spreading the message on maritime cyber one preso and conversation at a time
spreading the message on maritime cyber one preso and conversation at a time
www.404media.co/wikipedia-pr...
www.404media.co/wikipedia-pr...
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Looks like this got caught by chance. Wonder how long it would have taken otherwise.
www.openwall.com/lists/oss-se...
It has everything: malicious upstream, masterful obfuscation, detection due to performance degradation, inclusion in OpenSSH via distro patches for systemd support…
Now I’m curious what it does in RSA_public_decrypt
The hooked RSA_public_decrypt verifies a signature on the server's host key by a fixed Ed448 key, and then passes a payload to system().
It's RCE, not auth bypass, and gated/unreplayable.
Gets table not found in DB
*checks name of DB table *
Fixes name reference
*Runs script again*
Table not found
*opens DB*
DB file is empty
Pain. Pain. Pain.
Gets table not found in DB
*checks name of DB table *
Fixes name reference
*Runs script again*
Table not found
*opens DB*
DB file is empty
Pain. Pain. Pain.
warontherocks.com/2023/11/citi...
warontherocks.com/2023/11/citi...
thecyberwire.com/podcasts/con...
thecyberwire.com/podcasts/con...
A few months ago I purposely deleted my back up code and code generator for Twitter bc I decided next time it deleted it I would be done with the app ….
So guess I’m on here more now
A few months ago I purposely deleted my back up code and code generator for Twitter bc I decided next time it deleted it I would be done with the app ….
So guess I’m on here more now
The only way to get progress on this technical approach and processing 800-82 r3
The only way to get progress on this technical approach and processing 800-82 r3
I’m working the corpo b2b angle but curious if anyone has actually had success in getting one for research/homelab use w/o shelling out for a full cost through a distributor
I’m working the corpo b2b angle but curious if anyone has actually had success in getting one for research/homelab use w/o shelling out for a full cost through a distributor