Accueil
devl00p's infosec stuff
Annuler

SSRF dans le plugin Wordpress Webmention

Présentation du plugin Le plugin Webmention se présente de cette façon : A Webmention is a notification that one URL links to another. Sending a Webmention is not limited to blog posts, and ca...

Writeups for Huntress 2023 Warmups challenges

Baking Description Do you know how to make cookies? How about HTTP flavored? Solution You are given a URL to a webapp that looks like an oven. You can click several buttons, and it will pu...

Writeup for the Huntress 2023 Steganography challenge

Land Before Time Description This trick is nothing new, you know what to do: iSteg. Look for the tail that’s older than time, this Spike, you shouldn’t climb. Solution LSB (Least Significan...

Writeups for Huntress 2023 Miscellaneous challenges

Babel Description It’s babel! Just a bunch of gibberish, right? Solution This is not gibberish. This is a C# source code which has been a little bit obfuscated : using System; using System...

Writeups for Huntress 2023 Malware challenges

Batchfuscation Description I was reading a report on past Trickbot malware, and I found this sample that looks a lot like their code! Can you make any sense of it? Solution We are given a b...

Writeup for Huntress 2023 M Three Sixty Five challenges (Azure AD)

Description For this challenge, you can connect into a PowerShell Core instance. Note that this is running out of a Linux-based Docker container, so you do not have a full-blown Windows operati...

Writeups for Huntress 2023 Forensics challenges

Backdoored Splunk Description You’ve probably seen Splunk being used for good, but have you seen it used for evil? NOTE: the focus of this challenge should be on the downloadable file below...

Faille d'injection SQL dans le plugin Wordpress Loginplus

Présentation du plugin Le plugin Loginplus se présente de cette façon : Login plus changes WordPress Login Logo and Logo Url without altering any core file. See Login Logs like Hacking attempt...

Faille d'injection SQL dans le plugin Wordpress LogDash Activity Log

Présentation du plugin Le plugin LogDash Activity Log (slug: logdash-activity-log) se présente de cette façon : LogDash Activity Log is the ultimate solution for tracking activities on your Wo...

Cross-Site Scripting (reflected) dans le plugin Wordpress Like DisLike Voting

Présentation du plugin Le plugin Like DisLike Voting (slug: like-dislike-voting) se présente de cette façon : Get like-dislike rating for your content. You can use the plugin to allow your use...