Skip to content
Mehmet Ince @mdisec – Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
  • Posts
  • CVE INDEX
  • About Me
  • X
  • LinkedIn
  • YouTube
  • GitHub

0day advisory authentication clickhouse cve cyber django exploit hacking hll hyperloglog logpoint metasploit middleware neondb postgis postgres postgresql product security supabase vulnerability

  • Unexpected Journey #4 – Escaping from Restricted Shell and Gaining Root Access to SolarWinds Log & Event Manager (SIEM) Product
    Mar 17, 2017

    Unexpected Journey #4 – Escaping from Restricted Shell and Gaining Root Access to SolarWinds Log & Event Manager (SIEM) Product

    By time goes, I’ve found myself more focusing on SIEM product during penetration test. This is the fourth article of my article series called as “Unexpected Journey” which all of them focused on different SIEM products. In this article, I will share the details how I’ve got root access to the SolarWinds Log & Event Management product.

    (more…)
  • Unexpected Journey #3 – Visiting Another SIEM and Uncovering Pre-auth Privileged Remote Code Execution
    Mar 7, 2017

    Unexpected Journey #3 – Visiting Another SIEM and Uncovering Pre-auth Privileged Remote Code Execution

    This is the third part of our article series that intended to share my real-life penetration testing experience.In this article, I will share a whole process of how we managed to find a -0day- pre-auth RCE vulnerability on another SIEM product.

    (more…)
  • Unexpected Journey #2 – Taking Down Entire Domain Using Vulnerabilities of a SIEM Product
    Feb 16, 2017

    Unexpected Journey #2 – Taking Down Entire Domain Using Vulnerabilities of a SIEM Product

    As I said on my previous article, being a penetration tester makes us feel like a group of traveler. Today, I would like to share a details about yet another 0day vulnerability we’ve found during penetration test which later lead us to take down entire domain network.

    (more…)
  • Advisory | CVE-2017-6398 Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
    Feb 7, 2017

    Advisory | CVE-2017-6398 Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution

    In this article, we  will show details and metasploit module for vulnerability that affects Trend Micro’s IMSVA solution.

    (more…)
  • Unexpected Journey into the AlienVault OSSIM/USM During Engagement
    Jan 7, 2017

    Unexpected Journey into the AlienVault OSSIM/USM During Engagement

    Being a penetration tester makes us feel like a group of traveler. Discovering the internal world of the institution during engagement gives us the opportunity to make unexpected journeys. In this article, I will share a details of how we got an access to the heart of the company.

    (more…)
←
1 2 3
  • Posts
  • CVE INDEX
  • About Me