Accueil
devl00p's infosec stuff
Annuler

Cross-Site Scripting (reflected) dans le plugin Wordpress Valz Display Query Filters

Présentation du plugin Le plugin Valz Display Query Filters se présente de cette façon : This plugin, once activated, spits out the information passed by each filter used in manipulating datab...

Cross-Site Scripting (reflected) dans le plugin Wordpress NanoSupport — Support Ticketing & Knowledgebase for WordPress

Présentation du plugin Le plugin NanoSupport — Support Ticketing & Knowledgebase for WordPress (slug: nanosupport) se présente de cette façon : Create a fully featured Support Center withi...

Open Redirect dans le plugin Wordpress Multipurpose CSS3 Animated Buttons

Présentation du plugin Le plugin Multipurpose CSS3 Animated Buttons se présente de cette façon : Multipurpose CSS3 Animated Buttons allow you to select between social media buttons or your own...

SSRF dans le plugin Wordpress Webmention

Présentation du plugin Le plugin Webmention se présente de cette façon : A Webmention is a notification that one URL links to another. Sending a Webmention is not limited to blog posts, and ca...

Writeups for Huntress 2023 Warmups challenges

Baking Description Do you know how to make cookies? How about HTTP flavored? Solution You are given a URL to a webapp that looks like an oven. You can click several buttons, and it will pu...

Writeup for the Huntress 2023 Steganography challenge

Land Before Time Description This trick is nothing new, you know what to do: iSteg. Look for the tail that’s older than time, this Spike, you shouldn’t climb. Solution LSB (Least Significan...

Writeups for Huntress 2023 Miscellaneous challenges

Babel Description It’s babel! Just a bunch of gibberish, right? Solution This is not gibberish. This is a C# source code which has been a little bit obfuscated : using System; using System...

Writeups for Huntress 2023 Malware challenges

Batchfuscation Description I was reading a report on past Trickbot malware, and I found this sample that looks a lot like their code! Can you make any sense of it? Solution We are given a b...

Writeup for Huntress 2023 M Three Sixty Five challenges (Azure AD)

Description For this challenge, you can connect into a PowerShell Core instance. Note that this is running out of a Linux-based Docker container, so you do not have a full-blown Windows operati...

Writeups for Huntress 2023 Forensics challenges

Backdoored Splunk Description You’ve probably seen Splunk being used for good, but have you seen it used for evil? NOTE: the focus of this challenge should be on the downloadable file below...