Bounty Team


  • Home

  • Archives

  • Tags

XStream Vulnerability Notice

Posted on 2021-05-19 | In Vulnerability Notice
Recently, DBAPPSecurity SRC has monitored that XStream has officially released a security update bulletin
Read more »

Chrome issue 1196683 (CVE-2021-21220) vulnerability analysis

Posted on 2021-04-16 | In Vulnerability Analysis
I have not done a very thorough analysis of this vulnerability, so I will be relatively conservative in some of my conclusions.
Read more »

Catch me if you can

Posted on 2021-03-29 | In Windows Analysis
With the introduction of sandboxed mechanism in several major browsers (Chrome, Edge, IE) and word processing software (Office, Adobe Reader) on Windows platform, the demand of Windows kernel privilege vulnerability is also rising.
Read more »

VMware vCenter Server RCE Vulnerability Recurrence

Posted on 2021-03-25 | In Vulnerability Analysis
In an un-arbitrary location of CVE-2021-21972 vmware vcenter and then just execute the webshell.
Read more »

XStream <=1.4.15 Deserialization JNDI Injection

Posted on 2021-03-19 | In Vulnerability Analysis
I found a chain a year ago, but the repair of several chains and I find the sink point and trigger toString point are different, this should be considered a new CVE, here to share out.
Read more »

Untitled

Posted on 2021-05-19
Read more »

Set http redirection for covenant

Posted on 2021-02-21 | In RedTeam Skill
External c2 is not much to say, it is a technology to prevent the real c2 address from leaking and wasting resources and time after being banned by the Blue Team.
Read more »

Analysis of Bluetooth Impersonation Attack (BIAS) Vulnerability Principle

Posted on 2021-02-05 | In Vulnerability Analysis
Boffins disclosed a Bluetooth security vulnerability called BIAS (CVE-2020-10135), which can be used by attackers to spoof remote pairing devices.
Read more »

How do I debug and analyze the Office EPS vulnerability sample?

Posted on 2021-02-03 | In Vulnerability Analysis
Recently, an APT organization began to use Office EPS vulnerability samples to attack again.
Read more »

Analysis of Weblogic T3/IIOP Deserialization Vulnerability (XXE Vulnerability)

Posted on 2021-01-29 | In Vulnerability Analysis
Weblogic T3/IIOP Deserialization & XXE Analysis
Read more »
1 2
Bounty Team

Bounty Team

11 posts
4 categories
25 tags
RSS
© 2021 Bounty Team
浙ICP备09102757号-18