A place to share links and articles that i have found helpful. This blog tends to be more offensive security minded. Basically it is a collection of notes that I will update periodically. None of this is set in stone, and I could very well be wrong on most of it. Just saying.
Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts
Windows WMI Recieve Notification
https://packetstormsecurity.com/files/147498/ms16_014_wmi_recv_notif.rb.txt
Lexpress for the win
Check out @bohops’s Tweet: https://twitter.com/bohops/status/969388848416460800?ref_src=twcamp%5Eshare%7Ctwsrc%5Eandroid%7Ctwgr%5Edefault%7Ctwcon%5E7090%7Ctwterm%5E3
Code Execution via CSV file
Totally stumbled across this by accident, but it does not look like I ma the first to find this:
http://georgemauer.net/2017/10/07/csv-injection.html
https://www.owasp.org/index.php/CSV_Excel_Macro_Injection
https://pentestmag.com/formula-injection/
https://www.contextis.com/blog/comma-separated-vulnerabilities
https://hackerone.com/reports/72785
http://georgemauer.net/2017/10/07/csv-injection.html
https://www.owasp.org/index.php/CSV_Excel_Macro_Injection
https://pentestmag.com/formula-injection/
https://www.contextis.com/blog/comma-separated-vulnerabilities
https://hackerone.com/reports/72785
Subscribe to:
Posts (Atom)