rastating.github.io

Minecraft Servers List Unauthenticated Shell Upload

January 18, 2018

Due to a lack of input sanitisation and auto-removal of the installation script, an unauthenticated user is able to re-purpose the connect.php file to gain remote code execution.

Continue reading

RegistrationMagic - Custom Registration Forms <= 3.7.9.2 Reflected XSS

December 10, 2017

Using an SQL injection vulnerability, arbitrary markup can be reflected back to the user, achieving JavaScript execution in the context of the authenticated user.

Continue reading

RegistrationMagic - Custom Registration Forms <= 3.7.9.2 Authenticated SQL Injection

December 10, 2017

Due to a lack of input sanitisation, arbitrary `SELECT` statements can be executed and the results viewed in the field management page.

Continue reading

"Merna" Malware Being Distributed w/ WordPress Plugins

October 29, 2017

Whilst doing some research this evening, I acquired a plugin from an unofficial distributor. When doing exploit development, I do so in an isolated environment with all external network access disabled, for situations such as these.

Continue reading

Scanning Barcodes w/ Panasonic FZ-N1

October 27, 2017

Reading barcodes in Android from the Panasonic FZ-N1 barcode scanner is natively achievable via the dispatchKeyEvent method within an Activity.

Continue reading
Prev Next