c1sc0
@c1sc01
OSCP, OSEP, OSWE, OSED, OSCE3, OffSec, Pentesting, Hacking Enthusiast, #kaeferjaeger
ID: 1065487301323735040
https://hesec.de 22-11-2018 06:09:03
370 Tweet
329 Takipçi
189 Takip Edilen
Another product, another deserialization vulnerability, another RCE from Markus Wulftange: Patch your Telerik Report Server (CVE-2024-6327 & CVE-2024-6096) code-white.com/public-vulnera…
Our crew members Markus Wulftange & frycos discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam's blacklist for CVE-2024-40711 & CVE-2025-23120 as well as further entry points following SinSinology & Piotr Bazydło's blog. Don’t blacklist, replace BinaryFormatter.
I once again did it. Hack The Box accepted my box submission for an insane Linux box. Be sure to play it and have some fun. I am looking forward to feedback. Cheers ✌🏼
Justin Elze big fan of goshs for this type of stuff github.com/patrickhener/g…