Sign in

Will Dormann is on Mastodon

@wdormann.bsky.social
1.8K followers 253 following 153 posts

I play with vulnerabilities and exploits. While this site initially showed promise, I've grown tired with its lack of improvement. You'll find me @wdormann@infosec.exchange on Mastodon.

PostsRepliesMedia
Will Dormann is on Mastodon @wdormann.bsky.social · 18/08/2026
I will be presenting at THREATCON1 in October, explaining how I figured out how a non-admin user could get code execution as SYSTEM on Windows 11 by way of playing a MIDI file. 😂 threatcon1.org/agenda
020
Will Dormann is on Mastodon @wdormann.bsky.social · 15/12/2025
Social media user double taps image in their web browser... Twitter, Mastodon: Zoom in. BlueSky: Close image, re-open it. 🤦‍♂️
200
Will Dormann is on Mastodon @wdormann.bsky.social · 18/11/2024
Testing multi-posting app Croissant...
210
Will Dormann is on Mastodon @wdormann.bsky.social · 16/11/2024
To those who still have posts remaining on the Nazi site for the sole purpose of being able to search through things that you've said in the past: 1) First download an archive of your data. (There might be a 1-day delay before you get it) x.com/settings/dow...
x.com
x.com
1102
Will Dormann is on Mastodon @wdormann.bsky.social · 16/11/2024
Did everybody enjoy that video streaming marvel that was the Mike Tyson fight last night?
1153
Will Dormann is on Mastodon @wdormann.bsky.social · 14/02/2024
Did you notice that Temu dropped the bucks for *several* superbowl ads? Turns out that their Android app was utilizing an 0day exploit to achieve an advantage over their competition. Totally normal stuff going on here. arstechnica.com/information-...
264
Will Dormann is on Mastodon @wdormann.bsky.social · 13/02/2024
Every Patch Tuesday I'm reminded that in Microsoft's world, "No thanks" means "Ask me again later".
050
Will Dormann is on Mastodon @wdormann.bsky.social · 11/02/2024
Dear documentation authors, You... You do know that people can't click buttons on paper, right?
040
Will Dormann is on Mastodon @wdormann.bsky.social · 09/02/2024
watchTowr: Ivanti Connect Secure CVE-2024-22024 - Are We Now Part Of Ivanti? labs.watchtowr.com/are-we-now-p...
031
Will Dormann is on Mastodon @wdormann.bsky.social · 03/02/2024
Ivanti Connect Secure is vulnerable to xmltooling CVE-2023-36661. How was this handled? HackerOne assigned CVE-2024-21893 to capture this. Nobody knows how CVE works, and nobody enforces any rules. 🤦‍♂️ twitter.com/stephenfewer...
241
Will Dormann is on Mastodon @wdormann.bsky.social · 02/02/2024
We all know that the Ivanti ICT cannot be trusted on a maybe-compromised device. Even the external ICT. But what about this recommended factory reset? That restores it to the state when you got it from the factory, right? Get real. Please avoid magical thinking, folks 🪄 (insert desire for GIFs here)
100
Will Dormann is on Mastodon @wdormann.bsky.social · 02/02/2024
Got a cheap toy drone, and it has... Fake antennas! I mean, why bother?
400
Will Dormann is on Mastodon @wdormann.bsky.social · 31/01/2024
Hey everybody there are unfixed vulnerabilities in Ivanti Connect Secure! No, not those (which are STILL unfixed). The new ones: CVE-2024-21888 (privesc to admin) and CVE-2024-21893 (SSRF to access "restricted resources") mitigation.release.20240126.5.xml forums.ivanti.com/s/article/KB...
CVE-2024-21888	A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.	8.8	AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2024-21893	A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.	8.2	AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
162
Will Dormann is on Mastodon @wdormann.bsky.social · 28/01/2024
Apparently the Intel Wi-Fi driver for Linux isn't terribly reliable. Which makes me wonder... what's the go-to Wi-Fi 6E adapter that people use in the Linux world these days? Or has the Linux world not quite embraced Wi-Fi yet, and reliable requires wired? bugzilla.kernel.org/show_bug.cgi...
