Critical : Malware and XSS file can be uploaded and executed on udemy
https://hackerone.com/reports/172694
https://hackerone.com/reports/172694
HackerOne
Udemy disclosed on HackerOne: Critical : Malware and XSS file can...
The investigator found that he can upload any file type to our upload bucket. That is intended behavior - file content is enforced before moving it out of our upload bucket.
Attacking UEFI Runtime Services and Linux
http://blog.frizk.net/2017/01/attacking-uefi-and-linux.html
http://blog.frizk.net/2017/01/attacking-uefi-and-linux.html
blog.frizk.net
Attacking UEFI Runtime Services and Linux
Attackers with physical access are able to attack the firmware on many fully patched computers with DMA - Direct Memory Access. Once code ex...
Oops!
FaceBook Remote Code Excution
http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html
FaceBook Remote Code Excution
http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html
If You Can't Find Vulnerability In php noscript, Dont Worry!
PHP Support All Vulnerabilities!
PHP Support All Vulnerabilities!
Microsoft Remote Desktop Client for Mac Remote Code Execution
Video Demo: https://www.youtube.com/watch?v=6HeSiXYRpNY
Advisory: https://goo.gl/wmk9Dy
From RDP to RCE :)
Video Demo: https://www.youtube.com/watch?v=6HeSiXYRpNY
Advisory: https://goo.gl/wmk9Dy
From RDP to RCE :)
YouTube
Microsoft Remote Desktop Client for Mac Remote Code Execution
A vulnerability exists in Microsoft Remote Desktop for Mac that allows a remote attacker to execute arbitrary code on the target machine. User interaction is...