Aggregator
CVE-2024-9374 | Terms Descriptions Plugin up to 3.4.6 on WordPress cross site scripting
CVE-2024-10286 | LocalServer 1.0.9 /testmail/index.php cross site scripting
CVE-2024-10287 | LocalServer 1.0.9 /mlss/ForgotPassword ListName cross site scripting
CVE-2024-10288 | LocalServer 1.0.9 /mlss/SubscribeToList ListName cross site scripting
CVE-2024-10289 | LocalServer 1.0.9 /mlss/ManageSubscription MSubListName cross site scripting
Pwn2Own Ireland 2024: Day Three Results
Welcome to Day Three of our first ever Pwn2Own Ireland competition! We’ve already awarded $874,875, and we have 15 attempts left to go. Will we hit the $1,000,000 mark or will all remaining attempts end up in bug collisions? Stay tuned to find out. All times are Irish Standard Time (GMT +1:00).
SUCCESS - Ha The Long with Ha Anh Hoang of Viettel Cyber Security (@vcslab) used a single command injection bug to exploit the QNAP TS-464 NAS. Their fourth-round win nets them $10,000 and 4 Master of Pwn points.
FAILURE - Unfortunately, Sina Kheirkhah (@SinSinology) and Enrique Castillo (@hyprdude) of Summoning Team (@SummoningTeam) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.
SUCCESS - Pumpkin Chang (@u1f383) and Orange Tsai (@orange_8361) from the DEVCORE Research Team combined a CRLF Injection, an Auth Bypass, and a SQL Injection to exploit the Synology BeeStation. They earn $20,000 and 4 Master of Pwn points.
SUCCESS - PHP Hooligans / Midnight Blue (@midnightbluelab) used an OOB Write and a memory corruption bug to go from the QNAP QHora-322 to the Lexmark printer, which they demonstrated by printing their own "cash". Their successful SOHO Smashup earns them $25,000 and 10 Master of Pwn points.
SUCCESS - The Viettel Cyber Security (@vcslab) used a single type confusion bug to exploit the Lexmark CX331adwe printer. In the process, they earn $20,000 and 2 Master of Pwn points.
COLLISION - Our first collision of Day Three: the group from STEALIEN Inc. successfully popped the Lorex camera, but the bug they used had already been demonstrated in the contest. They still earn $3,750 and 1.5 Master of Pwn points.
COLLISION - namnp and tunglth of Viettel Cyber Security (@vcslab) ran into another collision. Their stack-based buffer overflow took over the Canon printer, but it had been previously used in the competition. They still earn $5,000 and 1 Master of Pwn point.
SUCCESS - Newcomers Team Smoking Barrels used an unprotected primary channel bug to exploit the Synology BeeStation for code execution. They earn $10,000 and 4 Master of Pwn points.
FAILURE - Unfortunately, the Viettel Cyber Security (@vcslab) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.
SUCCESS - In the penultimate attempt of Day 2, Daan Keuper (@daankeuper), Thijs Alkemade (@xnyhps), and Khaled Nassar (@notkmhn) from Computest Sector 7 (@sector7_nl) combined 4 bugs, including a command injection and a path traversal to going from the QNAP QHora-322 to the TrueNAS Mini X. They earn $25,000 and 10 Master of Pwn points.
FAILURE - ExLuck (@ExLuck99) of ANHTUD was unable to complete his SOHO S=mashup in the time allotted. HE was able to get into the Synology router but couldn't successfully pivot to the Canon printer.
《辐射:伦敦》玩家数量突破 100 万
Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker
CVE-2013-1650 | Open-Xchange Server 6.20.7/6.22.0/6.22.1 Filesystem access control (EDB-24791 / ID 803182)
关于SCA的使用探讨,以及开发、运维人员访问生产服务器如何进行安全管控?|总第269周
科学家在阿秒尺度上调查量子纠缠有多快
CVE-2002-0477 | Macromedia Flash Player up to 5.0.30 SWF File exec privileges management (XFDB-8587 / BID-4321)
19 000 против ИИ: ABBA, Radiohead и The Cure защищают права музыкантов
不受约束的私营企业如何破坏民主
Fortinet Warns of Critical Vulnerability in FortiManager Under Active Exploitation
CVE-2016-10193 | espeak-ruby Gem up to 1.0.2 on Ruby lib/espeak/speech.rb speak/save/bytes/bytes_wav access control (ID 370320)
Google Patches Multiple Chrome Security Vulnerabilities
Google has released several security patches for its Chrome browser, addressing critical vulnerabilities that malicious actors could exploit. The update is now available on the Stable channel, with version 130.0.6723.69/.70 for Windows and Mac and version 130.0.6723.69 for Linux. The rollout is expected to reach users over the coming days and weeks. The Extended Stable […]
The post Google Patches Multiple Chrome Security Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.