Kacper SzurekTagsPolishNewsletterAbout
YouTubeWebinaryFacebookTwitter
Kacper Szurek
TagsPolishNewsletterAboutYouTubeWebinaryFacebookTwitter

Vulnerabilities

GPG Reaper - Steal GPG Private Keys

This POC demonstrates method for obtaining GPG private keys from gpg-agent memory under Windows. Normally this should be possible only within 10 minutes time frame (--default-cache-ttl value).

05-03-2018

1 MIN READ

Vulnerabilities

Pentest TeamCity Server using Metasploit

Obtain passwords from JetBrains IDE (like IntelliJ or PyCharm) and use those credentials inside TeamCity Continuous Integration Server

11-02-2018

1 MIN READ

Vulnerabilities

Burp WP - Find vulnerabilities in WordPress using Burp

If you have Burp Pro, issues will also appear inside Scanner tab. Interesting things will be highlighted.

22-01-2018

1 MIN READ

Vulnerabilities

GitStack 2.3.10 Unauthenticated Remote Code Execution

$_SERVER['PHP_AUTH_PW'] is directly passed to exec function.

18-01-2018

1 MIN READ

Vulnerabilities

QNAP HelpDesk 1.1.12 Privilege Escalation using SQL Injection

We can access registerExternalLog without any user credentials.

25-10-2017

2 MIN READ

Vulnerabilities

Netgear ReadyNAS Surveillance 1.4.3-16 Unauthenticated RCE

$_GET['uploaddir'] is not escaped and passed to system() through $tmp_upload_dir.

29-09-2017

1 MIN READ

Vulnerabilities

Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution

CVE-2017-11151 allows remote attackers to upload arbitrary files to the specified directories.

17-09-2017

1 MIN READ

Vulnerabilities

ManageEngine Desktop Central 10 Build 100087 RCE

When uploading a file, the FileUploadServlet class does not check the user-controlled fileName parameter using hasVulnerabilityInFileName function.

24-07-2017

3 MIN READ

© 2022 Kacper Szurek
Disclosure Policy
YouTube
Facebook
Twitter