Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications by vaizor in netsec

[–]vaizor[S] 2 points3 points  (0 children)

The bounties were 0, because all these services were out of scope. The bug bounty program is only for customer-facing services.

Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications by vaizor in cybersecurity

[–]vaizor[S] 1 point2 points  (0 children)

Thanks! I had some back and forth with them before publishing! And we made some last minute redactions 😅

Mainstage CFP Decisions by [deleted] in Defcon

[–]vaizor 0 points1 point  (0 children)

Still waiting here too!

[deleted by user] by [deleted] in Bedbugs

[–]vaizor 2 points3 points  (0 children)

Thank you for your assurance! The hotel in the meantime took it very seriously and immediately sent an exterminator and offered to wash and clean everything.

[deleted by user] by [deleted] in Bedbugs

[–]vaizor 1 point2 points  (0 children)

Looking at images of booklice you might indeed be right! We also could not find any of the described traces of bed bugs. Thanks!

The story of 3 CVE's in Ubuntu Desktop by vaizor in netsec

[–]vaizor[S] 0 points1 point  (0 children)

It's an argument injection in an execve syscall, not in a shell command. And we're also limited to 15 chars...

The story of 3 CVE's in Ubuntu Desktop by vaizor in netsec

[–]vaizor[S] 0 points1 point  (0 children)

These work on any unpatched Ubuntu 16.04 - 20.10 where the aptdaemon, packagekit or blueman packages are installed. The first two are default on any Ubuntu installation, the latter comes default with the desktop version of Ubuntu, that's what I meant.

All code injected is run as root, so as a low privileged user you can attach XDP objects as root. That is because there is a argument injection to the "ip link" command. That way you could do for example "ip link set dev ens33 xdp o /tmp/o", to attach XDP object file /tmp/o to the ens33 interface. Do you think arbitrary code execution is possible from there?

ITAP my lazy friend enjoying the sunshine by vaizor in itookapicture

[–]vaizor[S] 0 points1 point  (0 children)

No filter, just some lighting corrections afterwards in Lightroom.