Skip to content

WindowsTechs.com

Collaborate Disseminate

Menu

Primary menu

  • Home

Author Archives: Wealot

CVSS score for no-input validation

Posted on May 9, 2017 by Wealot

During a security assesment I found that an application wrote JavaScript from input fields directly in the database. The application it self had good output sanitization so no XSS was possible in that application. A different… Continue reading CVSS score for no-input validation→

Posted in cvss, penetration-test, validation

Responder during pentest risks

Posted on May 8, 2017 by Wealot

I want to use the Responder tool during a pentest to find/show vulnerabilities in how the network is configured. But I am not sure how much effect it would have on the end-users aka the people I have to work with the rest of … Continue reading Responder during pentest risks→

Posted in penetration-test

Macro injection in different Excel versions

Posted on March 27, 2017 by Wealot

I have found a nice macro injection vulnerability in an Excel export functionality. I can inject =1+1 (or worse) into the exported Excel file.

But when opening the file in Excel the formula isn’t directly evaluated at start… Continue reading Macro injection in different Excel versions→

Posted in injection, Office, Vulnerability

Bypass x-frame-options for clickjacking

Posted on March 22, 2017 by Wealot

Is there any way to bypass the x-frame-options header without using a MitM or changing the packets in another way?

So actually getting a site that has x-frame-options: DENY to be shown in an iframe.

Continue reading Bypass x-frame-options for clickjacking→

Posted in clickjacking, penetration-test, Vulnerability

Session Fixation cookie delivery

Posted on March 21, 2017 by Wealot

I found a possibility for session fixation in an application I am researching. It is a session fixation through a session ID cookie. Now I’ve read up on session fixation and the concept is clear and comes down to getting a vi… Continue reading Session Fixation cookie delivery→

Posted in session-fixation, Vulnerability

POST request no-cache header

Posted on March 20, 2017 by Wealot

During security tests/assessments it is often said that you need to set the cache-control to no-cache (and some other things). But as I was looking at this I found that POST requests are not cached (which makes sense) by defa… Continue reading POST request no-cache header→

Posted in caching, HTTP

Burp with whatsapp

Posted on March 15, 2017 by Wealot

While doing some pentesting on an android app with Burp setup as a proxy (with https) I saw no traffic coming from whatsapp messages that I received or send.

I looked around in Burp, but I cannot find out why those messages don’t get int… Continue reading Burp with whatsapp→

Posted in Android, burp-suite, proxy, TLS, Whatsapp

URL injection vulnerability

Posted on March 13, 2017 by Wealot

I am busy with a pentest and found something that made me wonder if it would be exploitable. I am currently not able to exploit it, but I wanted to make sure. Also I am curious why the application/server behaves as it does.

This is the f… Continue reading URL injection vulnerability→

Posted in penetration-test, rest, Vulnerability

MCC records in JPEG2000

Posted on January 11, 2017 by Wealot

I was looking at some image vulnerabilities and came across the fairly new openjpeg vulnerability in JPEG2000 images. It says that: “out of bounds memory can be accessed due to an error in mcc records parsing”.

I wanted to p… Continue reading MCC records in JPEG2000→

Posted in exploit-development, known-vulnerabilities | Tagged Image

Meterpreter HTTPS detected by IPS

Posted on January 9, 2017 by Wealot

I am busy with security testing on a clients network and was asked to show how “easy” AV evasion is. I created a nice powershell reverse HTTPS file through veil-evasion, which is not detected by the Symantec virusscanner (tes… Continue reading Meterpreter HTTPS detected by IPS→

Posted in antivirus, IDS, meterpreter, TLS

Post navigation

← Older posts
Newer posts →

Primary Sidebar Widget Area

Infocon Status

Internet Storm Center Infocon Status

Recent Posts

  • Disney Creates Its Own IMAX for ‘Avengers: Doomsday’ After Losing Screens to ‘Dune: Part 3’ April 19, 2026
  • Qilin’s 2024 attack on NHS vendor continues to impact patient care for one NHS Trust April 19, 2026
  • Building a Rim-Driven Jet Engine April 19, 2026
  • Can the ‘Attention Liberation Movement’ Foment a Rebellion Against Screens? April 19, 2026
  • DIY UPS Keeps Home Assistant Running April 19, 2026

Tag Cloud

Agriculture Alzheimer's Disease Art Audio Automation Bluetooth Building and Construction Campervan Camping Cancer Coronavirus (COVID-19) Cycling Dementia Diabetes DNA Electric Vehicles Food Home House Huawei Indiegogo MIT Mobility Moon New Atlas Audio NVIDIA Off-grid Off-road Pedal-assisted Photography Physics Radio Repair RV Samsung Satellite Sony SpaceX spoofing sustainable design The Immune System Tiny Footprint Training Water Zoom

Archives

  • Facebook
  • Twitter
  • Linkedin
  • Email
Copyright © 2026 WindowsTechs.com. All Rights Reserved.
Theme: Catch Box by Catch Themes
Scroll Up