The_Maxu

123 posts

The_Maxu banner
The_Maxu

The_Maxu

@The_Maxu

Katılım Nisan 2016
88 Takip Edilen128 Takipçiler
The_Maxu
The_Maxu@The_Maxu·
@notnotzecoxao Ok... Path Traversal in PSDescriptorFactory to overwrite the internal /userprefs file with a poisoned Java object (Payload) that, when processed without filters by readObject() in UserPreferenceManagerImpl, executes arbitrary code... ???
English
1
1
2
593
Jose Coixao
Jose Coixao@notnotzecoxao·
some diffs from ps5 bdjstack 12.00 and 13.00
Jose Coixao tweet mediaJose Coixao tweet mediaJose Coixao tweet mediaJose Coixao tweet media
English
13
17
206
18.5K
The_Maxu
The_Maxu@The_Maxu·
@CelesteBlue123 @ps3120 file:///app0/bdjstack/lib/ext/sunjce_provider.jar/../../../../../disc/BDMV/JAR/00000.jar
English
1
0
3
120
120
120@ps3120·
github.com/ps3120/ps3120.… iso bdj 1304 uploaded to github, it's just a user exploit, a kernel exploit is missing, patched on 13.50 and not work on 13.00 and 13.02
English
7
19
125
13.2K
The_Maxu
The_Maxu@The_Maxu·
@CelesteBlue123 In Java, you can use `!` to access the internal contents of a JAR file and load a specific class. It's simply one of the easy ways to exploit the bug before the patch.
English
1
0
1
141
leftthebird 
leftthebird @CelesteBlue123·
@The_Maxu Why do you need the exclamation mark (!)? I would think doing instead .jar../../payload.jar.
English
1
0
0
138
The_Maxu retweetledi
Jose Coixao
Jose Coixao@notnotzecoxao·
differences between 13.02 and 13.04 (what i could find at least)
Jose Coixao tweet media
English
16
24
280
55.2K
The_Maxu
The_Maxu@The_Maxu·
@notnotzecoxao The validation logic still relies on string-based path handling (indexOf(".jar") and startsWith()), which is fragile by design...
English
0
0
2
1.6K
The_Maxu retweetledi
Jose Coixao
Jose Coixao@notnotzecoxao·
i've deleted previous tweet, but 15432 asked me to repost it again, so yeah. path traversal is still possible on 13.04 because sony fucked big time. expect it to be patched on something like 13.50 or 14.00 though. and if you think hackerone is what made the scene prosper, you are wrong :)
English
20
16
258
26.4K
The_Maxu
The_Maxu@The_Maxu·
@spammail350362 @notnotzecoxao BD-J bug where JAR paths were improperly validated. Using .jar!/../../payload.jar could trick the runtime into treating an external JAR as if it were in lib/ext and grant it AllPermission. The patch trims the path at .jar before canonicalization. Sandbox escape via path confusion
English
4
5
70
12.1K
The_Maxu
The_Maxu@The_Maxu·
@m0ur0ne @BlieDieBlaDie WTF? Escribí eso en noviembre... Que mal te debes de sentir por dentro... ¿Y ahora cambias la historia diciendo que es otro? Lo que hay que ver... Por lo menos espero que hagas buen uso del dinero. Un saludo.
Español
0
0
0
27
The_Maxu retweetledi
David Lrt
David Lrt@Bushigan·
Just testing...
English
47
26
387
91K
The_Maxu retweetledi
Jose Coixao
Jose Coixao@notnotzecoxao·
GIF
ZXX
4
11
65
11.1K