311
Will Dormann is on Mastodon @wdormann.bsky.social · 25/01/2024
I wonder why Atlassian doesn't have any security documents anymore. No? Just me?
100
Will Dormann is on Mastodon @wdormann.bsky.social · 25/01/2024
Just 3 adjacent passengers on a Delta flight, suggests said airline.
020
Will Dormann is on Mastodon @wdormann.bsky.social · 23/01/2024
Connect Secure customers should: "stop pushing configurations to appliances with the [workaround] XML in place... it stops some key web services from functioning, and stops the mitigation from functioning" Surely no regrets with Ivanti purchases here. forums.ivanti.com/s/article/KB...
Important: customers should stop pushing configurations to appliances with the XML in place, and not resume pushing configurations until the appliance is patched. When the configuration is pushed to the appliance, it stops some key web services from functioning, and stops the mitigation from functioning. This only applies to customers who push configurations to appliances, including configuration pushes through Pulse One or nSA. This can occur regardless of a full or partial configuration push.
010
Will Dormann is on Mastodon @wdormann.bsky.social · 20/01/2024
Only today did Google Nest send me a warning that my furnace started experiencing problems on January 9. Thanks for the tip, but guess what? I started noticing that there was trouble when... the house WAS COLD! Why was this information held back for a week and a half? 🤦‍♂️
120
Will Dormann is on Mastodon @wdormann.bsky.social · 18/01/2024
Python: If you choose to explicitly enable shell=True, it's the application's responsibility to avoid shell injection vulnerabilities. Ivanti: (Hold my beer) YOLO!!!!!!!1
def get(self, url_suffix=None, node_name=None):
        if request.path.startswith("/api/v1/license/keys-status"):
            try:
                dsinstall = os.environ.get("DSINSTALL")
                if node_name == None:
                    node_name = ""
                proc = subprocess.Popen(
                    dsinstall
                    + "/perl5/bin/perl"
                    + " "
                    + dsinstall
                    + "/perl/getLicenseCapacity.pl"
                    + " getLicenseKeys "
                    + node_name,
                    shell=True,
                    stdout=subprocess.PIPE,
                )
                output, errors = proc.communicate()Security Considerations
Unlike some other popen functions, this implementation will never implicitly call a system shell. This means that all characters, including shell metacharacters, can safely be passed to child processes. If the shell is invoked explicitly, via shell=True, it is the application’s responsibility to ensure that all whitespace and metacharacters are quoted appropriately to avoid shell injection vulnerabilities. On some platforms, it is possible to use shlex.quote() for this escaping.
120
Will Dormann is on Mastodon @wdormann.bsky.social · 16/01/2024
Ivanti Connect Secure CVE-2023-46805: You can access resources by prefixing with any number of no-auth resources and directory traversal to where you want to go. CVE-2024-21887: Command injection with certain targets. Paying customers can mitigate the former. attackerkb.com/topics/AdUh6...
152
Will Dormann is on Mastodon @wdormann.bsky.social · 16/01/2024
CVE wonders: Apache created CVE-2023-49070 to capture: "Our OFBiz product has Apache XML-RPC, which is vulnerable to CVE-2019-17570". This seems... wrong? If every vendor created a new CVE to capture "Hey, we use library <foo> that already has a CVE", how can this possibly scale?
120
Will Dormann is on Mastodon @wdormann.bsky.social · 12/01/2024
So apparently starting with Linux 5.18, ASLR is weakened for 64-bit executables, and absolutely BROKEN (i.e. not present) for 32-bit executables when the library is 2MB or larger. Oops? 🤦‍♂️ zolutal.github.io/aslrnt/ (Insert desire for BlueSky to support animated GIFs here)
1118
Will Dormann is on Mastodon @wdormann.bsky.social · 11/01/2024
Let's use Ivanti VPN CVE-2024-21887 CVE-2023-46805 as an example of magical thinking. If you think your web server was compromised, would you use a remote web browser to confirm whether this is true? This is what the "external" ICT workflow does. Thoughts and prayers to customers.
