❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayHacking Tutorials

Installing Rogue-jndi on Kali Linux

10 January 2022 at 03:02

Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example) in response to the forged [...]

The post Installing Rogue-jndi on Kali Linux appeared first on Hacking Tutorials.

Log4Shell VMware vCenter Server (CVE-2021-44228)

17 December 2021 at 03:40

Log4Shell is a critical vulnerability with the highest possible CVSSv3 score of 10.0 that affects thousands of products running Apache Log4j and leaves millions of targets potentially vulnerable. CVE-2021-44228 affects log4j versions 2.0-beta9 to 2.14.1. Log4j is an incredibly popular logging library used in many different products and various Apache frameworks like Struts2, Kafka, and [...]

The post Log4Shell VMware vCenter Server (CVE-2021-44228) appeared first on Hacking Tutorials.

The Great Leak: Microsoft Exchange AutoDiscover Design Flaw

27 September 2021 at 08:05

Recently a β€œdesign flaw” in the Microsoft Exchange’s Autodiscover protocol was discovered by researchers that allowed access to 372,072 Windows domain credentials and 96,671 unique sets of credentials from applications such as Microsoft Outlook and third-party email clients. According to Amit Serper , the person who discovered the flaw, the source of the leak is [...]

The post The Great Leak: Microsoft Exchange AutoDiscover Design Flaw appeared first on Hacking Tutorials.

❌
❌