REDTEAM.PL TECHBLOG

cybersecurity, red teaming, threat hunting

Home

Pages

  • REDTEAM.PL
  • RTFS.PL

CVE-2019-10677 Multiple Cross-Site Scripting (XSS) in the web interface of DASAN Zhone ZNID

With recent software update of DASAN Zhone Solutions (DZS) routers, the company pushed fixes for multiple vulnerabilities I found in it [ h...
September 05, 2019 by Adam Ziaja
Newer Posts Older Posts Home
  • 2020
  • August (2)
  • July (1)
  • June (3)
  • May (1)
  • April (1)
  • March (1)
  • January (1)
  • 2019
  • December (1)
  • October (2)
  • September (1)
  • CVE-2019-10677 Multiple Cross-Site Scripting (XSS)...
  • August (1)
  • May (5)
  • April (1)
  • 2018
  • February (1)
  • 2017
  • October (1)
  • September (1)
  • August (2)
  • July (3)

Popular Posts

  • Stealing local files using Safari Web Share API
    Description In general Web Share API [ https://w3c.github.io/web-share/ ] allows users to share links from the browser via 3rd party appl...
  • Sinkholing BadWPAD infrastructure - wpad.pl / wpadblocking.com case (part 4)
    Introduction We started research related to BadWPAD attack ( WPAD Name Collision Vulnerability [ https://www.us-cert.gov/ncas/alerts/TA...
  • Threat hunting using DNS firewalls and data enrichment
    After seeing a few advertisements about DNS firewalls and how expensive they are, I want to share my experience with blue teamers about h...
  • Internal domain name collision
    Brief introduction Internal domain name collisions occurs when the organisations are using local domains in the internal network and the...
  • DNS based threat hunting and DoH (DNS over HTTPS)
    Malicious communication over encrypted HTTPS channel is in fact nothing new, but DoH (DNS Queries over HTTPS [ https://tools.ietf.org/html/...
  • Rocket.Chat Cross-Site Scripting leading to Remote Code Execution CVE-2020-15926
    Product description Rocket.Chat [ https://rocket.chat ] is an open source multiplatform messaging application similar to Slack. It is ava...
  • DNS for red team purposes
    Introduction In the following blog post I would like to demonstrate a proof-of-concept for how red teamers can build DNS command & c...
  • Deceiving blue teams using anti-forensic techniques
    Brief introduction In this short post I would like to demonstrate one of the techniques used by red teamers and real attackers to set up...
  • BadWPAD, DNS suffix and wpad.pl / wpadblocking.com case
    Quoting resolv.conf (Linux) man page for “ search ” option: “ Search list for host-name lookup. The search list is normally determined fro...
  • Google Chrome portal element fuzzing
    Background Some time ago, while browsing my Twitter feed I stumbled upon an interesting tweet from Michał Bentkowski [ https://twitter.c...

Contributors

  • Adam Ziaja
  • Pawel Wylecial

Subscribe To

Posts
Atom
Posts
All Comments
Atom
All Comments
Copyright © REDTEAM.PL. All Rights Reserved. Powered by Blogger.