CODE WHITE - FINEST HACKING
Intelligence Driven Security
Initial Assessment
Security Intelligence Service
About us
PUBLIC VULNERABILITY LIST
Unauthenticated Remote Code Execution via Deserialization of Untrusted Data in mediDOK
Multiple Vulnerabilities in GFI MailEssentials
Unauthenticated ServerSide TemplateInjection in Metazo
...
CAREERS
Challenge
Senior Red Teamer
Senior Penetration Tester
Vulnerability Intelligence Analyst
BLOG
Analyzing the Attack Surface of Ivanti's DSM
Teaching the Old .NET Remoting New Exploitation Tricks
Leaking ObjRefs to Exploit HTTP .NET Remoting
...
>
CODE WHITE | Red Teaming & Attack Surface Management
>
Authors
>
Matthias Kaiser
LethalHTA - A new lateral movement technique using DCOM and HTA
Marshalling to SYSTEM - An analysis of CVE-2018-0824
Exploiting Adobe ColdFusion before CVE-2017-3066
Return of the Rhino: An old gadget revisited
Infiltrate 2016 Slidedeck: Java Deserialization Vulnerabilities
CVE-2015-3269: Apache Flex BlazeDS XXE Vulnerabilty
Exploiting the hidden Saxon XSLT Parser in Ektron CMS
How I could (i)pass your client security