Aggregator
.NET 安全基础入门学习知识库
8 months ago
01知识库背景新加入社群的朋友们普遍怀揣着夯实.NET安全基础、寻求清晰学习路径的强烈愿望。这不仅反映了大家对于提升自我技能的热切期待,也揭示了当前网络资源中有关.NET安全基础知识覆盖不足的现状。正
.NET内网实战:通过winlogon进程提升至SYSTEM权限
8 months ago
01阅读须知此文所节选自小报童《.NET 内网实战攻防》专栏,主要内容有.NET在各个内网渗透阶段与Windows系统交互的方式和技巧,对内网和后渗透感兴趣的朋友们可以订阅该电子报刊,解锁更多的报刊内
.NET | SCM权限维持在红队实战中的应用
8 months ago
01阅读须知此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直
A Platform-Agnostic Approach in Cloud Security for Data Engineers
8 months ago
Companies are now turning to data as one of the most important assets in their businesses, and data
CVE-2022-26940 | Microsoft Windows 11/Server 2022 Remote Desktop Protocol Client information disclosure
8 months ago
A vulnerability was found in Microsoft Windows 11/Server 2022 and classified as problematic. Affected by this issue is some unknown functionality of the component Remote Desktop Protocol Client. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2022-26940. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-29102 | Microsoft Windows Server 20H2 up to Server 2019 Failover Cluster information disclosure
8 months ago
A vulnerability was found in Microsoft Windows Server 2012 up to Server 2019. It has been classified as problematic. This affects an unknown part of the component Failover Cluster. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2022-29102. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-29103 | Microsoft Windows up to Server 2022 Remote Access Connection Manager Privilege Escalation
8 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code of the component Remote Access Connection Manager. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2022-29103. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-29104 | Microsoft Windows up to Server 2022 Print Spooler Privilege Escalation
8 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. This issue affects some unknown processing of the component Print Spooler. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2022-29104. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-29108 | Microsoft SharePoint Server 2013 SP1/2016/2019/Subscription Edition Privilege Escalation
8 months ago
A vulnerability, which was classified as critical, was found in Microsoft SharePoint Server 2013 SP1/2016/2019/Subscription Edition. This affects an unknown part. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2022-29108. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2010-0397 | PHP 5.3.1 xmlrpc_decode_request null pointer dereference (EDB-33755 / Nessus ID 75429)
8 months ago
A vulnerability classified as problematic was found in PHP 5.3.1. This vulnerability affects the function xmlrpc_decode_request. The manipulation leads to null pointer dereference.
This vulnerability was named CVE-2010-0397. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-1131 | Knowledgebuilder 2.0.1/2.1.0/2.1.4/3.0.1 index.php page privileges management (EDB-23476 / XFDB-14078)
8 months ago
A vulnerability, which was classified as critical, has been found in Knowledgebuilder 2.0.1/2.1.0/2.1.4/3.0.1. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument page leads to improper privilege management.
This vulnerability is handled as CVE-2003-1131. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
快速定位解析银狐WinOS4.0木马C2配置信息
8 months ago
#恶意软件分析 #银狐
手动快速定位解析银狐WinOS4.0木马C2配置信息
快速定位解析银狐WinOS4.0木马C2配置信息
8 months ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2012-5000 | DZCP Witze Addon 0.9 jokes/index.php id sql injection (EDB-18558 / XFDB-73681)
8 months ago
A vulnerability, which was classified as critical, has been found in DZCP Witze Addon 0.9. Affected by this issue is some unknown functionality of the file jokes/index.php. The manipulation of the argument id with the input 9999999999999999999999999999+union+select+1,1,nick,pwd,1,1+from+dzp_users+where+id=1--+ leads to sql injection.
This vulnerability is handled as CVE-2012-5000. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
派早报:火狐 Firefox 浏览器推出 Orbit AI 助手、百度网页版推出 AI 搜功能等
8 months ago
你可能错过的新鲜事火狐 Firefox 浏览器推出 Orbit AI 助手Mozilla 于 2024 年 12 月 31 日发布博文,宣布为 Firefox 浏览器推出名为 Orbit 的 AI
8Base
8 months ago
cohenido
8Base
8 months ago
cohenido
8Base
8 months ago
cohenido
8Base
8 months ago
cohenido