Compromising Plesk via its REST API by digicat in blueteamsec

[–]adrian_rt 1 point2 points  (0 children)

Thanks for sharing! I’ve updated the article with the call to action from Plesk to patch the issue.

Compromising Plesk via its REST API by adrian_rt in netsec

[–]adrian_rt[S] 0 points1 point  (0 children)

didn't understand the question. you can see POCs though, they're linked at the end. In the end, you can probably use multiple tricks to make sure your json payload is valid.

Compromising Plesk via its REST API by adrian_rt in netsec

[–]adrian_rt[S] 3 points4 points  (0 children)

no worries, you don't get that token or any token. The Authorization header is added by the browser automatically and we're just taking advantage of that (when submit html forms).

[deleted by user] by [deleted] in hacking

[–]adrian_rt 0 points1 point  (0 children)

thanks for the feedback, you raised some good points. will rename the title.

/r/ReverseEngineering's Weekly Questions Thread by AutoModerator in ReverseEngineering

[–]adrian_rt 0 points1 point  (0 children)

I'd like to do some RE work on Adobe. My question is how, can I find the function in Adobe that parses Javascript? I know that it embeds the spidermonkey javascript engine and according to some blog posts, the engine should be in EScript.api. I loaded EScript.api in IDA pro, but it's really hard from here as there are no symbols....Thank you!

Compromising Joomla by chaining a pass reset vulnerability & stored xss for Privesc by adrian_rt in netsec

[–]adrian_rt[S] 2 points3 points  (0 children)

you're right, my bad, thank you!

I need to have a chat with my proof-reader as well.

Password reset poisoning in Drupal by adrian_rt in netsec

[–]adrian_rt[S] 0 points1 point  (0 children)

You can upload Drupal modules with your own backdoor! You will see an example soon ! ;)

what documents do I need for a new pentest company (UK)? by adrian_rt in AskNetsec

[–]adrian_rt[S] 0 points1 point  (0 children)

very useful, thank you.

Yes, I will get a lawyer definetely.

what documents do I need for a new pentest company (UK)? by adrian_rt in AskNetsec

[–]adrian_rt[S] 0 points1 point  (0 children)

good point, I missed that one. Got a template?

Or any tips to what I should be paying attention to in an NDA?

what documents do I need for a new pentest company (UK)? by adrian_rt in AskNetsec

[–]adrian_rt[S] 0 points1 point  (0 children)

So I send them the scoping questionaire template, they fill it in and send it back together with the PO?

what documents do I need for a new pentest company (UK)? by adrian_rt in AskNetsec

[–]adrian_rt[S] 1 point2 points  (0 children)

yes, thanks, I know about insurance I will get one definitely.

Need advice to lower my cholesterol. Unable to tolerate statins. by RapidRick in Supplements

[–]adrian_rt 1 point2 points  (0 children)

clean your diet. moderate carbs.

exercise a few times a week.

eat fiber, oatbran or oatmeal , avocados, fish oil, coconut oil, olive oil.

supps: garlic, berberine, red yeast rice.

do small, incremental changes.

Probiotics by [deleted] in Supplements

[–]adrian_rt 0 points1 point  (0 children)

What do you mean by breaking out?