An Trinh

23 posts

An Trinh

An Trinh

@aphtrinh

San Francisco, CA Katılım Nisan 2016
273 Takip Edilen1.4K Takipçiler
An Trinh retweetledi
Calif
Calif@calif_io·
New blog post: in a recent engagement, we turned a simple XSRF in Argo CD to a shell with cluster admin privileges. No fix is available. We recommend hosting Argo CD on an isolated domain. Details: blog.calif.io/p/argo-cd-csrf
English
0
9
42
6.9K
An Trinh retweetledi
Calif
Calif@calif_io·
In a recent engagement, we encountered a target running CraftCMS, and discovered a Remote Code Execution vulnerability that allowed us to compromise the target. blog.calif.io/p/craftcms-rce CC @yeuchimse
English
0
33
77
11.8K
An Trinh
An Trinh@aphtrinh·
@christophetd @calif_io re-reporting to AWS: We haven't, mostly because we think of this as a new way to exploit an old flaw. Thanks again. Feel free to reach out if you want to discuss further.
English
0
0
0
145
An Trinh
An Trinh@aphtrinh·
@christophetd @calif_io GCP seems to have similar problems in the past with the node/kubelet token and have since greatly restricted the permissions of the GKS token stored on metadata. On system:node being able to create serviceaccounts/token (*for the pods on it), I believe this is the nature of k8s.
English
1
0
0
152
Simon Scannell
Simon Scannell@scannell_simon·
CVE-2022-27924 allows an unauthenticated, remote attacker to dump clear-text creds from a Zimbra instance with default config. We used Memcache response injection to bypass restrictions. Apparently Zimbra is used by over 200.000. Patch now! blog.sonarsource.com/zimbra-mail-st…
English
3
101
219
0
ϻг_ϻε
ϻг_ϻε@steventseeley·
I’m curious, had anyone here found any real world saml authentication bypass vulnerabilities with write ups?
English
6
9
37
0
An Trinh
An Trinh@aphtrinh·
@matthias_kaiser It looks worse. The substitutions can happen in both the string format *and* the string arguments
English
0
0
5
0
Matthias Kaiser
Matthias Kaiser@matthias_kaiser·
log4j2 is the new format string !
English
1
13
79
0
An Trinh
An Trinh@aphtrinh·
@mogwailabs Thanks for writing it up. Although I believe jmxrmi doesn't prevent this. Have you tried the lookup op instead of bind?
English
1
1
3
0
Dave Aitel
Dave Aitel@daveaitel·
@_tint0 You should submit a talk to INFILTRATE! :)
English
1
0
0
0