the grugq's newsletter

Subscribe
Archives
March 15, 2023

March 15, 2023

-

Twitter avatar for @plopz0r
Alain M. @plopz0r
A quick writeup on how I was able to exploit Fortinet's heap overflow (CVE-2022-42475) :
blog.scrt.chProducing a POC for CVE-2022-42475 (Fortinet RCE) – Sec Team Blog
3:18 PM ∙ Mar 14, 2023
137Likes61Retweets

-

Twitter avatar for @n0x08
🇺🇦 Nate Warfield | @n0x08@infosec.exchange🌻 @n0x08
Hi. Guy who worked in MSRC & shipped the MS17-010 patch here. *Preview pane* RCE was like the holy grail of non-OS vulns. This is so cool (the vuln, not the target because I will always #StandWithUkraine). But goddamn y’all better install this one. Trust me. I know.
Twitter avatar for @ryanaraine
Ryan Naraine @ryanaraine
Ukrainian CERT credited with the MS Outlook 0day, suggesting this is gov-level APT activity https://t.co/5tHyY4gPjE "This could lead to exploitation BEFORE the email is viewed in the Preview Pane."
3:46 AM ∙ Mar 15, 2023
76Likes29Retweets
Twitter avatar for @MDSecLabs
MDSec @MDSecLabs
We've just published a quick write up on CVE-2023-23397, which allows a remote adversary to leak NetNTLMv2 hashes: mdsec.co.uk/2023/03/exploi… by @domchell
Image
11:55 PM ∙ Mar 14, 2023
506Likes257Retweets
Twitter avatar for @HaifeiLi
Haifei Li @HaifeiLi
Well, I'd argue the Outlook 0day has its limitations, although it seems to be a nation state 0day attack (see who reported it). It doesn't allow RCE but NTLM leaking. What I want to say is if ur org still allows outbound 139/445 connection, well, you already got bigger problems.
Image
6:47 AM ∙ Mar 15, 2023
22Likes3Retweets

-

Twitter avatar for @jilles_com
Jilles Groenendijk @jilles_com
Image
10:12 PM ∙ Mar 14, 2023
158Likes36Retweets

-

Twitter avatar for @Infoxicador
Ruben Casas 🦊 @Infoxicador
Today is a sad day: Apparently, my favourite HTML element, <marquee /> Has been deprecated ⚠️ My first ever website used it everywhere. Thanks for all the great memories. We will miss ya.
10:57 AM ∙ Mar 14, 2023
1,474Likes162Retweets

-

Twitter avatar for @thekitze
kitze @thekitze
GPT-4 can take a picture of napkin mockup as an input and output a fully functional website (HTML/CSS/JS) 🤯🤯🤯
Image
Image
8:20 PM ∙ Mar 14, 2023
7,490Likes999Retweets

-

The oldest privesc: injecting careless administrators' terminals using TTY pushback

https://www.errno.fr/TTYPushback.html

-

Twitter avatar for @nearcyan
near @nearcyan
page 37 of the GPT-4 paper: cdn.openai.com/papers/gpt-4.p…
Image
8:21 PM ∙ Mar 14, 2023
1,855Likes316Retweets

-

Don't miss what's next. Subscribe to the grugq's newsletter:

Start the conversation:

Be the first to share your thoughts

X