Subscribe via feed.
Archive for July, 2022

http://www.sptn.dss.go.th/bas/public/site/images/zbiok/Ox.gif

Posted by deepcore under defacement (No Respond)

http://www.sptn.dss.go.th/bas/public/site/images/zbiok/Ox.gif notified by Moroccan Revolution

Tags:

Windows Defender Remote Credential Guard Authentication Relay Privilege Escalation

Posted by deepcore under exploit (No Respond)

The handling of Windows Defender Remote Credential Guard credentials is vulnerable to authentication relay attacks leading to elevation of privilege or authentication bypass.

Advanced Testimonials Manager 5.6 SQL Injection

Posted by deepcore under exploit (No Respond)

Advanced Testimonials Manager version 5.6 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Ransom Lockbit 3.0 MVID-2022-0621 Code Execution

Posted by deepcore under exploit (No Respond)

Lockbit version 3.0 ransomware looks for and executes DLLs in its current directory. Therefore, we can hijack a DLL, in this case “RstrtMgr.dll”, execute our own code, and terminate the malware pre-encryption. The exploit DLL checks if the current directory is “C:WindowsSystem32” and if not we grab our process ID and terminate. All basic tests […]

Google: Half Of Zero-Day Exploits Linked To Poor Software Fixes

Posted by deepcore under exploit (No Respond)

Ransom Lockbit 3.0 MVID-2022-0621 Code Execution

Posted by deepcore under exploit (No Respond)

Lockbit version 3.0 ransomware looks for and executes DLLs in its current directory. Therefore, we can hijack a DLL, in this case “RstrtMgr.dll”, execute our own code, and terminate the malware pre-encryption. The exploit DLL checks if the current directory is “C:\Windows\System32” and if not we grab our process ID and terminate. All basic tests […]

Stock Management System 2020 SQL Injection

Posted by deepcore under exploit (No Respond)

Stock Management System 2020 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

Paymoney 3.3 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Paymoney version 3.3 suffers from a cross site scripting vulnerability.

DouPHP 1.2 Release 20141027 SQL Injection

Posted by deepcore under exploit (No Respond)

DouPHP version 1.2 Release 20141027 suffers from a remote SQL injection vulnerability.

Ransom Lockbit 3.0 MVID-2022-0620 Buffer Overflow

Posted by deepcore under exploit (No Respond)

Lockbit ransomware version 3.0 apparently now requires a password to execute as noted by “@vxunderground”, but does not properly check bounds for both the -pass and -k arguments. Supplying a long string of characters for either flag will trigger a unicode stack buffer overflow overwriting the ECX register and structured exception handler (SEH).