Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-32278: Igo0r – Medium

XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

CVE
#ios#google#oauth#auth#chrome

Dec 19, 2021

Destroying files using Google Chrome

Hello guys! Today I will share my experience of how you can destroy files using google chrome. Let’s see the follow chrome.exe command: “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” — type=crashpad-handler “ — user-data-dir=C:\Users\nopriv2\AppData\Local\Google\Chrome\User Data” /prefetch:7 — monitor-self-annotation=ptype=crashpad-handler “ — database=C:\lololo45l” “ — metrics-dir=C:\Users\nopriv2\AppData\Local\Google\Chrome\User Data” — url=https://www.google.com/cr/report — annotation=channel= — annotation=plat=Win64…

Hacking

2 min read

Dec 1, 2021

Transporting malware in google links.

Hello guys! Today I will share my experience of how you can transport a encoded malware using accounts.google.com. Researching I noticed that the response_type= google parameter of https://accounts.google.com/o/oauth2/v2/auth/identifier?response_type= is reflective on response… So I focused more on that. I either noticed that after you make a GET request…

Hacking

3 min read

Jul 3, 2020

Exercicios FreeBsd

Instalando sem ports: Criar usuário e colocar ele dentro do grupo wheel: Com o comando adduser é possivel criar um usuário e adiciona-lo em outro grupo, no caso o wheel

6 min read

Jan 25, 2020

Write up — Code On (500) — Crypto-Bio — Rice Tea Cat Panda CTF

#RATF The challenge give us a sequence of mRNA and a “Key”: My houseplant and I were working on a biology assignment together. Yes, my houseplant. Don’t question it. Anyways, she ended up giving me a new cipher to use in my next project! So I’m giving it to my…

Ctf Writeup

2 min read

Jul 24, 2019

CyBRICS Matreshka — Write-up

Bom, esse é o primeiro write-up que escrevo. provavelmente a terceira ou quarta vez que tiro um tempo para escrever sobre esse mundo e também é a primeira vez “publicamente” mas enfim, desculpa qualquer erro e vamo lá: CyBRICS — https://cybrics.net — foi um CTF que rolou dia 20 onde…

Brazil

8 min read

Related news

Gentoo Linux Security Advisory 202409-09

Gentoo Linux Security Advisory 202409-9 - A vulnerability has been discovered in Exo, which can lead to arbitrary code execution. Versions greater than or equal to 4.17.2 are affected.

Ubuntu Security Notice USN-6008-1

Ubuntu Security Notice 6008-1 - It was discovered that Exo did not properly sanitized desktop files. A remote attacker could possibly use this issue to to cause a crash or arbitrary code execution.

CVE-2022-32278: exo-open : Only execute local .desktop files (c71c04ff) · Commits · Xfce / exo · GitLab

XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907