Jun 23, 2022Miracle - One Vulnerability To Rule Them All# Introduction As mentioned in Jang blog, We (me and Jang) found a mega 0-day. After April Critical Patch, finally the vulnerability was patched properly. If you never known about this vulnerability, please patch your system ASAP ! # Summary Let us name this attack The Miracle Exploit because it affects many products based…Cve 2022 2144511 min readCve 2022 2144511 min read
Nov 19, 2021Some notes about Microsoft Exchange Deserialization RCE (CVE-2021–42321)Vietnamese version: https://testbnull.medium.com/some-notes-of-microsoft-exchange-deserialization-rce-cve-2021-42321-f6750243cdcd INTRO It’s been several months since our last story about ProxyShell Exploit and recently Exchange was pwned again at Tianfu Cup 2021. We’re very excited about that Exploit and we’re waiting for Tuesday Patch of MS Exchange this month to analyse it. There’s already a blog analysis about…Exchange8 min readExchange8 min read
Sep 19, 2021[::ACSC Quals 2021::] — Breaking LogicsYesterday, I have played ACSC 2021 and there an interesting challenge from Orange Tsai and I want to write down something about this challenge. The challenges from ACSC so good and it will be up for 1–2 days. If you curious about them, go head https://score.acsc.asia/ This challenge is easy…Acsc5 min readAcsc5 min read
Sep 16, 2021Linh tinh về Oracle Business Intelligence [part 3]Để tiếp nối series Oracle Business Intelligence, mình sẽ write-up 2 bug pre-auth RCE mà mình tìm được đợt này CVE-2021-2244 và CVE-2021-2456 (số đẹp vkl ( ͡° ͜ʖ ͡°) ). Bài viết này sẽ nói về 2 bug trên cũng như những tip/trick khi target Oracle BI. Enviroment Weblogic: 12.2.1.3.0 …Cve 2021 22448 min readCve 2021 22448 min read
Published intradahacking·Sep 7, 2021[Atlassian Confluence CVE-2021–26084]::: The other side of bug report!tl;dr A pull request for Nuclei template of CVE-2021–26084 turned out to be a leak of our Pre-Auth RCE exploit payload for Atlassian Confluence that had been provided to VMWare. When CVE-2021–26084 advisory came out, our team as usual tried to reproduce the bug with a reliable exploit. I noticed…Confluence4 min readConfluence4 min read
Aug 6, 2021Reproducing The ProxyShell Pwn2Own ExploitINTRO I and Jang recently successfully reproduced the ProxyShell Pwn2Own Exploit of Orange Tsai 🍊. Firstly, I just want to tell that I respect your hard work and the contribution of you to cybersecurity which inspired me many years ago. Now I want to summary the progress when we reproduce this…Proxy7 min readProxy7 min read
Published intradahacking·Feb 20, 2021CVE-2019–2725 RevisitedINTRO Hi guys! Lần này mình sẽ mang tới cho các bạn 1 case mình thấy khá là hay ho nên muốn viết write-up chia sẻ về case này. Context của target mình gặp phải là một site dính CVE-2019–2725 NHƯNG Weblogic version 12.1.3.0.0 target này không có bất kỳ outbound…Cve 2019 27256 min readCve 2019 27256 min read
Jul 25, 2020CVE-2020–2950 — Turning AMF Deserialize bug to Java Deserialize bugINTRO Hi các bạn ! Cũng lâu rồi mình chưa có viết lách gì về kỹ thuật thì lần này mình sẽ write-up về 1 case pentest liên quan đến bug CVE-2020–2950 . Mình reproduce lại…Gadget11 min readGadget11 min read
Published inCDLabs·Feb 23, 2020RMI Study Note And Some Study CaseHi ! Lâu rồi mình cũng không viết blog hay là write-up về CTF nữa, mà lần này mình muốn viết về một chủ đề khác, về RMI, về Java và muốn chia sẻ chính về cách mình tiếp cận, quá trình đào sâu một vấn đề mới và nhiều…Java15 min readJava15 min read
Published intradahacking·Feb 23, 2020[RMI] Study Note And Some Study CaseHi ! Lâu rồi mình cũng không viết blog hay là write-up về CTF nữa, mà lần này mình muốn viết về một chủ đề khác, về RMI, về Java và muốn chia sẻ chính về cách mình tiếp cận, quá trình đào sâu một vấn đề mới và nhiều…Java15 min readJava15 min read