Budanthara

1.3K posts

Budanthara banner
Budanthara

Budanthara

@budanthara

just another tech guy

Indonesia Katılım Mayıs 2010
779 Takip Edilen640 Takipçiler
Budanthara retweetledi
blasty
blasty@bl4sty·
the xz sshd backdoor rabbithole goes quite a bit deeper. I was just able to trigger some harder to reach functionality of the backdoor. there's still more to explore.. 1/n
blasty tweet media
English
32
965
5.1K
872.2K
Budanthara
Budanthara@budanthara·
@yeswehack Those two highlighted functions will consider this as a valid input from the user and will be executed through the "file_get_contents()". More bypasses if you wanna try: "file::////etc/passwd","php::////filter/convert.base64-encode|convert.base64-decode/resource=/etc/passwd"
English
0
0
1
102
Budanthara
Budanthara@budanthara·
@yeswehack So how to reproduce this into a simple LFI payload? just simply pass "?file=/etc/passwd" directly through the parameter.
English
1
0
1
164
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
Vulnerable Code Snippets Time 🥷 Level: Medium 🐝 This web application does not like dot dot slash! Try it out at Github: github.com/yeswehack/vuln… #BugBounty #YesWeRHackers Found the issue? Explain how in the comments! 👇 🎁 The best solution gets an exclusive swag!
YesWeHack ⠵ tweet media
English
8
11
63
15K
nopslide
nopslide@nopsIide·
The lowest user "nobody" could use this simple bash script and allows anybody to overwrite data in arbitrary read-only files (CVE-2022-0847) It is similar to CVE-2016-5195 “Dirty Cow” but is easier to exploit. dirtypipe.cm4all.com #infosec #CVE
nopslide tweet media
English
3
32
73
0
Budanthara
Budanthara@budanthara·
Since this #Log4J vulnerability (CVE-2021-44228) has extremely bad impact, I've decided to build a small local environment to measure and test the impact of it by chaining into a shell RCE attack. Insane! #Log4Shell #cybersecurity
Budanthara tweet media
English
3
3
20
0
Budanthara
Budanthara@budanthara·
@AceAintDead malah sempet"nya nanya "kok bisa segitu" pas lagi bertempur
Indonesia
1
0
0
0
DenCak
DenCak@Santuynism_·
@budanthara Biar valid je jawabanmu pas itu 😌
Indonesia
1
0
0
0
Budanthara
Budanthara@budanthara·
@AceAintDead bukannya ga ada, tpi kl makan di daerahnya lgsg dri segi rasa pasti lebih autentik
Indonesia
1
0
0
0
DenCak
DenCak@Santuynism_·
Lihat food vlogger makan nasi campur bali kok lahap bener ya apa di daerahnya gaada ya😦
Indonesia
1
0
0
0
nopslide
nopslide@nopsIide·
yup.. Apache 2.4.50 ✅
nopslide tweet media
English
1
1
5
0
Budanthara
Budanthara@budanthara·
Me n @nopsIide trying to figure out the macOS Finder #vulnerability behavior today,since we found that we don't really need to mangle "file://" protocol at this current version of macOS (Big Sur) by using ".fileloc" rather than ".inetloc". youtu.be/YqERFRMkyBs via @YouTube
YouTube video
YouTube
Budanthara tweet media
English
1
2
7
0