Yaniv Nizry

50 posts

Yaniv Nizry banner
Yaniv Nizry

Yaniv Nizry

@YNizry

Security researcher

เข้าร่วม Aralık 2020
141 กำลังติดตาม1.8K ผู้ติดตาม
Yaniv Nizry
Yaniv Nizry@YNizry·
TROOPERS talks are now live on YouTube! Curious how attackers can turn endpoint protection into an entry point? In my session, I break down exactly how these compromises happen - step by step. 🎥 Watch here: youtube.com/watch?v=sfjxjW…
YouTube video
YouTube
English
0
2
6
1.3K
Yaniv Nizry รีทวีตแล้ว
Sonar Research
Sonar Research@Sonar_Research·
🔓⏫ After compromising every endpoint within an organization, our “Caught in the FortiNet” series comes to an end with one more thing. Read more about FortiClient's XPC mistake that allows local privilege escalation to root on macOS sonarsource.com/blog/caught-in… #appsec #security
English
0
6
19
2.2K
Yaniv Nizry
Yaniv Nizry@YNizry·
[2/2] Meaning that if you have a file write and can't control the extension and the extension doesn't correlate to any Content-Type (let's say .abc), you can add .html to the file name (filename.html.abc) and httpd will serve it as text/html
English
1
1
10
1.4K
Yaniv Nizry
Yaniv Nizry@YNizry·
[2/2] Meaning that if you have a file write and can't control the extension and the extension doesn't correlate to any Content-Type (let's say .abc), you can add .html to the file name (filename.html.abc) and httpd will serve it as text/html
English
0
0
0
146
Yaniv Nizry รีทวีตแล้ว
Yaniv Nizry รีทวีตแล้ว
Sonar Research
Sonar Research@Sonar_Research·
Catch our second talk at #TROOPERS25: 🕸️ Caught in the FortiNet: Compromising Organizations Using Endpoint Protection @YNizry will tell you the story of multiple vulnerabilities in Fortinet products that can compromise an entire organization, starting with a single click
Sonar Research tweet media
English
0
5
17
3.5K
Yaniv Nizry รีทวีตแล้ว
Sonar Research
Sonar Research@Sonar_Research·
Join us at OWASP SF for our talk, "Sanitize Client-Side: Why Server-Side HTML Sanitization is Doomed to Fail" to discover why client-side sanitization is crucial for a secure web. Can't make it? Stay tuned for our upcoming blog post. #OWASP #GlobalAppSecSanFran
Sonar Research tweet media
English
0
8
27
3.4K