Sign in

SinSinology

@sinsinology.bsky.social
250 followers 65 following 0 posts

Pwn2Own 20{22,23,24,24.5}, i look for 0-Days but i find N-Days & i chase oranges 🍊 summoning.team

PostsRepliesMedia
Reposted by SinSinology
Clément Labro @itm4n.bsky.social · 04/12/2024
I updated the diagram representing the different Point and Print configurations and their exploitation on my blog. Hopefully, this should provide a better understanding of the whole "PrintNightmare" situation to both defenders and red teamers. 🤞
Diagram representing the various Windows Point and Print configurations that reintroduce the PrintNightmare exploit variants.
0188
Reposted by SinSinology
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
Reposted by SinSinology
Bad Sector Labs @badsectorlabs.com · 19/11/2024
Arc browser RCE, more Fortinet woes (@sinsinology.bsky.social), PowerHuntShares v2, make_token_cert, BOFs without DFR (@netbiosx.bsky.social), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2024-11-18
Arc browser RCE (@RenwaX23), more Fortinet woes (@SinSinology), PowerHuntShares v2 (@_nullbind), make_token_cert (@freefirex2), BOFs without DFR (@netbiosX), and more!
052