The ICT in a nutshell
- Show me your admin page
- Here it is (trust me)
- Please run this ICT package
- OK, I will (trust me)
- I'm not compromised (trust me)Rickrolled external ICT resultsWe have seen evidence of threat actors attempting to manipulate Ivanti’s internal integrity checker (ICT). Out of an abundance of caution, we are recommending that all customers run the external ICT. We have added new functionality to the external ICT that will be incorporated into the internal ICT in the future.Shia LeBouf Magic
031
Will Dormann is on Mastodon @wdormann.bsky.social · 21/10/2023
I'll admit it. I'm giddy.
FLUID KARMA
WITH DIRECTOR RICHARD KELLY
OCTOBER 21, 2023
000
Will Dormann is on Mastodon @wdormann.bsky.social · 08/10/2023
Well, forcing Twitter users to now invent their own headlines is going exactly as absolutely everyone could have predicted. I really wish this exodus would happen quicker than the current pace. 😕
NEW SCOOP: evidence showing elon musk is a pedophile mounting quickly
060
Will Dormann is on Mastodon @wdormann.bsky.social · 18/08/2023
Meanwhile on the smoldering remains of the Twitter site: Elmo finds a way to make it better for the worst people on the planet. I also love how it says "subscribed", which I'm clearly not, and have had the account blocked for years.
210
Will Dormann is on Mastodon @wdormann.bsky.social · 02/08/2023
It's so embarrassingly weird over at that other site. My hope is that BlueSky will get to the point where it's open to the public before Twitter explodes and/or the exodus actually happens. Otherwise, it'll just be a fun little experiment.
Tab for X (formerly Twitter) with 3 X's
130
Will Dormann is on Mastodon @wdormann.bsky.social · 01/08/2023
The in-app purchases part of the Twitter app in the iOS App Store is (unintentionally?) hilarious. Sign me up?
In-App Purchases
Twitter Blue (1 Month)
@elonmusk Subscription (1 Month)
Twitter Blue (1 Year)
@FatKidDeals Subscription (1 Month)
@pulte Subscription (1 Month
@Jake_
_Wujastyk Subscription (1 Mon...
@dreamwastaken Subscription (1 Month)
@Rainmaker1973 Subscription (1 Month)
@shreyas Subscription (1 Month)
@MrBeast Subscription (1 Month)
$11.00
$4.00
$114.99
$1.00
$2.99
$10.00
$5.00
$2.00
$9.99
$5.00
010
Will Dormann is on Mastodon @wdormann.bsky.social · 24/07/2023
Meanwhile on the other site that used to be called Twitter, the new logo is apparently a standard Unicode character. The effort they're putting in over there is just... Chef's kiss.
New X logoUnicode U+1D54F
151
Will Dormann is on Mastodon @wdormann.bsky.social · 11/07/2023
"Users want federation!" Meanwhile, on that weird Twitter alternative site... One of these is actually me. I think.
Mastodon search for: Will Dormann
Lots of identical-looking results
192
Will Dormann is on Mastodon @wdormann.bsky.social · 02/07/2023
Microsoft saying that they protect against BYOVD attacks is a lie through omission. The part omitted: You need to be an admin to bring a driver, and it need not be vulnerable to do whatever they want. Microsoft admits that there is no security boundary between an admin user and the kernel. 🤦‍♂️
020
Will Dormann is on Mastodon @wdormann.bsky.social · 18/05/2023
If you're not logged in to Twitter (e.g in a clean Incognito window) you get not one, but TWO posts from Supreme Leader right at the top. Imagine being the engineer that implemented this narcissism-fulfilling feature. 🤦‍♂️
030
Reposted by Will Dormann is on Mastodon
SwiftOnSecurity @swiftonsecurity.com · 05/05/2023
610615
Will Dormann is on Mastodon @wdormann.bsky.social · 10/05/2023
Normal enter after this line. Shift+enter after this line.This post should have 3 lines of text.
