TARLOGIC's BLOG
Cybersecurity - Page 11
Cybersecurity articles with security analysis and ethical hacking technics information
Vulnerabilities in Televes COAXDATA GATEWAY – CVE-2017-6532
=============================== – Advisory – =============================== Title: Televes COAXDATA GATEWAY 1Gbps – Priv Escalation Risk: High Date: 19.Jul.2017 [...]
Read moreProtections against network privilege escalation
The application of perimeter security controls in each layer of any infrastructure as well as hardening measures in systems enable limiting an intruder lateral movement in the netw[...]
Read moreKerberos tickets: Comprehension and exploitation
The main aim of this post is explaining the most common attacks that can be carried out in a security audit or pentest of Kerberos protocol used in Microsoft active directory domai[...]
Read moreAeroAdmin 4.1 Vulnerability – CVE-2017-8893 CVE-2017-8894
Tarlogic Advisory: Tarlogic-2017-001 Title: Multiple vulnerabilities found in AeroAdmin 4.1 software. Discovered by: Juan Manuel Fernandez (@TheXC3LL) CWE-ID: CWE-119 Improper Rest[...]
Read moreSame-Site cookies against CSRF attacks analysis
CSRF vulnerabilities Cross-site request forgery (CSRF) vulnerabilities are extremely common in web applications. Despite they are known since a long time ago, we are used to find t[...]
Read moreHow PHP Object Injection works
PHP Object Injection enables the arbitrary manipulation of an object content that shall be unserialized using the PHP unserialize() function. This kind of web application vulnerabi[...]
Read moreEnterprise WiFi network security audit from openwrt
The main difficulties found when performing a security audit of Enterprise WiFi network by a security analyst in ethical hacking are the following: WPA Enterprise networks imperson[...]
Read moreBackdoors in IDEs – RootedCON 2015 Talk
This article describes in detail the content of “Bend the developers to your will” talk given by Miguel Tarascó and included in RoodCON 2015 Congress. 1. Why developers? Devel[...]
Read more