Newsletter 30/10/2022

This machine has a DNS service that is vulnerable to a Domain Zone Transfer attack and leaks a subdomain. Here we can bypass authentication with SQLi and exploit an LFI. Both vulnerabilities can be chained to get access to the machine. Then, we find another subdomain that is again vulnerable to LFI, and we can leak a user’s SSH private key. This user is able to restart fail2ban with sudo and modify configuration files

PHP. Laravel Debugger

64-bit binary. seccomp rules. open-read-write shellcode

Blockchain. Integer operations. Server-Side Template Injection

RC4. FMS attack

64-bit static binary. JOP. sys_rt_sigreturn and sys_execve

Adversarial Machine Learning

PHP. Laravel exploit
25 challenges (Web, Reversing, Pwn, Forensics, Crypto)