PT SWARM
Open in Telegram
Positive Technologies Offensive Team: twitter.com/ptswarm This is the channel where we share articles/vulnerabilities/scripts/etc, not necessarily authored by us, that we find interesting
Show more6 782
Subscribers
No data24 hours
-47 days
-430 days
Posts Archive
6 782
🚀 We’re launching Positive Hack Talks! These are worldwide one-day cybersecurity meetups featuring insights from our speakers and local experts!
📍 Bengaluru, India 🇮🇳
🗓 Oct 11, 2024
Got something to share or want to join the event? Sign up today! ⬇️
https://phtalks.ptsecurity.com/
6 782
⚠️ We've confirmed critical CVE-2024-45519 in Zimbra!
SMTP-based vulnerability in postjournal service allows unauthenticated attackers to inject commands under zimbra user.
✅ Update your software ASAP to avoid exploitation!
6 782
World of SELECT-only PostgreSQL Injections: (Ab)using the filesystem
👤 by Maksym Vatsyk
In this article, author managed to escalate the impact of a seemingly very restricted SQL injection to a critical level by recreating DELETE and UPDATE statements from scratch via the direct modification of the DBMS files and data, and develop a novel technique of escalating user permissions!
Excessive server file read/write permissions can be a powerful tool in the wrong hands. There is still much to discover with this attack vector, but he hopes you've learned something useful today.
📝 Contents:
● Introduction
● PostgreSQL storage concepts
● Updating the PostgreSQL data without UPDATE
● SELECT-only RCE
● Conclusions
● References
● Source code
http://phrack.org/issues/71/8.html#article
6 782
📱 Check out our new article on Android Jetpack Navigation by our researcher @OxFi5t!
Learn how to exploit implicit deep links and hijack user sessions. A must-read for Android devs and mobile security researchers!
https://swarm.ptsecurity.com/android-jetpack-navigation-go-even-deeper/
6 782
🥷🏻 DEFCON 32 is over and you can find the links on the interesting researches (in our view) below:
🛑SQL Injection Isn't Dead. Smuggling Queries at the Protocol Level
🛑A TWO-PART SAGA: CONTINUING THE JOURNEY OF HACKING MALWARE C2S
🛑Outlook Unleashing RCE Chaos: CVE-2024-30103 & CVE-2024-38021
🛑Gotta Cache ‘em all: Bending the rules of web cache exploitation
🛑NTLM: the last ride
🛑HookChain: a new perspective for Bypassing EDR Solutions
🛑sshamble: Unexpected Exposures in SSH
🛑MaLDAPtive LDAP Obfuscation Deobfuscation and Detection
🛑Iconv, set the charset to RCE: exploiting the glibc to hack the PHP engine
🛑Techniques for Creating Process Injection Attacks with Advanced Return-Oriented Programming
All presentations from DEFCON32: https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/
6 782
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
👤 by Orange Tsai
This article explores architectural issues within the Apache HTTP Server, highlighting several technical debts within Httpd, including 3 types of Confusion Attacks, 9 new vulnerabilities, 20 exploitation techniques, and over 30 case studies. The content includes, but is not limited to:
🛑How a single
? can bypass Httpd’s built-in access control and authentication.
🛑How unsafe RewriteRules can escape the Web Root and access the entire filesystem.
🛑How to leverage a piece of code from 1996 to transform an XSS into RCE.
📝 Contents:
● Before the Story
● How Did the Story Begin?
● Why Apache HTTP Server Smells Bad?
● A Whole New Attack — Confusion Attack
• Filename Confusion
• DocumentRoot Confusion
• Handler Confusion
• Other Vulnerabilities
● Future Works
● Conclusion
https://blog.orange.tw/2024/08/confusion-attacks-en.html6 782
Splitting the email atom: exploiting parsers to bypass access controls
👤 by Gareth Heyes
Some websites parse email addresses to extract the domain and infer which organisation the owner belongs to. This pattern makes email-address parser discrepancies critical. Predicting which domain an email will be routed to should be simple, but is actually ludicrously difficult - even for 'valid', RFC-compliant addresses.
In this paper author is going to show you how to turn email parsing discrepancies into access control bypasses and even RCE.
This paper is accompanied by a free online CTF, so you'll be able to try out your new skill set immediately.
📝 Contents:
● Introduction
● Creating email domain confusion
● Parser discrepancies
● Punycode
● Methodology/Tooling
● Defence
● Materials
● CTF
● Takeaways
● Timeline
● References
https://portswigger.net/research/splitting-the-email-atom
6 782
🤖 New article by our researcher Nikita Petrov: "From opcode to code: how AI chatbots can help with decompilation".
Read the blog post: https://swarm.ptsecurity.com/from-opcode-to
6 782
🔥 Our researcher Arseniy Sharoglazov has discovered two unauthenticated RCE vulnerabilities in Xerox WorkCentre!
