CarolinaCon Online 2 will be hosted April 29th to May 1st, 2022. The conference will be virtual and submitted talks will be live streamed.
fff7bbd7db49ebd9315d7d680ff911339bafb26146b0e7b53c22f7e97b628388
The 27th European Symposium on Research in Computer Security (ESORICS) 2022 call for papers has been announced. It will take place September 26th through the 30th, 2022, in Copenhagen, Denmark.
d6d561f5decef2aeebfa90197d0283329d02bb79413abb4a528024c02cec78af
Whitepaper that gives exploitation and overview details on the Log4j vulnerability as noted in CVE-2021-44228.
1718bbf0d45e1ebf16dbdf6e329a8b2f32b620f142e69ae4db5a2403502ff6ac
Whitepaper that explains a misconfiguration based flaw about Local Administrator Password Solution.
afd186867562453b4d7f00ad96270e7a4c5c6b2facd655ef9e4e3c6d602fb576
Whitepaper that gives an overview of the LightSpeed cache vulnerability as noted in CVE-2020-29172.
6b116687f316d0d1b0c270c949274568a68280101b8f2b8703b1d129c2fd14fe
Brief whitepaper that discusses well-known standards like OWASP Top 10, OWASP ASVS, WASC and CWE SANS 25.
bb8c3ba79e4589a5aa83121ea754034f9c5a42dd7b26ad8c48c817a89a9ea285
This is a brief write up discussing insecure functions susceptible to classic buffer overflows.
6c56ef6f21fb5c517c4f05fbff6461b2f130d800355ad39593d8b2f06bee3943
Call For Papers for RootedCON 2022, a technology congress that will be held in Madrid, Spain March 10th through the 12th of 2022. The conference has a capacity of 2,500 to 3,000 people.
6494ed735b857e402c7c71ec3ad563f3512c3a165f5484d32389022c1d1f3f1d
Whitepaper titled CurveBall Windows CryptoAPI Spoofing that discusses the CVE-2021-0601 vulnerability.
728bd43bdaed0560d5327ad21645854d75e4367110b510fd004bcf6753926332
Whitepaper discussing untrusted data deserialization in jsoniter. Written in Spanish.
bfcbc92c461eee304f389597423031549d816389de0416f3fa662b1cb15e3995
Whitepaper that gives an overview of the Polkit vulnerability as discussed in CVE-2021-3560. Written in Spanish.
a41b8393ce5c22e793b28b10b8d6c72d64b22b0b06202998991ab9e195b4ef1c
This is a whitepaper that discusses DNS spoofing. Written in Spanish.
f2ea4bf58281fa68bc973561373c15277c62566c003a2f7a9096cddecd79929e
This document covers a vulnerability in policy kit (polkit) used on many Linux distributions, which enables an unprivileged local user to get a privileged shell (root) on the system by manually sending dbus messages to the dbus-daemon, then killing the request before it has been fully processed.
ff7bcacb2c7403598821beac18efca74a1f7003754707a0f87aff49223d1293a
Whitepaper called Mail Information Gathering AppScript. This paper contains the exploitation of vulnerabilities for collecting email information using Google utilities via App Script using the Gmail App class. This paper exposes the design of a web application that collects mail information from users with associated Google mail accounts.
bb58e73be8e657614e1304dca838b2c7c09c9f5bf8e0bb733adf4f93ad1f3671
This whitepaper is an overview on the Microsoft MSHTML remote code execution vulnerability recently highlighted in CVE-2021-40444.
087e3d97e374ce1d4b7286735f7a428ab28ea89b53f87246c6b35e526a161c30
The Nullcon Berlin 2022 Call For Papers is open. It will take place April 8th through the 9th, 2022 in Berlin, Germany.
198c70e918acee017241f39e3a28687dd2d5c957ff48b61de4f62dee5c5b1c00
This document aims at explaining some recent vulnerabilities in Apache HTTP Server that leads to attacks like path traversal and remote code execution.
f1aae18afbd9ad17a4af83ba0fe8f963226438309f210e48576d57b0bdf705a2
This whitepaper provides an overview of a Polkit authentication bypass vulnerability that allows for local privilege escalation.
93e86eaad4a245a57200302487bb9941411bfdb877a212d1a63b777283e5ebdb
Whitepaper called Wireshark for Newbies. Written in Spanish.
4eba6ef7844800c28ebd51692b48a6153ba4549162d4af3786f0e308332432db
Whitepaper that gives an analysis of the remote code execution vulnerability noted in CVE-2019-11932 for WhatsApp that affects versions prior to 2.19.244. Written in Spanish.
7866772d314829babcae8d60f3a6173f7e55759aac6e5184ca91290e471e6320
Whitepaper called PrintNightmare Vulnerability. This document illustrates the exploitation of the vulnerability found in the Windows spooler service. Originally thought to be a local privilege escalation vulnerability in the Windows Print Spooler, identified as CVE-2021-1675 and patched during Microsoft's June Patch. Microsoft increased the severity of this issue on June 21 as well as reclassifying it as a 'remote code execution' (RCE) threat. This RCE vulnerability has been assigned a new identifier, CVE-2021-34527.
a5647c132e4877c92a507d0bcd1ac0ea57ab7bb3dca97b06b3806f2dcf13942f
In this paper, the authors conduct an analysis of the previously over-looked attack surface related to DNS, and are able to uncover even stronger side channels that have existed for over a decade in Linux kernels. The side channels affect not only Linux but also a wide range of DNS software running on top of it, including BIND, Unbound and dns-masq. They also discovered that about 38% of open resolvers (by frontend IPs) and 14% (by backend IPs) are vulnerable including the popular DNS services such as OpenDNS and Quad9.
285348238e1453af785253da8bbd1e4ba41081c23566393003c3960304917844
Whitepaper called Pass-The-Hash Attack on Named Pipes against ESET Server Security. Written in Spanish.
f9316a93cdca8ab23c7d80dd39ad820bd1df91d1d115107172ebf3e6abcf7799
The call for papers has been announced for the 4th international workshop in Artificial Intelligence and Industrial Internet-of-Things Security (AIoTS). It will be co-located with the ACNS2022 conference June 20 through the 23rd in Rome, Italy.
93e3635739ba0bfd607e2ca07b7aed66f2efbf31ba1d7bb6fb8e6f40b4743083
Whitepaper discussing the OWASP top ten and security of APIs. Written in Spanish.
5d6c059cffab55d95f06d12ecf6b042c525b6ac3c50432367d0c388815310a67