Aggregator
HackTheBox OneTwoSeven:从 SFTP 软链接到 APT 软件包注入的完整渗透链
1 week 5 days ago
本文记录了 HackTheBox 靶机 OneTwoSeven 的完整渗透过程。攻击链从端口扫描与 Web 信息搜集开始,发现目标开放 SSH、HTTP 以及仅允许本地访问的 60080 管理端口。随后利用 SFTP 提供的软链接功能绕过目录限制,读取系统敏感文件与 Vim swap 文件,恢复后台登录源码并获得管理员凭据。通过 SSH 本地端口转发访问内部管理后台后,进一步分析插件管理逻辑,利用
Наследие Хокинга, Пенроуза и Зельдовича. Черную дыру воспроизвели в лаборатории США
1 week 5 days ago
Эксперимент физиков доказал, что экстремальные космические процессы можно изучать на лабораторном столе.
NEW2CTI | Beyond the Feed: CTI That Matters to Business
1 week 5 days ago
SANS Digital Forensics and Incident Response
Anubis
1 week 5 days ago
You must login to view this content
cohenido
Anubis
1 week 5 days ago
You must login to view this content
cohenido
Anubis
1 week 5 days ago
You must login to view this content
cohenido
Everest
1 week 5 days ago
You must login to view this content
cohenido
DragonForce
1 week 5 days ago
You must login to view this content
cohenido
CVE-2026-15543 | Tenda CH22 1.0.0.1 /goform/CertListInfo formCertListInfo Name buffer overflow
1 week 5 days ago
A vulnerability was found in Tenda CH22 1.0.0.1 and classified as critical. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in buffer overflow.
This vulnerability is reported as CVE-2026-15543. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
DragonForce
1 week 5 days ago
You must login to view this content
cohenido
CVE-2026-15542 | will-moss Isaiah up to 1.36.9 Websocket Connection Authentication app/main.go improper authentication (Issue 33)
1 week 5 days ago
A vulnerability has been found in will-moss Isaiah up to 1.36.9 and classified as critical. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication.
This vulnerability is documented as CVE-2026-15542. The attack can be initiated remotely. There is not any exploit available.
The pull request to fix this issue awaits acceptance.
vuldb.com
CVE-2026-15541 | will-moss Isaiah up to 1.36.9 Master Websocket server.go Server.Handle Agent authorization (Issue 34)
1 week 5 days ago
A vulnerability, which was classified as critical, was found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization.
This vulnerability is registered as CVE-2026-15541. It is possible to launch the attack remotely. No exploit is available.
The pull request to fix this issue awaits acceptance.
vuldb.com
D1R New Threat Actor
1 week 5 days ago
You must login to view this content
cohenido
Submit #855077: Tenda CH22 V1.0.0.1 Buffer Overflow [Accepted]
1 week 5 days ago
Submit #855077 / VDB-377893
ysnysn0121
CTF PWN入门实战|从栈溢出到ret2libc——从零到拿Shell的全过程
1 week 5 days ago
pwn的一点心得体会
D1R
1 week 5 days ago
You must login to view this content
cohenido
Submit #855075: will-moss Isaiah 1.36.9 CWE-287 Improper Authentication [Accepted]
1 week 5 days ago
Submit #855075 / VDB-377892
Dem0000000
PWN从入门到精通(结合第四届黄河流域挑战赛)
1 week 5 days ago
很荣幸可以主导这个比赛pwn方向的命题,结合核心知识点进行了命题
D1R
1 week 5 days ago
You must login to view this content
cohenido