141
Will Dormann is on Mastodon @wdormann.bsky.social · 10/05/2023
I'll be presenting at this year's GRIMMCon 0x8 on the topic of Crassus.The tool is a variant of Accenture's Spartacus, but enhanced and simplified to the point of being suspiciously easy to find Windows LPEs. The conference is virtual + free, so why not?Register: bit.ly/3ovordw
010
Will Dormann is on Mastodon @wdormann.bsky.social · 09/05/2023
Remember when Twitter added link shorteners? example.com/?LOL=LOLOLOLOLOLOLOLOLO… d
000
Will Dormann is on Mastodon @wdormann.bsky.social · 09/05/2023
49 vulnerabilities in today's Patch Tuesday set, 2 of which are being exploited in the wild: CVE-2023-24932 : SecureBoot bypass CVE-2023-29336 : Win32k EoP
[+] Microsoft Patch Tuesday Stats
[+] https://github.com/Immersive-Labs-Sec/msrc-api
[+] May 2023 Security Updates
[+] Found a total of 49 vulnerabilities
  [-] 8 Elevation of Privilege Vulnerabilities
  [-] 4 Security Feature Bypass Vulnerabilities
  [-] 12 Remote Code Execution Vulnerabilities
  [-] 8 Information Disclosure Vulnerabilities
  [-] 5 Denial of Service Vulnerabilities
  [-] 1 Spoofing Vulnerabilities
  [-] 11 Edge - Chromium Vulnerabilities
[+] Found 2 exploited in the wild
  [-] CVE-2023-29336 - 6.8 - Win32k Elevation of Privilege Vulnerability
  [-] CVE-2023-24932 - 6.2 - Secure Boot Security Feature Bypass Vulnerability
[+] Highest Rated Vulnerabilities
  [-] CVE-2023-24941 - 8.5 - Windows Network File System Remote Code Execution Vulnerability
  [-] CVE-2023-24943 - 8.5 - Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
[+] Found 8 vulnerabilites more likely to be exploited
  [-] CVE-2023-24941 -- Windows Network File System Remote Code E
143
Will Dormann is on Mastodon @wdormann.bsky.social · 09/05/2023
Left: LOLDrivers SHA256 AuthentihashesRight: Microsoft driver block list SHA256 Authentihashes When I started looking last fall, MS driver blocking was simply broken in *multiple* ways. Perhaps it's now worth looking at what kind of a subset of known vulnerable drivers it is! 🤔
WinMerge comparison of LOLDrivers list vs. Microsoft recommended driver block rules list. LOLDrivers has WAY more authentihashes.
010
Will Dormann is on Mastodon @wdormann.bsky.social · 09/05/2023
LOLDrivers 1.0 has dropped: loldrivers.io This list enumerates 593 unique SHA256 Authentihashes for vulnerable drivers. Of this list, only 56 are on the Microsoft recommended driver block rules.🤔
021
Will Dormann is on Mastodon @wdormann.bsky.social · 01/05/2023
Elmo: What's that box do? It uses a lot of electricity. Remaining Twitter staff: <crickets> Elmo: Shut. It. Down.
162
Will Dormann is on Mastodon @wdormann.bsky.social · 28/04/2023
Other BlueSky wonders: - Once this exits beta or whatever it is now, will posts be accessible outside of this walled garden? - If so, if a user changes their handle, presumably links to their posts will redirect to what their current handle is? 🤔
100
Will Dormann is on Mastodon @wdormann.bsky.social · 25/04/2023
Random wonder: I suspect that some folks are here to take cover from the blue check dumpster fire on that other site. Where can I read up on what BlueSky aims to do to help prevent impersonation and maybe other troubles that plague Twitter?
120
Will Dormann is on Mastodon @wdormann.bsky.social · 24/04/2023
Since we are doing introductions around here: I've worked with vulnerabilities at the CERT/CC for nearly 20 years, up until around when the CERT/CC stopped being a thing. I'm curious how exploits work, and what can be done to stop them from working. I like sharing what I'm working on.
011