-firewall-takeovers/168764/
https://threatpost.com/unpatched-fortinet-bug-firewall-takeovers/168764/
Threat Post
Unpatched Fortinet Bug Allows Firewall Takeovers
The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month.
Zoom RCE from Pwn2Own 2021 writeup https://t.co/HWERqRCNaV
Sector 7
Zoom RCE from Pwn2Own 2021
On April 7 2021, Thijs Alkemade and Daan Keuper demonstrated a zero-click remote code execution exploit in the Zoom video client during Pwn2Own 2021. Now that related bugs have been fixed for all users (see ZDI-21-971 and ZSB-22003) we can safely detail the…