unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
Looking at the Attack Surfaces of the Kenwood DMX958XR IVI
In our previous Kenwood DMX958XR blog post, we detailed the internals of the Kenwood in-vehicle i...
2024-11-22 00:52:56 | 阅读: 0 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
kenwood
dmx958xr
carplay
remote
mpeg
Looking at the Internals of the Kenwood DMX958XR IVI
For the upcoming Pwn2Own Automotive contest, a total...
2024-11-20 00:52:27 | 阅读: 2 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
dmx958xr
ivi
automotive
boards
murata
The November 2024 Security Update Review
It’s not quite the holiday season, despite what some early decorators will have you believe. It i...
2024-11-13 02:26:35 | 阅读: 4 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
microsoft
cves
windows
attacker
privileges
Multiple Vulnerabilities in the Mazda In-Vehicle Infotainment (IVI) System
Multiple vulnerabilities have been discovered in the...
2024-11-8 06:9:4 | 阅读: 8 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
software
srv
attacker
mcu
Pwn2Own Ireland 2024: Day Four and Master of Pwn
It’s the final day of our first ever Pwn2Own Ireland. After three days of exploitation, we have aw...
2024-10-25 15:56:5 | 阅读: 10 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
pwn2own
ireland
awarded
993
625
Pwn2Own Ireland 2024: Day Three Results
Welcome to Day Three of our first ever Pwn2Own Ireland competition! We’ve already awarded $874,875...
2024-10-24 15:7:7 | 阅读: 4 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
ireland
awarded
874
collisions
irish
Pwn2Own Ireland 2024: Day Two Results
October 23, 2024 | Dustin Childs...
2024-10-23 16:39:30 | 阅读: 2 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
pwn2own
ireland
canon
samsung
qnap
Pwn2Own Ireland Day One - The Results
October 22, 2024 | Dustin Childs...
2024-10-22 15:25:8 | 阅读: 6 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
pwn2own
ireland
security
dustin
tremendous
Pwn2Own Ireland - The Full Schedule
Welcome to Pwn2Own Ireland 2024 - our first event eve...
2024-10-22 01:2:59 | 阅读: 1 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
network
synology
qnap
security
vcslab
The October 2024 Security Update Review
It’s the spooky season, and there’s nothing spookier than security patches – at least in my world...
2024-10-9 01:54:47 | 阅读: 5 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
microsoft
attacker
windows
remote
cves
From Pwn2Own Automotive: More Autel Maxicharger Vulnerabilities
The vulnerable function is responsible for handling ACMP messages received from a websockets server...
2024-10-4 00:5:14 | 阅读: 17 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
overflow
decoded
attacker
firmware
acmp
Exploiting Exchange PowerShell After ProxyNotShell: Part 4 – No Argument Constructor
As you may know, I recently presented my Exchange-rela...
2024-9-27 02:25:7 | 阅读: 11 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
exchange
powershell
conversion
remoting
deserialize
Announcing Pwn2Own Automotive for 2025
If you just want to read the rules, you can find them...
2024-9-24 22:58:14 | 阅读: 13 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
pwn2own
contest
automotive
tesla
vehicle
Exploiting Exchange PowerShell After ProxyNotShell: Part 3 – DLL Loading Chain for RCE
As you may know, I recently presented my Exchange-rel...
2024-9-20 02:2:10 | 阅读: 13 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
expand
exchange
attacker
windows
Exploiting Exchange PowerShell After ProxyNotShell: Part 2 - ApprovedApplicationCollection
As you may know, I recently presented my Exchange-related talk during OffensiveCon 2024. This seri...
2024-9-12 23:0:0 | 阅读: 12 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
extrac32
exchange
microsoft
windows
deny
The September 2024 Security Update Review
We’ve reached September and the pumpkin spice floats in the air. While they aren’t pumpkin-spiced...
2024-9-11 01:25:32 | 阅读: 8 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
microsoft
windows
attacker
security
zdi
Exploiting Exchange PowerShell After ProxyNotShell: Part 1 - MultiValuedProperty
In this article, part one of the series, I describe the...
2024-9-5 23:39:37 | 阅读: 9 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
exchange
attacker
microsoft
powershell
Abusing Arbitrary File Deletes to Escalate Privilege and Other Great Tricks (Archive)
This version of the blog is preserved for archival purposes only. An updated version of this blog, i...
2024-9-3 23:51:7 | 阅读: 7 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
windows
eop
rbs
rollback
oplock
CVE-2024-37079: VMware vCenter Server Integer Underflow Code Execution Vulnerability
In this excerpt of a Trend Micro Vulnerability Researc...
2024-8-28 23:0:0 | 阅读: 19 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
trailer
spnego
client
dcerpc
From Pwn2Own Automotive: Taking Over the Autel Maxicharger
This blog highlights two vulnerabilities that were di...
2024-8-23 01:47:11 | 阅读: 4 |
收藏
|
Zero Day Initiative - Blog - www.thezdi.com
firmware
autel
door
ghidra
memory
Previous
-46
-45
-44
-43
-42
-41
-40
-39
Next