Aggregator
雷神众测漏洞周报2024.09.18-2024.09.22
HITCON CTF & corCTF & sekaiCTF 2024 筆記
久違的筆記,想寫很久了但一直拖延,像是 CTF 這種東西的 writeup 其實速度滿重要的,因為賽後討論大部分都在 Discord 裡面發生,時間久了訊息比較難找,而且很有可能忘記,要趕快寫成 writeup 才能把那些實用的資訊記錄下來。
這篇一次帶來三個 CTF 的 writeup,有些我沒有打,只是純粹看著別人的筆記重新記一遍而已。
關鍵字列表:
- bfcache
- response splitting
- Service-Worker-Allowed
- gunicorn script_name
- socket.io disconnect
- socket.io JSONP CSP bypass
- performance API
- streaming HTML parsing
- content-type ISO-2022-JP
LinkedIn Pauses GenAI Training Following ICO Concerns
CVE-2024-8903 | Acronis Cyber Protect Cloud Agent 36943/37758/38235 on Windows/macOS Setting unnecessary privileges
CVE-2016-7258 | Microsoft Windows 10/Server 2016 Kernel Memory Address information disclosure (MS16-152 / Nessus ID 95769)
安全热点周报:时隔一周,Ivanti 又公开一云服务设备漏洞正面临在野利用
对话地瓜机器人 CEO 王丛:500 元的机器人「心脏」,是怎么炼成的?
CVE-2024-45348 | Xiaomi Router AX9000 1.0.173 command injection
Bitdefender debuts GravityZone PHASR, enhancing security through user behavior analysis
Bitdefender has unveiled Bitdefender GravityZone Proactive Hardening and Attack Surface Reduction (PHASR), a technology that transforms how defense-in-depth-security is applied and managed across businesses. GravityZone PHASR analyzes individual user behavior such as application use, resource privileges, and others, clustering users into groups with similar patterns. This approach ensures security policies and controls are mapped precisely to user intended privileges and behaviors, dynamically adjusting as the attack surface evolves. Security teams struggle to keep pace as … More →
The post Bitdefender debuts GravityZone PHASR, enhancing security through user behavior analysis appeared first on Help Net Security.
Critical Expat Vulnerabilities Fixed: Urgent Update Required
A recent discovery has highlighted significant security risks within the widely used Expat XML parsing C library. Security researcher Shang-Hung Wan identified three critical Expat vulnerabilities that could potentially lead to denial-of-service attacks or the execution of arbitrary code. These vulnerabilities are identified in versions of libexpat before 2.6.3 and have the severity score of […]
The post Critical Expat Vulnerabilities Fixed: Urgent Update Required appeared first on TuxCare.
The post Critical Expat Vulnerabilities Fixed: Urgent Update Required appeared first on Security Boulevard.