Posts of last 24 hours
本文记录 Hack The Box Zero 靶机的完整渗透过程。目标仅开放 SSH 与 HTTP 服务,初始突破口来自一个支持 SFTP 上传的静态主页系统。通过注册获取 SFTP 凭据后,利用可覆盖的 .htaccess 配置 Apache ErrorDocument 404,实现任意文件读取,并从 Web 源码中泄露数据库凭据,成功拿到普通用户 Shell。随后通过 pspy 捕获 root
https://xz.aliyun.com/news/92665
表面上是个 debug 接口问题,顺着调用链跟下去会发现,真正失守的是 `authentik` 在 detail `GET` 上依赖的对象级授权边界。只要目标实例配置过 LDAP Source,攻击者又能访问 API 并知道或猜到某个 `slug`,就可以在未登录状态下请求
https://xz.aliyun.com/news/92667
资产测绘实战踩坑:580 个子域名结果 85% 是假阳性,从 grep -qv '^$' 空应答误判、泛解析、UDP 53 被墙到裸域漏验,逐个排坑后沉淀出"预筛 + 多轮枚举"两阶段方案,误报率降至 0。代码已开源。
https://xz.aliyun.com/news/92673
本文以一款会员时长类应用作为研究样本,完整拆解因账号注销物理删库带来的权限校验缺陷,复现 “注销 - 重注册” 无限领取新人权益的攻击链路,同时搭配抽象伪代码定位底层代码问题,给出通用化修复与审计思路。
https://xz.aliyun.com/news/92682
米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
https://jvn.jp/vu/JVNVU97889580/
A vulnerability identified as critical has been detected in IBM AIX and PowerVM VIOS 7.2/7.3/4.1. This affects an unknown part. Performing a manipulation results in out-of-bounds write.
This vulnerability is identified as CVE-2026-16958. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/394012
A vulnerability categorized as critical has been discovered in Microsoft Entra. Affected by this issue is some unknown functionality. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-69851. It is possible to launch the attack remotely. No exploit is available.
This product operates as a managed service, which prevents users from maintaining vulnerability countermeasures themselves.
https://vuldb.com/vuln/394011
A vulnerability was found in Microsoft Azure Virtual Machines. It has been rated as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-69543. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service, so users are unable to manage vulnerability countermeasures on their own.
https://vuldb.com/vuln/394010
A vulnerability was found in Microsoft Azure Data Factory. It has been declared as problematic. Affected is an unknown function. The manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-66800. The attack may be performed from remote. There is no available exploit.
This product is a managed service. This means that users cannot maintain vulnerability countermeasures themselves.
https://vuldb.com/vuln/394009