rioru (Dany Bach)
@ddxhunter
Penetration tester & security researcher
ID: 28323272
02-04-2009 11:55:18
634 Tweet
1,1K Followers
470 Following
Thank you TyphoonCon🌪️, and everybody for attending! I will release the demo code, the RCE on #Adminer using #CVE-2022-31626, in the next few days! The other one is more complex, so you'll have to wait for the blog post on Ambionics Security
Learn how we discovered 5 distinct vulnerabilities on WatchGuard #Firebox/#XTM firewalls, and obtained a pre-auth Remote Code Execution as root #0day (CVE-2022-31789, CVE-2022-31790). ambionics.io/blog/hacking-w…
Introducing sshimpanzee, a reverse shell made by Titouan Lazard based on openssh's sshd. It supports DNS, ICMP and HTTP encapsulation as well as SOCKS and HTTP Proxies : blog.lexfo.fr/sshimpanzee.ht…
#Fortinet published a patch for CVE-2023-27997, the Remote Code Execution vulnerability rioru (Dany Bach) and I reported. This is reachable pre-authentication, on every SSL VPN appliance. Patch your #Fortigate. Details at a later time. #xortigate
Iconv, set the charset to RCE: in the first blog post of this series, Charles Fol will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961) ambionics.io/blog/iconv-cve…