Welcome to no-sec blog, where a team of passionate Telekom MMS pentesters shares their insights and expertise from the world of cybersecurity. From CVE write-ups to practical guides on exploitation techniques and defense strategies, we aim to contribute valuable knowledge to the security community.
Investigating CVE-2019-19781 on Citrix NetScaler appliances
We got quite a few cases related to CVE-2019-19781 during the past few weeks. However, most of the NetScaler VM images we got were acquired after the appliances were shut down, so we had no RAM image data. Unfortunately, this also implicates the loss of the root file system `/`, as it turned out that the root partition was mounted as a RAM disk.
Read more ⟶Write-up Hackvent 2019
Like the past few years, the HackingLab Team provided the white-hat hacking competition Hackvent in the form of a advent calendar. From December 1^(st) to 24^(th) , each day, a new challenge was released that has to be solved in-time for scoring full points. Like the past years, challenges were provided from various community members.
Read more ⟶ARM-X Challenge Breaking the webs
At the beginning of November, @therealsaumil announced a brand new IP camera CTF challenge on Twitter This sounded like the perfect opportunity to try out his new ARM-X IoT Firmware Emulation Framework.
Read more ⟶Write-up Flare-On 6
From August 16 to September 27, FireEye’s FLARE team ran the Flare-On challenge for the 6th straight year (see announcement, here). This CTF-style challenge is comprised of 12 reverse-engineering tasks for different architectures. Like the past years, it was a great event with so much new things learned.
Read more ⟶Write-up DVAR ROP Challenge
Not long after I took the „ARM IoT Exploit Laboratory“ training by @therealsaumil, the following tweet popped up on my timeline Since ROPping on ARM can easily become a major pain, I decided to take a look at the DVAR ROP Challenge.
Read more ⟶Writeup KringleCon 2018
The annual Holiday Hack Challenge by SANS and the Counterhack team takes place during Christmas time and is always entertaining and great for learning a new trick (or two). This year, the challenge was organized as an online conference, called KringleCon with great talks and a well thought-out story.
Read more ⟶BurpSuite – Update HTTP Header in Session Handling Rules
First, this post will not cover the basics of recoding macros or use of the session handling rules in BurpSuite
Read more ⟶Wammer – WiFi jamming made easy
Since years the IEEE 802.11 WiFi protocol has a well-known design flaw which allows attackers to disconnected clients from the WiFi access point they’re connected to.
Read more ⟶Bypass Kiosk Mode with Libre/Open Office
Given you have restricted access to a computer and can only open certain programs. Usually this is caused by the Kiosk Mode that has a white list which contains only trusted programs. Libre/Open Office is a widely used/unlocked program on such Kiosk Modes.
Read more ⟶Chrome Information Leakage – Prediction Service & Preload
Last year in February, I found a vulnerability at google chrome and submitted it(Bug Report). So far nothing has happened and now the vulnerability has been published on twitter https://twitter.com/zerosum0x0/status/958890437837692928
Read more ⟶