en
Feedback
@Phantasm_Lab

@Phantasm_Lab

Open in Telegram

- Red x Blue Security - Bug Bounty 💷 💵 - Exploitable tools - Programming Languages - Malware Analysis Youtube: t.ly/TrGo 🇺🇸 🇧🇷 🇪🇸 since 2017 © Parceiros: @TIdaDepressaoOficial @acervoprivado @ReneGadesx @G4t3w4y

Show more
2 974
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
SANS CWE Top 25 Software Errors https://www.sans.org/top25-software-errors/

Ukrainian military agencies, state-owned banks hit by DDoS attacks https://ift.tt/JUODXvp

photo content

Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package On Thursday, December 9th, a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE), by logging a certain string. Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it "Log4Shell" for short. The 0-day was tweeted along with a POC posted on GitHub. It has now been published as CVE-2021-44228. https://www.lunasec.io/docs/blog/log4j-zero-day/

Log4shell Zero-Day Exploit— Full Guide Hello guys! My name is Tuhin Bose (@tuhin1729). I am currently working as a Chief Information Security Officer and Infosec trainer at DSPH. In this write-up, I am going to describe the critical zero-day vulnerability called Log4Shell that existed in the widely used Java logging library Log4j used by millions of Java applications. So without wasting time, let's start: https://infosecwriteups.com/log4shell-zero-day-exploit-full-guide-3a505f0c4248

The Story of an RCE on a Java Web Application It was about two months ago (November 2021) I was invited to a private program. According to their program scope, I decided to hack them for a while. This post is about a vulnerability I’ve found in this company that led to RCE. https://infosecwriteups.com/the-story-of-a-rce-on-a-java-web-application-2e400cddcd1e