Read more: https://swarm.ptsecurity.com/inside-xerox-workcentre-two-unauthenticated-rces/
6 782
😀 Simple way to bypass a WAF in Command Injections!
Also helps with length restrictions! 🚀
Source code
6 782
✅ Did you know that XSLT injection can lead to file creation?
Check the tip!
High resolution tip and the .xsl file
6 782
🧧 Our researcher Igor Sak-Sakovskiy has discovered an XXE in Chrome and Safari by ChatGPT!
Bounty: $28,000 💸
Here is the write-up 👉 https://swarm.ptsecurity.com/xxe-chrome-safari-chatgpt/
6 782
Exploiting CVE-2024-32002: RCE via git clone
👤 by Amal Murali
A new RCE in Git caught researcher's attention on a recent security feed, labeled CVE-2024-32002. The idea of an RCE being triggered through a simple
git clone command fascinated him. Given Git’s ubiquity and the widespread use of the clone command, he was instantly intrigued. Could something as routine as cloning a repository really open the door to remote code execution? His curiosity was piqued, and he had to investigate. Plus, who doesn’t want an excuse to break stuff in the name of research?
What’s the fun in just reading about an RCE? He wanted to see it wreak havoc – maybe launch a rogue application, or worse, wipe out his directories. At least, he wanted it to pop his calculator. In this post, He will walk you through his journey of reversing the Git RCE, from initial discovery to crafting a working exploit.
📝 Contents:
● Basic Reconnaissance
• git under the hood
• Symlinks
● Digging into the source code
• Inspecting builtin/submodule--helper.c
• Inspecting t/t7406-submodule-update.sh
● Piecing everything together
● Getting the RCE
• Weaponizing a GitHub repository
● Working PoC
https://amalmurali.me/posts/git-rce/6 782
🏜 We're live at GISEC2024 in Dubai, UAE!
Join PT SWARM for a master class on soldering your smart 🥤 opener or enjoy our ATM hacking contest! 📠
Catch us until April 25 at 5 PM! 🇦🇪
6 782
CVE-2024-3400 - Technical Analysis
👤 by Rapid7
Rapid7’sanalysis of this vulnerability has identified that the exploit is in fact an exploit chain, consisting of two distinct vulnerabilities: an arbitrary file creation vulnerability in the GlobalProtect web server, for which no discrete CVE has been assigned, and a command injection vulnerability in the device telemetry feature, designated as CVE-2024-3400.
If device telemetry is disabled, it is still possible to leverage the file creation vulnerability; at time of writing, however, Rapid7 has not identified an alternative way to leverage the file creation vulnerability for successful exploitation.
📝 Contents:
● Overview
● Analysis
• Rooting the Device
• Diffing the Patch
• Arbitrary File Creation
• Command Injection Exploitation
● IOCs
● Remediation
https://attackerkb.com/topics/SSTk336Tmf/cve-2024-3400/rapid7-analysis
6 782
🏭 We've tested the new RCE in Microsoft Outlook (CVE-2024-21378) in a production environment and confirm it works well!
A brief instruction for red teams:
1. Compile our enhanced DLL;
2. Use NetSPI's ruler and wait!
No back connect required!
🔥 📐📏
6 782
🚀 We're excited to unveil a new tool developed by our researcher @kiber_io: APKd. Now, you can effortlessly download APKs from AppGallery, APKPure, and RuStore directly from the terminal!
Check it out here: https://github.com/kiber-io/apkd
6 782
📱 New article by our researcher Andrey Pesnyak: "Android Jetpack Navigation: Deep Links Handling Exploitation"
Read about a flaw that allows an attacker to launch any fragments in a navigation graph associated with an exported activity.
https://swarm.ptsecurity.com/android-jetpack-navigation-deep-links-handling-exploitation/
6 782
🎁 Source Code Disclosure in IIS 10.0! Almost.
There is a method to reveal the source code of some .NET apps. Here's how it works.
👉 https://swarm.ptsecurity.com/source-code-disclosure-in-asp-net-apps/
6 782
CVE-2024-27198 and CVE-2024-27199: JetBrains TeamCity Multiple Authentication Bypass Vulnerabilities (FIXED)
👤 by Rapid7
In February 2024, Rapid7’s vulnerability research team identified two new vulnerabilities affecting JetBrains TeamCity CI/CD server:
• CVE-2024-27198 is an authentication bypass vulnerability in the web component of TeamCity that arises from an alternative path issue (CWE-288) and has a CVSS base score of 9.8 (Critical).
• CVE-2024-27199 is an authentication bypass vulnerability in the web component of TeamCity that arises from a path traversal issue (CWE-22) and has a CVSS base score of 7.3 (High).
📝 Contents:
● Overview
● Impact
● Remediation
● Analysis
• CVE-2024-27198
• CVE-2024-27199
● Rapid7 customers
● Timeline
https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/
