Tue 24 March 2020
This articles intends to bring an exploitation scenario encountered during a common penetration test.
Mon 09 March 2020
In this whitepaper, Lexfo analyses Lazarus malwares, from their motives, to their detection and mitigation, through their techniques, tactics, procedures.
Mon 06 January 2020
We demonstrate how one can recover mt_rand()'s seed with only two outputs and without any bruteforce.
mt_rand()
Fri 29 March 2019
Several flaws have been identified in the latest version of Magento 2, allowing an attacker to obtain complete control over the server. We're now releasing the exploit for the unauthenticated SQL injection. We'll release the details for the RCE vulnerability at a later time.
Fri 22 February 2019
Exploitation and mitigation bypasses for the new Drupal 8 RCE (SA-CORE-2019-003, CVE-2019-6340), targeting the REST module.
Tue 02 October 2018
The first article covers an in-depth CVE/bug analysis, designs an attack scenario and starts implementing a PoC in ring-0 with SystemTap. The core concept section focuses on file/socket related data structures, netlink and refcounters.
Check our offensive & continuous web security assessment service