Kai Ullrich (@kaidentity) 's Twitter Profile
Kai Ullrich

@kaidentity

ID: 1121260424

calendar_today26-01-2013 07:29:16

14 Tweet

79 Takipçi

25 Takip Edilen

Chris Frohoff (@frohoff) 's Twitter Profile Photo

Write-ups on three recent WebLogic #javadeser RCEs (translated from chinese): translate.google.com/translate?sl=a… translate.google.com/translate?hl=e…

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

It is always good to take a 2nd look at existing vulns. So Markus Wulftange found a new rock-solid exploitation technique for the Telerik UI framework (hint: affects an Avast product ;) Enjoy: codewhitesec.blogspot.com/2019/02/teleri… #CVE-2017-11317

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

Once upon a time there was a #Sophos XG Firewall N-day that had Ramoliks and niph dig deep until they got RCE, a 0-day and a comprehensive blog post. #CVE-2020-12271 #CVE-2020-15504 codewhitesec.blogspot.com/2020/07/sophos…

Brandoooo 🚀 (@rocketsarefun_) 's Twitter Profile Photo

@TwitterSupport I truly cannot fathom why this access would ever even exist. This is like an employee having access to unencrypted credit card or bank account numbers. Companies know not to do this. How did Twitter not know this was unacceptably risky??

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

Unauth'd admin access to #SAP #Netweaver? Our very own Kai Ullrich has you covered, see #CVE-2021-21481 and SAP Security Note 3022422. Better patch than sorry. Our customers got their heads-up already and we'll publish a detailed blog post when appropriate.

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

How the search for deser bugs in #SAP sent Kai Ullrich down a rabbit hole where he winded up stumbling upon a completely unrelated unauth'ed admin access #CVE-2021-21481 codewhitesec.blogspot.com/2021/06/about-…

CODE WHITE GmbH (@codewhitesec) 's Twitter Profile Photo

Interested in Advanced Java Exploitation? Check out our new blog post about exploiting Adobe ColdFusion codewhitesec.blogspot.com/2018/03/exploi…