Local File Read to RCE
During a recent engagement against a web application, a known vulnerability, CVE-2020-35340 was exploited to gain remote code execution on the server hosting the application
During a recent engagement against a web application, a known vulnerability, CVE-2020-35340 was exploited to gain remote code execution on the server hosting the application
adversary simulation
Attack Infrastructure Automation Part 2 - Terraform module design, software setup and configuration, and operator experience
xxe
During one of our perimeter assessment exercises, we identified and exploited a vulnerability in an in-house developed thin client
adversary simulation
Attack Infrastructure Automation Part 1 - An overview of our approach, main building blocks and design choices
cve
SilentGrid identified an unauthenticated time-based blind SQL injection in Global Vision Media's Blueprint Learning Management System (LMS)
research
An attack path from a recent engagement involving symbolic links
cve
SilentGrid identified a blind SQL injection vulnerability in Hexagon's GeoMedia WebMap 2020 solution
perimeter assessment
Who tries to knock on your server's door(s)
browser
CVE-2017-[0037 and 0059]
cve
PoC exploit for a type confusion issue in Internet Explorer 10, 11 and Edge
browser
PoC exploit for an use-after-free bug in IE
cve
A Proof of Concept exploit for CVE-2016-0450 in Oracle GoldenGate