Reposted by SinSinologyClément Labro @itm4n.bsky.social · 04/12/2024I updated the diagram representing the different Point and Print configurations and their exploitation on my blog. Hopefully, this should provide a better understanding of the whole "PrintNightmare" situation to both defenders and red teamers. 🤞 0188
Reposted by SinSinologyϻг_ϻε @steven.srcincite.io · 26/11/2024I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...srcincite.ioRemote Code Execution with Spring PropertiesRecently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting... 17636
Reposted by SinSinologyBad Sector Labs @badsectorlabs.com · 19/11/2024Arc browser RCE, more Fortinet woes (@sinsinology.bsky.social), PowerHuntShares v2, make_token_cert, BOFs without DFR (@netbiosx.bsky.social), and more! blog.badsectorlabs.com/last-week-in...blog.badsectorlabs.comLast Week in Security (LWiS) - 2024-11-18Arc browser RCE (@RenwaX23), more Fortinet woes (@SinSinology), PowerHuntShares v2 (@_nullbind), make_token_cert (@freefirex2), BOFs without DFR (@netbiosX), and more! 052