Gaetan

269 posts

Gaetan

Gaetan

@_mabote_

AppSec researcher @SonarSource | Former pentester 🥾 | @[email protected]

Katılım Mart 2019
88 Takip Edilen197 Takipçiler
Gaetan retweetledi
Fenrisk
Fenrisk@FenriskSec·
Expecting to struggle finding a gadget chain in WordPress Core during an assessment when devs suddenly decided to make it easy : fenrisk.com/publications/b…
English
1
9
18
3.9K
Gaetan retweetledi
Sonar Research
Sonar Research@Sonar_Research·
🔥 Unauthenticated RCE vulnerability in JetBrains TeamCity (CVE-2023-42793) 🔥 We just disclosed the technical details explaining how a vulnerable Request Interceptor and a few undocumented endpoints led to RCE on one of the most popular CI/CD servers: sonarsource.com/blog/teamcity-…
Sonar Research@Sonar_Research

⚠️ Unauthenticated RCE vulnerability in JetBrains TeamCity (CVE-2023-42793) ⚠️ Attackers could steal source code and poison build artifacts to launch supply chain attacks: sonarsource.com/blog/teamcity-… #appsec #security #vulnerability

English
0
22
56
14.8K
Gaetan retweetledi
Sonar Research
Sonar Research@Sonar_Research·
We are excited to share that we have two entries in the running for the next Pwnie Awards 🐴✨ 👇
English
1
4
12
3.3K
Gaetan retweetledi
Hexacon
Hexacon@hexacon_fr·
🥑 The Hazards of Technological Variety and Parallelism: An Avocado Nightmare, by Stefan Schiller (@scryh_)
Hexacon tweet media
English
0
2
6
3.1K
Gaetan
Gaetan@_mabote_·
@g0ziem @TheASF Considering the exploitation scenario is application dependent, there is no generic, always working, PoC. That said, you should find all the required technical information in the issue write-up synacktiv.com/publications/c….
English
0
0
0
14
Gaetan
Gaetan@_mabote_·
I have just been credited by @TheASF for CVE-2022-31813. It's a weakness in mod_proxy management of hop-by-hop headers. More details to come. Brace yourselves #BugBounty hunters, new opportunities for 💰💰💰.
English
2
4
39
0
Gaetan retweetledi
Sonar
Sonar@SonarSource·
Sonar at @BlackHatEvents Asia! Look for us at Booth B20 for live demos with our solution! In addition, @Sonar_Research member Paul Gerste will host a presentation: "Stealing with Style: Using CSS to Exploit ProtonMail & Friends" on May 11, 11:20 am at Roselle Junior Ballroom!
English
0
2
13
15K
Gaetan retweetledi
Synacktiv
Synacktiv@Synacktiv·
Windows authentication & Prox-Ez is the topic of the last Synacktiv talk at #THCon, staring @b1two_ and @YofBalibump
Synacktiv tweet media
English
0
9
26
3.4K
Gaetan retweetledi
Synacktiv
Synacktiv@Synacktiv·
A server monitoring software 🌡 named Supermicro SuperDoctor 5 has been encountered during an assessment. However, @bak_sec and @_mabote_ were not big fans of the web app UX and thought a root shell would be more suitable 🐚 ➡️ Read more about this RCE: synacktiv.com/sites/default/…
Synacktiv tweet media
English
0
15
43
11.2K
Gaetan retweetledi
Synacktiv
Synacktiv@Synacktiv·
Did you enjoy the latest blogpost on PHP filter chains? Well, our ninja @_remsio_ strikes again with a new article detailing how you can abuse them to leak files from the targeted system, as well as a freshly developed tool to exploit it! synacktiv.com/publications/p…
English
2
67
143
26K
Gaetan retweetledi
Arthur CHARLES
Arthur CHARLES@0xbeefed·
Fishing for bugs in PHP apps be like
English
2
4
36
4.9K