CODE WHITE - FINEST HACKING
Intelligence Driven Security
Initial Assessment
Security Intelligence Service
About us
PUBLIC VULNERABILITY LIST
Local Privilege Escalation in Ivanti DSM
SPPageparserFilter Bypass in SharePoint
Data Source Protection Bypass During XML Deserialization in DevExpress
...
CAREERS
Challenge
Pentester / Redteamer
Developer
Systems Engineer / Admin
BLOG
Blindsiding auditd for Fun and Profit
From Blackbox .NET Remoting to Unauthenticated Remote Code Execution
Java Exploitation Restrictions in Modern JDK Times
...
>
CODE WHITE - Finest Hacking
>
Authors
>
Markus Wulftange
JMX Exploitation Revisited
Bypassing .NET Serialization Binders
.NET Remoting Revisited
RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through
Liferay Portal JSON Web Service RCE Vulnerabilities
Exploiting H2 Database with native libraries and JNI
Telerik Revisited
Poor RichFaces
AMF – Another Malicious Format
Compromised by Endpoint Protection: Legacy Edition
Java and Command Line Injections in Windows
Compromised by Endpoint Protection
Reading/Writing files with MSSQL's OPENROWSET
CVE-2015-0935: PHP Object Injection in Bomgar Remote Support Portal
$@|sh – Or: Getting a shell environment from Runtime.exec