Burninator Sec

This blog is about the educational (and sometimes entertainment) value of simple hacks. For active vulnerabilities, real names are concealed.

Sunday, November 29, 2020

Palo Alto Networks - WAF Bypass for Webshell

›
I originally found/reported to Palo Alto in 2018. You can use the default Kali Linux aspx webshell to get RCE on a server protected by Palo ...
Monday, October 26, 2020

CVE-2020-26885 XSS in Anchor Tags

›
For CVE-2020-26885, the AWS WAF made it difficult to get XSS payloads through to the server, but I was able to rely on the client to execute...
Sunday, October 4, 2020

CVE-2020-15864 - XSS in Quali CloudShell Login

›
Payload: {{constructor.constructor(%27alert(19891337)%27)()} Add "username" as a parameter to the login URL to reference the usern...
Wednesday, September 2, 2020

CVE-2020-13972 - XSS via SSRF in Enghouse/Zeacom web chat

›
Here's a chained attack of a known SSRF issue ( CVE-2019-16948 / CVE-2019-16951 ) in order to get XSS in Enghouse Web Chat 6.2.284.34. W...
Tuesday, August 11, 2020

Filter Bypass for Open Redirect

›
Trying to add a redirect payload through a URL parameter (but it's just getting harm less ly tacked to the end of the domain)? Bypass by...
Saturday, April 4, 2020

SQL Rollback Hack

›
Ever seen an application display a message like "changes will be rolled back ", particularly after a SQL operation? This may be a ...

Buffer Overflow Practice

›
Although it can seem daunting when you're staring at hex and registers for too long, at the end of the day, a buffer overflow is like an...
‹
›
Home
View web version
Powered by Blogger.