Murat (@manfromkz) 's Twitter Profile
Murat

@manfromkz

Pentester | OSCP | eWPTXv2 | Master of Computer Science

ID: 1337751609749737473

linkhttp://murat.one calendar_today12-12-2020 13:30:22

21 Tweet

21 Followers

7 Following

Murat (@manfromkz) 's Twitter Profile Photo

CVE-2020-29139, CVE-2020-29140, CVE-2020-29142, CVE-2020-29143. Found multiple SQL injections in OpenEMR 6.0.0-dev, 5.0.2(5). murat.one/?p=70 murat.one/?p=86 murat.one/?p=90 murat.one/?p=94 Thanks to OpenEMR for the quick response and fixes!

Murat (@manfromkz) 's Twitter Profile Photo

Now I am an eWPTX2! The exam was exciting! Thanks to @eLearnSecurity for the opportunity to test my knowledge under extreme conditions! #elearnsecurity #ewptx

Now I am an eWPTX2!
The exam was exciting! Thanks to @eLearnSecurity for the opportunity to test my knowledge under extreme conditions!

#elearnsecurity #ewptx
Murat (@manfromkz) 's Twitter Profile Photo

Found an unauthenticated SQL injection in Chamilo LMS. Thanks to Asociación Chamilo developers, the vuln was fixed quickly! But unfortunately MITRE is ignoring me, and yet didn't assign CVE id for this :( Details at murat.one/?p=118 #research #security #chamilo #mitre

Murat (@manfromkz) 's Twitter Profile Photo

The only IT / InfoSec / *OPS open conference in Kazakhstan without advertising and vendors is coming (2 weeks left). Interesting reports from experienced specialists. Hurry up to register (at sysconf.io)! #sysconf #security #cybersecurity #opensysconf #Almaty

Murat (@manfromkz) 's Twitter Profile Photo

Когда я говорю, что работаю в сфере информационной безопасности, многие думают, что я охранник. Это все что вам надо знать про cybersecurity awareness в народе. #иб #инфосек #Awareness #CyberSec #zeroday

Murat (@manfromkz) 's Twitter Profile Photo

Мы победили в третий раз подряд на The Standoff 365! #standoff #infosec #phdays #ctf #codeby #nitroteam

Мы победили в третий раз подряд на The Standoff 365!

#standoff #infosec #phdays #ctf #codeby #nitroteam
Murat (@manfromkz) 's Twitter Profile Photo

Всем, у кого версия Moodle с 3.11 по 3.11.4, нужно срочно обновиться. В сети гуляет эксплойт, который позволяет получить доступ к базе данных (SQL-инъекция). Отмечайте IT-отделы университетов. #moodle #security #exploit github.com/numanturle/CVE…

Murat (@manfromkz) 's Twitter Profile Photo

Опять проблемы с принтерами у Microsoft. Опубликован эксплойт (не проверял) на CVE-2022–22718, который позволяет поднять права до SYSTEM и добавить нового администратора. Base score по CVSS 8.3 из 10. t.me/c/1498912552/18 #exploit #microsoft

Murat (@manfromkz) 's Twitter Profile Photo

Details of Spring4shell were published. No patch. 2022, please, stop! cyberkendra.com/2022/03/spring… #exploit #0day #CyberSecurity #rce #java #spring

Details of Spring4shell were published. No patch. 2022, please, stop!

cyberkendra.com/2022/03/spring…

#exploit #0day #CyberSecurity #rce #java #spring
Murat (@manfromkz) 's Twitter Profile Photo

I've found several vulnerabilities (CVE-2022-29938, CVE-2022-29939, CVE-2022-29940) in LibreHealth EHR 2.0.0. Write-up: murat.one/?p=160 #security #zeroday #librehealth #exploit #poc

Murat (@manfromkz) 's Twitter Profile Photo

I've found an SSRF vulnerability in the Tumbler plugin for XFCE that works by default in the latest Kali Linux, Debian XFCE, etc. murat.one/?p=187 #xfce #kali #debian #ssrf #security #exploit #linux