Log4Shell: when a log line becomes code execution
Log4j evaluated JNDI expressions inside logged messages. A simple header with ${jndi:ldap://...} led to RCE.
|
main menu
user menu
topics
|
latest postsLog4Shell: when a log line becomes code executionLog4j evaluated JNDI expressions inside logged messages. A simple header with ${jndi:ldap://...} led to RCE. Password spraying and credential stuffingNot a thousand passwords on one account (lockout), but one password on a thousand accounts (spraying), or stolen pairs reused everywhere (stuffing). Phishing: harvesting credentials at scaleThe most common entry vector attacks not software but people. Reverse proxies like evilginx steal the MFA session too. OSINT: reconnaissance before the attackSubdomains, emails, leaked credentials, metadata: much of an attack is prepared without touching the target. Hash cracking: dictionaries, rules, masksRecovering passwords from stolen hashes with GPUs. Strategy — wordlists with rules, targeted masks — matters more than raw brute force. BLE attacks: sniffing, spoofing and replayBluetooth Low Energy is everywhere: locks, wearables, sensors. Weak pairing and unauthenticated commands open the door to sniffing and replay. RFID/NFC cloning: badges copied in secondsLow-frequency badges often transmit only a static ID, copyable with cheap hardware. Smart cards do better, if configured. Firmware extraction: UART, JTAG and the flashBefore analyzing a device you must read its firmware. Debug pins and the memory chips on the board are often the most direct way. Dependency confusion: impersonating the internal packageIf a package manager prefers the public registry over the private one, publishing a same-named package with a higher version hijacks the build.
« newer
older »
|
latest posts
your IP address:
216.73.216.108
visitor #0
MOTD:
Every abstraction leaks somewhere. Here we look at where. |