The Top 10 Not So Common SSH Usernames and Passwords, (Wed, Oct 16th)

Our list of “Top” ssh usernames and password is pretty static. Well known defaults, like “root” and “admin” are at the top of the list. But there are always some usernames and password in the list that are not as well known, or only showed up more recently. I will focus in this diary on these “second tier” credentials.

Continue reading The Top 10 Not So Common SSH Usernames and Passwords, (Wed, Oct 16th)

Posted in Uncategorized

Angular-base64-update Demo Script Exploited (CVE-2024-42640), (Tue, Oct 15th)

Demo scripts left behind after installing applications or frameworks are an ongoing problem. After installation, removing any “demo” or “example” folders is usually best. A few days ago, Ravindu Wickramasinghe noticed that the Angular-base64-upload project is leaving behind a demo folder with a script allowing arbitrary file uploads without authentication [1]. Exploitation of the vulnerability is trivial. An attacker may use the file upload script to upload a web shell, and in response, the attacker will obtain remote command execution with all the privileges granted to the web server.

Continue reading Angular-base64-update Demo Script Exploited (CVE-2024-42640), (Tue, Oct 15th)

Posted in Uncategorized

Phishing Page Delivered Through a Blob URL, (Mon, Oct 14th)

I receive a lot of spam in my catch-all mailboxes. If most of them are not interesting, some still attract my attention. Especially the one that I&#;x26;#;39;ll describe in this diary. The scenario is classic, an important document is pending delivery but… the victim needs to authenticate to get the precious! As you can see in the screenshot below, the phishing kit supports well-known service providers.

Continue reading Phishing Page Delivered Through a Blob URL, (Mon, Oct 14th)

Posted in Uncategorized