Aggregator
2018HCTF-share
8 months 3 weeks ago
本文首发先知社区,文章链接:https://xz.aliyun.com/t/3258
这次比赛感觉比较有意思的一道题。2019 HCTF-share
丶诺熙
2019DDCTF writeup
8 months 3 weeks ago
本文首发先知社区,文章链接:https://xz.aliyun.com/t/4862
最近打了打DDCTF,本来是无聊打算水一波。最后竟然做high了,硬肛了几天..
以下为本次比赛web题目的WriteUp:
丶诺熙
近两次比赛遇到的node题目简析
8 months 3 weeks ago
最近水了水国际赛(摸鱼选手),两次比赛都出现了node的题目。感觉挺有意思的,拿来分析一下。
- HackTM CTF 2020 - Draw with us
- nullcon HackIM 2020 - split second
- 自己出的 - node game
丶诺熙
Hexadecimal analysis on Mac - FNDRERIK@
8 months 3 weeks ago
Hexadecimal analysis on Mac - FNDRERIK@
British telecoms giant BT confirms attempted cyberattack after ransomware gang claims hack
8 months 3 weeks ago
British telecoms giant BT confirms attempted cyberattack after ransomware gang claims hack
New DroidBot Android banking malware spreads across Europe
8 months 3 weeks ago
New DroidBot Android banking malware spreads across Europe
SQL Injection Prevention: 6 Strategies
8 months 3 weeks ago
SQL Injection Prevention: 6 Strategies
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
8 months 3 weeks ago
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
Senators say U.S. military is failing to secure its phones from foreign spies
8 months 3 weeks ago
Senators say U.S. military is failing to secure its phones from foreign spies
IAM tech debt: Balancing modernization and legacy identity infrastructure
8 months 3 weeks ago
IAM tech debt: Balancing modernization and legacy identity infrastructure
CVE-2024-11643 | AllAccessible Accessibility Plugin up to 1.3.4 on WordPress Option Update authorization
8 months 3 weeks ago
A vulnerability classified as problematic has been found in AllAccessible Accessibility Plugin up to 1.3.4 on WordPress. This affects an unknown part of the component Option Update Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-11643. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-12138 | horilla up to 1.2.1 deserialization
8 months 3 weeks ago
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization.
This vulnerability was named CVE-2024-12138. The attack can be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2024-53614 | Thinkware Cloud APK 4.3.46 hard-coded key
8 months 3 weeks ago
A vulnerability was found in Thinkware Cloud APK 4.3.46. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to use of hard-coded cryptographic key
.
The identification of this vulnerability is CVE-2024-53614. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2024-12182 | DedeCMS 5.7.116 /member/soft_add.php body cross site scripting
8 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. The manipulation of the argument body leads to cross site scripting.
This vulnerability is handled as CVE-2024-12182. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12183 | DedeCMS 5.7.116 HTTP POST Request /plus/carbuyaction.php RemoveXSS cross site scripting
8 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-12183. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-12196 | Devolutions Server up to 2024.3.7.0 Permission authorization (DEVO-2024-0017)
8 months 3 weeks ago
A vulnerability was found in Devolutions Server up to 2024.3.7.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Permission Handler. The manipulation leads to incorrect authorization.
This vulnerability is handled as CVE-2024-12196. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CMMC Level 2 Requirements: A Guide to Achieving Compliance
8 months 3 weeks ago
CMMC Level 2 Requirements: A Guide to Achieving Compliance
Social Media Sanity in Relationships is Possible (Even on Vacation)
8 months 3 weeks ago
Social Media Sanity in Relationships is Possible (Even on Vacation)
Randall Munroe’s XKCD ‘Second Stage’
8 months 3 weeks ago
Randall Munroe’s XKCD ‘Second Stage’