CODE WHITE - FINEST HACKING
Intelligence Driven Security
Initial Assessment
Security Intelligence Service
About us
PUBLIC VULNERABILITY LIST
Multiple Unauthenticated Remote Memory Corruptions in agentlink_server Service in Vinchin Backup & Recovery
Unauthenticated Remote Code Execution via Deserialization of Untrusted Data in Lobster Data Platform
FileViewer Path Traversal File Read in MailEnable
...
CAREERS
Challenge
Senior Red Teamer
Senior Penetration Tester
n-day Researcher
Vulnerability Intelligence Analyst
BLOG
Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive
A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS
Analyzing the Attack Surface of Ivanti's DSM
...
>
CODE WHITE | Red Teaming & Attack Surface Management
>
Authors
>
Markus Wulftange
A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS
Teaching the Old .NET Remoting New Exploitation Tricks
Leaking ObjRefs to Exploit HTTP .NET Remoting
Exploiting ASP.NET TemplateParser — Part II: SharePoint (CVE-2023-33160)
Exploiting ASP.NET TemplateParser — Part I: Sitecore (CVE-2023-35813)
JMX Exploitation Revisited
Bypassing .NET Serialization Binders
.NET Remoting Revisited
RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through
Liferay Portal JSON Web Service RCE Vulnerabilities
Exploiting H2 Database with native libraries and JNI
Telerik Revisited
Poor RichFaces
AMF – Another Malicious Format
Compromised by Endpoint Protection: Legacy Edition
Java and Command Line Injections in Windows
Compromised by Endpoint Protection
Reading/Writing files with MSSQL's OPENROWSET
CVE-2015-0935: PHP Object Injection in Bomgar Remote Support Portal
$@|sh – Or: Getting a shell environment from Runtime.exec