Burninator Sec

This blog is about the educational (and sometimes entertainment) value of simple hacks. For active vulnerabilities, real names are concealed.

Saturday, April 16, 2022

Reporting Library RCE (Object Chaining) - CVE-2021-42777

›
  Similar to CVE-2020-15865 . However, this one was a little trickier because I could only execute chained C# commands that ultimately ret...
Sunday, January 2, 2022

Post-Exploitation PII Search Across All Databases

›
This is an improvement on the previous PII finder scripts. Since often times production db servers have many databases, this will iterate ov...
Wednesday, July 28, 2021

OnyakTech Comments Pro - Broken Encryption and XSS CVE-2021-33484 and CVE-2021-33483

›
  Broken Encryption / User Spoofing (CVE-2021-33484) https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33484   This exploit involves d...
Sunday, June 6, 2021

SQL Injection & Manual Data Exfiltration (For When SQLMap Won't Work)

›
This is a new payload that I'm hoping to incorporate into SQLMap soon ( here's the feature request ). Assume a field is vulnerable t...
Tuesday, April 13, 2021

CVE-2020-29592 and CVE-2020-29593 - Orchard CMS Unrestricted File Upload and XSS

›
  Note: This is fixed in Orchard 1.10, this post is about Orchard 1.8.1.0. CVE-2929-29592 - Unrestricted File Upload via Media Folder and Ti...

RCE Using Recaf: an Awesome Java Decompiler/Recompiler

›
Recaf is super slick for reverse engineering and editing Java, I used it for arbitrary command injection (for RCE running as root!) last wee...

Hash Cracking with Rental AI GPUs

›
I've been doing a lot with fast.ai lately and really enjoying it. The worst part about AI is how long it takes to train a model, realize...
‹
›
Home
View web version
Powered by Blogger.