abdilahrf's Avatar

abdilahrf

@abdilahrf.bsky.social

CTF / Bugbounty / Web Guy

754 Followers  |  117 Following  |  1 Posts  |  Joined: 21.11.2024  |  1.4765

Latest posts by abdilahrf.bsky.social on Bluesky

Preview
Top 10 web hacking techniques of 2024 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.

Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...

15.01.2025 15:24 โ€” ๐Ÿ‘ 24    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 7

Use golden goose until its not golden ๐Ÿคฃ๐Ÿ˜

14.01.2025 03:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CVE 2024-37397 - Ivanti Endpoint Manager XXE Vulnerability This blog provides an in-depth analysis of the exploitation process for an unauthenticated XXE vulnerability in Ivanti Endpoint Manager, identified as CVE-2024-37397.

TIL that the recent Ivanti ImportXML vulnerability is a second-order XXE, where the payload must be enclosed in the CDATA section of a SOAP request ๐Ÿฆพ

15.12.2024 12:00 โ€” ๐Ÿ‘ 14    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
11 char with open()

Slow race condition but 11 chars! terjanq.me/solutions/jo... Let me know if that works for you. With that, time to stop ๐Ÿ˜…

13.12.2024 20:34 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
DEF CON 32 - Splitting the email atom  exploiting parsers to bypass access controls - Gareth Heyes
YouTube video by DEFCONConference DEF CON 32 - Splitting the email atom exploiting parsers to bypass access controls - Gareth Heyes

In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! ๐Ÿš€ Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Donโ€™t miss it:

youtu.be/JERBqoTllaE?...

22.11.2024 07:27 โ€” ๐Ÿ‘ 97    ๐Ÿ” 30    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Post image

Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE.
Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...

22.11.2024 05:50 โ€” ๐Ÿ‘ 51    ๐Ÿ” 25    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@abdilahrf is following 20 prominent accounts