#responsibledisclosure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #responsibledisclosure, aggregated by home.social.
-
Fileless RCE on stock Android (~2.5B devices). Reported to Google VRP, confirmed by their own engineering team, closed as NSBC anyway.
#AndroidSecurity #infosec #Android #MobileSecurity #VulnerabilityResearch #RCE #BugBounty #VRP #ResponsibleDisclosure #AppSec #ThreatIntel #WebView #ZeroDay #CVE
-
You demonstrate a fileless RCE chain. Complex delivery, in-memory execution, zero detections, confirmed working on multiple devices.
The vendor reviews it twice, involves engineering, then tells you:
"Your research demonstrates a complex chain for delivering and executing code."
...and closes it as 'intended behavior. Not a platform vulnerability.'
Question: is it a vulnerability?
Follow-up: does your answer change if the attack surface exists *between* components — where no single owner's scope definition covers the full chain?
Asking because I have a paper dropping soon about that.
#VRP #responsibleDisclosure #semanticGap #infosec #securityResearch
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362