home.social

#responsibledisclosure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #responsibledisclosure, aggregated by home.social.

  1. three critical (9.1) advisories for wazuh i reported were published today. same trust assumption broken in three places: the cluster fernet key authenticates membership, and the cluster protocol then lets that peer pick filesystem paths.

    CVE-2026-49441: the peer-supplied metadata key in process_files_from_worker is used directly as the destination path. write etc/ossec.conf, root rce via wazuh-logcollector.

    CVE-2026-48024: same function, merged-file branch. traversal in the merged header name and in merge_type.

    CVE-2026-48162: the DAPI tmp_file field is joined to WAZUH_PATH with os.path.join and shipped back to the peer. absolute paths win, so it reads anything the wazuh user can open. grab private_key.pem, forge ES512 admin jwts offline. survives cluster key rotation, since the jwt keypair is a different scope.

    patched in 4.14.6.

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    github.com/wazuh/wazuh/securit

    #Wazuh #InfoSec #CVE #SIEM #ResponsibleDisclosure #CyberSecurity

  2. 🎢 Hacked South Park's Casa Bonita. Could access their entire POS system and see all customer payments/tips and more 😬

    Technical details:

    • Founders Club admin panel: No auth required, all member emails exposed
    • POS registration: Form disabled client-side only, API endpoint still functional
    • Reservation enumeration: Sequential IDs exposed full customer data
    • Full control over customer tabs, payments, and inventory
    • Supabase misconfiguration: Public signups triggered automated membership cards

    No security.txt anywhere. Had to email parkcounty.com addresses then get help from my friend whose company partners with South Park.

    Fixed fast but never thanked me. Got a Founders Club card 6 months later though, because the system automatically sends them 😂

    Full Technical Writeup: bobdahacker.com/blog/i-hacked-

    #infosec #bugbounty #responsibleDisclosure #security #vulnerability #hacking #cybersecurity #southpark #CasaBonita