
Source Incite
420 posts

Source Incite
@sourceincite
We are Incite Team. Providing high quality Vulnerability Research & Training Services.









🔥💀 Here is the "Real" writeup and exploit for the pre-auth deserialization RCE I reported to Ivanti CVE-2024-29847 Apparently, folks at horizon3 tried to write about my bug before me but they did it wrong summoning.team/blog/ivanti-ep…

This full chain analysis from discovery to exploit has been added to Full Stack Web Attack. The last training for this year is at Romhack between 24th-27th of September at romhack.io/training/2024/…. Student discount codes available, PM me but I only have a few left.

The last training for this year is at Romhack between 24th-27th of September at romhack.io/training/2024/… some student discount codes still available, DM us.


Of course I had to finish it off ^_^

Landed a nice auth-bypass via an XXE! If you wish to learn techniques like this, you should definitely sign up to our Sep 24-27th Full Stack Web Attack class at @cybersaiyanIT: romhack.io/training/2024/…







