qt_merlyn1
@qt_merlynn
Learning to have a career in pentesting/red teaming. Blue belt pwn.college | HTB CPTS | CRTO | HTB CWEE 🇻🇳
ID: 1048131250173530112
05-10-2018 08:42:18
1,1K Tweet
361 Takipçi
505 Takip Edilen
Really great post from Christophe Tafani-Dereeper about the menacing "allowPrivilegeEscalation" security context" blog.christophetd.fr/stop-worrying-…
I always recommend the use of Fail2ban for everything, including web services The good news is that it comes with a default config for sshd, which prevents the exploitation of CVE-2024-6387 & brute force attacks in general DigitalOcean has a tutorial digitalocean.com/community/tuto…
Critical XSS in Roundcube webmail⚠ A victim only has to view a malicious email. As reported by ESET Research, APTs have exploited similar vulns in the past to steal government emails. Our announcement: sonarsource.com/blog/governmen… (CVE-2024-42008, CVE-2024-42009, CVE-2024-42010)