Cybersecurity professional with an interest/background in networking. Beginning to delve into binary exploitation and reverse engineering.

  • 1 Post
  • 25 Comments
Joined 1 year ago
cake
Cake day: March 27th, 2024

help-circle

  • No. You can have control over specific parameters of an SQL query though. Look up insecure direct object reference vulnerabilities.

    Consider a website that uses the following URL to access the customer account page, by retrieving information from the back-end database: https://insecure-website.com/customer_account?customer_number=132355 Here, the customer number is used directly as a record index in queries that are performed on the back-end database. If no other controls are in place, an attacker can simply modify the customer_number value, bypassing access controls to view the records of other customers.




  • Just to be clear, I will absolutely create new domain users or add my own ssh keys to an authorized_keys file to escalate privs or move laterally through a network while I’m “hacking”.

    Also a malicious actor opening a reverse port forward tunnel with ssh allows them to punch a hole to them on the WAN side of the network when they’re dealing with NAT or firewall rules. If a system is truly airgapped then that accomplishes nothing. You’d need something plugged in to the airgapped system or airgapped network to bridge that air gap, like a usb adapter that has a SIM card in it.
















  • Dems told him he should not run for a second term, and he ignored them and did it anyway.

    During his 2020 campaign he fucking said he only wanted to serve one term, that he wanted to act as a bridge president. Then he proceeded to do absolutely nothing to put Harris in front of the country, absolutely nothing to set her up for an ezpz “incumbent” primary, and cock blocked the entire fucking country until the last minute.

    I don’t know if he lied to our faces, changed his mind, or just forgot but fuck him regardless.

    Edit - His only fucking job was to win in 2020, then unchain the AG or whoever to bring cases against every single person who used the Constitution as a cum rag as fast as realistically possible. He failed. He won the election in 2020, then just didn’t finish the fucking job. Fucking pathetic joke of an out of touch old.