Newsletter 05/09/2023
data:image/s3,"s3://crabby-images/27b02/27b02c83c7ab0cc931def8a5a1e2b1a99a9ed11b" alt="MonitorsTwo-image"
This machine has a Cacti service that is vulnerable to unauthenticated Remote Code Execution that grants access to a Docker container. Here we can find credentials in the database and reuse them for SSH on the host machine. Then, we find out that the Docker version is vulnerable to a CVE. To exploit this, we need to get root
in the container and configure a SUID binary that will be executed from the host machine via directory traversal to escalate privileges
data:image/s3,"s3://crabby-images/bdd58/bdd5841ada0d25f531c1660be2d65d15c7457f9b" alt="pwn-image"
64-bit binary. Heap exploitation. Integer overflow. Heap overflow. ret2libc
data:image/s3,"s3://crabby-images/72f81/72f81014bb0e7bbe977654dd92f99de1edd21c63" alt="cryptography-image"
Recurrence relation. Telescoping series. LCG
data:image/s3,"s3://crabby-images/72f81/72f81014bb0e7bbe977654dd92f99de1edd21c63" alt="cryptography-image"
Graph Encryption Scheme
1: Key leakage. Decryption
2: Single-Destination Shortest Path. Node degrees
3: Query recovery. Tree isomorphisms
data:image/s3,"s3://crabby-images/72f81/72f81014bb0e7bbe977654dd92f99de1edd21c63" alt="cryptography-image"
CRC. Chinese Remainder Theorem. Brute force