@Phantasm_Lab – Telegram
@Phantasm_Lab
2.56K subscribers
712 photos
34 videos
671 files
2.71K links
- Red x Blue Security
- Bug Bounty 💷 💵
- Exploitable tools
- Programming Languages
- Malware Analysis

🇺🇸 🇧🇷 🇪🇸

since 2017 ©


Parceiros:
@TIdaDepressaoOficial @acervoprivado @ReneGadesx @G4t3w4y
Download Telegram
Forwarded from Security Talks (Jonhnathan Jonhnathan Jonhnathan)
Breach: From Recon to penetrating the perimeter, to actions on the target

https://youtu.be/e99iQC-dod8

@SecTalks
Laravel debug mode RCE | CVE-2021-3129 PoC

https://youtu.be/gr8ZKQpYiug
voipmonitor rce | CVE-2021-30461 poc

https://youtu.be/9V_BI6Lq-Rw
Apache ofbiz rce | CVE-2020-9496 PoC

#Apacheofbiz unauth rce vulnerability : #CVE-2020-9496
Apache OFBiz is an open source enterprise resource planning (ERP) system. It provides a suite of enterprise applications that integrate and automate many of the business processes of an enterprise.

https://youtu.be/DO93Xc8sGWg
CVE-2020-7048 PoC | WordPress Database Reset Plugin Vulnerability

VULNERABILITIES IN WORDPRESS DATABASE RESET PLUGIN ALLOW TO CAPTURE OR ERASE A SITE DATABASE. Wordfence specialists report that at the beginning of January, dangerous vulnerabilities were discovered in the popular WordPress Database Reset plugin installed on more than 80,000 sites. This plugin, developed by WebFactory Ltd, is designed to invest in database setup and quick reset to default settings. As a result, bugs can be used to capture sites and reset tables in the database.

https://youtu.be/nj_dqcvrwp4
From XSS in WordPress Core (CVE-2020-4046) to RCE

A long-lived XSS vulnerability was patched in WordPress 5.4.2. It allowed any authenticated user, with privileges to create or edit a post, to embed arbitrary JavaScript within the post. When the post was later viewed the code executed in the context of the site.

https://youtu.be/tCh7Y8z8fb4
Alh4zr3d - Type Jugging Leading to Auth Bypass!

For the final machine in the "Starting Point" track, we had the opportunity to bypass the login in a really interesting way: utilizing PHP's strange, eldritch logic for performing comparisons between objects of different types!

https://youtu.be/vn-kHZcdnzQ
DevSecCon24

DevSecCon24
is a global, vendor-neutral, community-driven conference that connects developers, security and operations teams to learn and enable the integration of security into their development practices.

https://events.bizzabo.com/308842/agenda