GEBIRGE · @GEBIRGE
0 followers · 1 posts · Server infosec.exchange

Taking over a server with a single HTTP request:
gebir.ge/blog/privesc-part-3/

I went ahead and created a social media presence, that's how proud I am! ¯\_(ツ)_/¯

#rce #privilegeescalation #deserialization

Last updated 1 year ago

Ron Bowes · @iagox86
1057 followers · 265 posts · Server infosec.exchange

Posted a technical of CVE-2022-47986 (CVE_2022_47986 / ), a in IBM's Aspera software, which runs on a humorously old version of Ruby:

attackerkb.com/topics/jadqVo21

#cve202247986 #writeup #ruby #deserialization #vulnerability #attackerkb

Last updated 2 years ago

Marco Ivaldi · @raptor
1693 followers · 933 posts · Server infosec.exchange
Marco Ivaldi · @raptor
1681 followers · 897 posts · Server infosec.exchange

vRealize Log Insight VMSA-2023-0001 Technical Deep Dive

CVE-2022-31706: VMware vRealize Log Insight

CVE-2022-31704: VMware vRealize Log Insight broken Access Control Vulnerability

CVE-2022-31710: VMware vRealize Log Insight Vulnerability

CVE-2022-31711: VMware vRealize Log Insight Information Disclosure Vulnerability

horizon3.ai/vmware-vrealize-lo

#vmware #directory #traversal #vulnerability #deserialization

Last updated 2 years ago

Ivan Enderlin 🌱 :ferris: · @hywan
941 followers · 865 posts · Server fosstodon.org

Supercharging Zero-Copy Deserialization, by Manish Goregaokar at Rust Zürisee 2022, youtu.be/DM2DI3ZI_BQ.

#rustlang #talk #deserialization #performance

Last updated 2 years ago

Oliver · @oliverturner
191 followers · 4082 posts · Server toot.cafe

This looks like a really *fantastic* way to teach and learn about security vulnerabilities in JS-based apps: a standards-uncompliant gamified hacking sandbox!

---
With v6.3.0 (which will come out next week latest & adds some really bad vulnerability) we are officially at 100% "incompliance" with 2017's @OWASPTop10 while staying fully "backward-incompliant" with all previous editions! @owasp @vanderaj @j12934
twitter.com/owasp_juiceshop/st

#deserialization

Last updated 7 years ago