dozer (@dozernz) 's Twitter Profile
dozer

@dozernz

🇳🇿 hacker / "security researcher" / pentester / redteam / bug bounty. tweets are individual capacity

ID: 3302818014

linkhttp://dozer.nz calendar_today01-08-2015 00:49:56

126 Tweet

970 Followers

483 Following

dozer (@dozernz) 's Twitter Profile Photo

Achieved POC for CVE-2020-36239 (Jira Datacenter RCE). Took a bit longer than I thought and there's probably an easier way but got it in the end 😅

Achieved POC for CVE-2020-36239 (Jira Datacenter RCE).

Took a bit longer than I thought and there's probably an easier way but got it in the end 😅
dozer (@dozernz) 's Twitter Profile Photo

Added a new blog post on how I developed a proof of concept exploit for the Jira DC RCE (CVE-2020-36239), including what I did wrong along the way :) dozer.nz/posts/CVE-2020…

Pulse Security NZ (@pulsesecuritynz) 's Twitter Profile Photo

Release day! Denis found some issues with ZeroTier that allow an attacker to gain access to private networks. Full advisory available at pulsesecurity.co.nz/advisories/Zer…

Nils Ole Timm (@firzen14) 's Twitter Profile Photo

firzen.de/building-a-poc… My writeup for CVE-2021-40438. I tried to describe my process and the rationale behind publishing a PoC and explanation. Update your Apache and implement sensible filters folks. #infosec #hacking #CVE

dozer (@dozernz) 's Twitter Profile Photo

The video of my DEF CON talk about hacking Aruba Networks products is now available on YouTube: youtube.com/watch?v=kMgXtu… Thanks to DEF CON for a great experience! #DEFCON30

Pulse Security NZ (@pulsesecuritynz) 's Twitter Profile Photo

Dynamic analysis is awesome, and we use it to understand target systems and hunt for bugs. @0x446f49 has written up some tricks for debugging dotnet targets, inspired by dozer's write-up for similar techniques in Java. pulsesecurity.co.nz/articles/dotne…

dozer (@dozernz) 's Twitter Profile Photo

FYI: The policy plugin in ROADtools now includes IP addresses for named locations - they was already being collected into the database but not displayed. Thanks Dirk-jan for merging my PR github.com/dirkjanm/ROADt…

dozer (@dozernz) 's Twitter Profile Photo

My latest CVEs: Straightforward preauth* RCE as well as a separate bug chain for preauth* -> RCE in Ivanti EPMM forums.ivanti.com/s/article/Secu… *config dependent Details soon!