Vulnerabilities
$_COOKIE[STATIONSID] is not escaped.
1 MIN READ
Vulnerabilities
$_COOKIE[STATIONSID] is not escaped.
1 MIN READ
Vulnerabilities
RunImpersonated() executes given function in the context of currently logged in user.
3 MIN READ
Vulnerabilities
CG6Service service has interesting method SetPeLauncherState which allows launch the debugger automatically for every process we want using Image File Execution Options
1 MIN READ
Vulnerabilities
ShadeYou service executes any file without any verification as SYSTEM user.
1 MIN READ
Vulnerabilities
Inside GenerateConfiguration method there is bug which leads to comand injection
1 MIN READ
Vulnerabilities
Only files digitally signed by SparkLabs can use this pipe because of usage of new X509Certificate2. But it's possible to bypass this by injecting our DLL into Viscosity.exe.
4 MIN READ
Vulnerabilities
It's possible to execute arbitrary commands using login form because exec() function is used without using escapeshellarg() or escapeshellcmd().
2 MIN READ
Vulnerabilities
Using Execute Command File we can execute commands on Scheduled system shutdown and because UPSMan is running as SYSTEM we execute them as Priveleged user.
1 MIN READ
From 0 to pentesting hero
Every service that has a login mechanism should also have the option to reset the password. But how to do it right?
26-02-2019
2 MIN READ