ZeroDay UZ (lab)
Open in Telegram
292
Subscribers
No data24 hours
No data7 days
No data30 days
Posts Archive
Repost from Zer0Day Lab
CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity exploit
https://github.com/W01fh4cker/CVE-2024-27198-RCE
https://github.com/Chocapikk/CVE-2024-27198
https://github.com/rapid7/metasploit-framework/pull/18922
Cyberspace Mapping Dork:
Fofa app="JET_BRAINS-TeamCity" ZoomEye app:"JetBrains TeamCity" Hunter.how product.name="TeamCity" Shodan http.component:"teamcity"
Read research: https://www.rapid7.com/blog/post/2024/03/04/etr-cve-2024-27198-and-cve-2024-27199-jetbrains-teamcity-multiple-authentication-bypass-vulnerabilities-fixed/White Snake Stealer update 1.6.1.7
- Record microphone command. - If auto-keylogger is enabled in builder it will save journals on victim pc, then you can list them using 'keylogger journals' command and download them using 'keylogger dump <journal>' - Added tool to restore google account cookies using chrome token. - Added separate tab for chrome tokens. - Chrome tokens extraction fix. - Updated C2 list.
CVE-2024-21413: Microsoft Outlook Leak Hash
https://github.com/duy-31/CVE-2024-21413
#exploit #pentest #redteam #ad
#pestudio pro 9.57 now available with following changes:
. Fix bug in XML report
. Fix bug in libraries detection
. Fix bug in Resources string-tables handling
. Add toggling of language flag
. Extend Certificate detectionCVE-2024-21413: Microsoft Outlook Leak Hash
https://github.com/duy-31/CVE-2024-21413
#exploit #pentest #redteam #ad
