Blogs

../assets/images/featured/CVE-2025-0282-p2.jpg
Ivanti Connect Secure Pre-Auth RCE Walkthrough and Techniques (CVE-2025-0282)

Exploitation walkthorugh of a tricky stack-based buffer overflow over IFT TLS Vpn protocol

../assets/images/featured/CVE-2025-0282.jpg
Ivanti Connect Secure Pre-Auth RCE (CVE-2025-0282)

Initial analysis of a pre-auth RCE vulnerability discovered in ivanti IFT TLS VPN protocol

../assets/images/featured/CVE-2024-50623.jpg
Cleo Harmony - Pre-Auth RCE (CVE-2024-50623)

the CVE-2024-50623 is an arbitrary file read and write in Cleo that leads to Pre-Auth RCE

../assets/images/featured/CVE-2024-47575.jpg
Fortimanager - Pre-Auth RCE Chain

Reverse engineering, authentication bypass and eventually 0day discovery in fortimanager fgfm network protocol

../assets/images/featured/CVE-2024-8068-CVE-2024-8069.jpg
Citrix Virtual Apps and Desktops Pre-Auth RCE

A critical .NET Deserialization vulnerability discoverd in Citrix Session Recording feature and how to trigger it Pre-Auth

../assets/images/featured/ivanti-epm-CVE-2024-29847.jpg
The real slim shady || Ivanti Endpoint Manager (EPM) Pre-Auth RCE

ivanti just pushed a patch for a Critical CVSS 9.8 Remote Code Execution Vulnerability that I reported on May 1st 2024, impacting Ivanti Endpoint Manager (EPM)

../assets/images/featured/CVE-2024-40711.jpg
Veeam Backup & Replication - Pre-Auth (3 bug chain) RCE

Chaining three vulnerabilities in Veeam backup and Replication to achieve Pre-Auth RCE over .NET Remoting

../assets/images/featured/cover-CVE-2024-6670.png
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection in WhatsUp Gold

I discovered an unauthenticatedagainst the latest version of progress whatsup gold and turned it into authentication bypass, this is the story of CVE-2024-6670

../assets/images/featured/whatsup-wcf-01.jpg
WhatsUp Gold Pre-Auth RCE GetFileWithoutZip Primitive

I discovered an unauthenticated path traversal against the latest version of progress whatsup gold and turned it into a pre-auth RCE, following is how I did it, this is the story of CVE-2024-4885

../assets/images/featured/whatsup-wcf-02.jpg
WhatsUp Gold Pre-Auth RCE WriteDataFile Primitive

Using a path traversal vulnerability to achieve remote code execution, this is the story of CVE-2024-4883 a pre-auth RCE against progress whatsup gold

../assets/images/featured/whatsup-CVE-2024-5009.jpg
WhatsUp Gold SetAdminPassword Privilege Escalation

Lets analyze a privilege escalation which I found targeting progress whatsup gold, this is the story of CVE-2024-5009

../assets/images/featured/CVE-2024-5806.jpg
Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806)

A creative authentication bypass technique that we discovered in MOVEit Transfer, yet another .NET Exploitation Technique

../assets/images/featured/veeam-vro-CVE-2024-29855.jpg
There are no Secrets || Exploiting Veeam CVE-2024-29855

This vulenrability is due to the fact that JWT secret used to generate authentication tokens was a hardcoded value which means an unauthenticated attacker can generate valid tokens for any user (not just the administrator) and login to the Veeam Recovery Orchestrator.

../assets/images/featured/veeam-epm-CVE-2024-29849.jpg
Bypassing Veeam Authentication CVE-2024-29849

An interesting authentication bypass exploit in Veeam Backup Enterprise Manager

../assets/images/featured/CVE-2024-4577.jpg
No Way, PHP Strikes Again! (CVE-2024-4577)

yet another interesting php issue for the lolz

../assets/images/featured/report-server-banner.jpg
Molding lies into reality || Exploiting CVE-2024-4358

Discovering a zero-day authentication bypass and chaining a .NET deserialization to achieve pre-auth RCE on Progress Report Server

../assets/images/featured/vrni-cover.png
VMWare Aria Operations for Networks Static SSH key RCE

VMWare Aria Operations for Networks Static SSH key RCE (CVE-2023-34039)

../assets/images/featured/vrni.png
Pre-authenticated RCE in VMware vRealize Network Insight

An interesting case of Pre-authenticated RCE in VMware vRealize Network Insight (CVE-2023-20887)

../assets/images/featured/vmware-nsx-exploited.png
Pre-authenticated Remote Code Execution in VMWare NSX Manager

Discovering a Pre-Auth Java Deserialization to Remote Code Execution in VMWare NSX Manager

../assets/images/featured/veeam-exploit.png
Veeam Unauthenticated Remote Code Execution

Exploiting three different .NET vulnerabilites in veeam backup and replication CVE-2022-26503,CVE-2022-26504,CVE-2022-26500,CVE-2022-26501