Y4er (@y4er_chabug) 's Twitter Profile
Y4er

@y4er_chabug

Happy!

ID: 1200233606276272128

linkhttp://Y4er.com calendar_today29-11-2019 02:02:55

145 Tweet

4,4K Takipçi

363 Takip Edilen

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

Even though JMX exploitation is well understood, Markus Wulftange and Tobias Neitzel found new universal exploitation techniques & one of them allows to gain instant Remote Code Execution using TemplatesImpl (which is now implemented in #beanshooter) codewhitesec.blogspot.com/2023/03/jmx-ex…

starlabs (@starlabs_sg) 's Twitter Profile Photo

It's TGIF and we have a new blog post by our team member, Janggggg Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) Thanks to all the other team members for reviewing it as well. starlabs.sg/blog/2023/04-m…

Y4er (@y4er_chabug) 's Twitter Profile Photo

need one MOVEit license activation key :( Most of the time in security research is spent looking for product installation packages and trial certificates.

Y4er (@y4er_chabug) 's Twitter Profile Photo

Great article! But I think you are missing a very critical part, CVE-2023-20887 is actually a patch bypass for CVE-2022-31702. This is an analysis article I wrote, please read it and correct me. xz.aliyun.com/t/12608

Soroush Dalili (@irsdl) 's Twitter Profile Photo

Cookieless DuoDrop: IIS Auth Bypass & App Pool Privesc in ASP .NET Framework (CVE-2023-36899) soroush.me/blog/2023/08/c… #Appsec #bugbountytips

Cookieless DuoDrop: IIS Auth Bypass & App Pool Privesc in ASP .NET Framework (CVE-2023-36899)

soroush.me/blog/2023/08/c…

#Appsec #bugbountytips
Y4er (@y4er_chabug) 's Twitter Profile Photo

After two days, I finally reproduced the CVE-2023-39476 Inductive Automation Ignition JavaSerializationCodec Deserialization RCE vulnerability submitted to ZDI by ϻг_ϻε

After two days, I finally reproduced the CVE-2023-39476 Inductive Automation Ignition JavaSerializationCodec Deserialization RCE vulnerability submitted to ZDI by <a href="/steventseeley/">ϻг_ϻε</a>
Y4er (@y4er_chabug) 's Twitter Profile Photo

公开了一些文章 VMware vROPS RCE of java bean y4er.com/posts/vmware-v… VMware vROPS 文件读取到反序列化RCE y4er.com/posts/vmware-v… Apache Geode/VMware GemFire Deserialize RCE y4er.com/posts/apache-g… Trend Micro Mobile Security 认证绕过/文件上传/文件包含 RCE y4er.com/posts/trend-mi…