Assetnote Research
https://www.assetnote.io
Fundamentally change how you secure your attack surface. Assetnote's industry-leading Attack Surface Management Platform gives security teams continuous insight and control over their ever-evolving exposure.
フィード
Insecurity through Censorship: Vulnerabilities Caused by The Great Firewall
Assetnote Research
We detail several practical client-side attacks that can result from DNS poisoning observed for domains hosted in China. These attacks impact every domain on the Internet that uses a nameserver located in China, and it's estimated that more than 30 million domains are vulnerable to this.
2ヶ月前
Chaining Three Bugs to Access All Your ServiceNow Data
Assetnote Research
Through the course of 3/4 weeks, we were able to find a chain of vulnerabilities that allows full database access and full access to any MID servers configured. This resulted in 3 separate CVE's.
3ヶ月前
Why nested deserialization is harmful: Magento XXE (CVE-2024-34102)
Assetnote Research
A critical, pre-authentication XML entity injection issue in Magento / Adobe Commerce (CVE-2024-34102), which Adobe rated as CVSS 9.8.
5ヶ月前
Digging for SSRF in NextJS apps
Assetnote Research
At Assetnote, we encounter sites running NextJS extremely often; in this blog post we will detail some common misconfigurations we find in NextJS websites, along with a vulnerability we found in the framework.
6ヶ月前
Advisory: Next.js SSRF (CVE-2024-34351)
Assetnote Research
Assetnote Security Advisory: A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the Host header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. An attacker is able to read the full HTTP response when successfully exploiting this SSRF issue.
6ヶ月前
Advisory: Progress WS_FTP RCE (CVE-2023-40044)
Assetnote Research
Assetnote Security Advisory: An attacker can exploit this vulnerability without authentication, to execute arbitrary commands on the Progress WS_FTP server through the deserialization of untrusted data. An attacker must be able to access the WS_FTP web server and the Ad Hoc Transfer application in order to exploit this issue.
6ヶ月前
Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762
Assetnote Research
Early this February, Fortinet released an advisory for an "out-of-bounds write vulnerability" that could lead to remote code execution. The issue affected the SSL VPN component of their FortiGate network appliance and was potentially already being exploited in the wild. In this post we detail the steps we took to identify the patched vulnerability and produce a working exploit.
8ヶ月前
Citrix Bleed: Leaking Session Tokens with CVE-2023-4966
Assetnote Research
It's time for another round Citrix Patch Diffing! Earlier this month Citrix released a security bulletin which mentioned "unauthenticated buffer-related vulnerabilities" and two CVEs. These issues affected Citrix NetScaler ADC and NetScaler Gateway.
8ヶ月前
Continuing the Citrix Saga: CVE-2023-5914 & CVE-2023-6184
Assetnote Research
While most of the attention for vulnerabilities within Citrix has been on their NetScaler VPN product, we noticed that there were several other products offered by Citrix that require an on-premise deployment of a web application, that is sometimes internet facing. This piqued our interest and led us to investigate the security of these self-hosted applications.
8ヶ月前
Finding and Exploiting Citrix NetScaler Buffer Overflow (CVE-2023-3519) (Part 3)
Assetnote Research
9ヶ月前
Ivanti's Pulse Connect Secure Auth Bypass Round Two
Assetnote Research
The Ivanti excitement continues! After an authentication bypass and command injection to kick off the year, Ivanti are following with a second authentication bypass and a privilege escalation. On January 22 Ivanti released this advisory describing the two new vulnerabilities in Ivanti Connect Secure, CVE-2024-21888 (privilege escalation) and CVE-2024-21893 (authentication bypass).
9ヶ月前
Getting access to Zendesk’s Google Cloud and Artifactory from GitHub dotfile repos
Assetnote Research
10ヶ月前
Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135)
Assetnote Research
10ヶ月前
RCE in Progress WS_FTP Ad Hoc via IIS HTTP Modules (CVE-2023-40044)
Assetnote Research
Over the last year or so, we've seen the mass exploitation of managed file transfer software. From GoAnywhere MFT, MOVEIt, and our own work on Citrix Sharefile. The threats towards enterprises through managed file transfer software has really hit home after the recent ransomware attack by Cl0p, leveraging a series of vulnerabilities in Progress MOVEIt.
10ヶ月前
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE
Assetnote Research
Last week, Ivanti disclosed two critical vulnerabilities affecting Ivanti Pulse Connect Secure - CVE-2023-46805 (Authentication Bypass) & CVE-2024-21887 (Remote Command Execution).
10ヶ月前
Leaking File Contents with a Blind File Oracle in Flarum
Assetnote Research
Our security researchers identified a critical vulnerability inside Flarum (popular forum software) which allows attackers to read local files from the system.
10ヶ月前
Advisory: Flarum LFI - CVE-2023-40033
Assetnote Research
Security Advisory: Our security researchers identified a critical vulnerability inside Flarum (popular forum software) which allows attackers to read local files from the system.
10ヶ月前