[FD] EBAY Bugbounty: Persistent DOM Based XSS on ebay.com

2016-02-18 Thread Alexander Korznikov
Hello all, Description: Persistent DOM based Cross Site Scripting on ebay.com domain. Disclosed to Ebay: January 2015 Fixed: February 2016 Vulnerability location: Every listing Who are able to create: Sellers Same origin policy bypass via postMessage Write-up: http://www.korznikov.com/2016/02/pe

[FD] RCE by abusing NAC to gain Domain Persistence.

2016-07-12 Thread Alexander Korznikov
Network Access Control systems. Alexander Korznikov & Viktor Minin ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] TS Session Hijacking / Privilege escalation all windows versions

2017-03-18 Thread Alexander Korznikov
Terminal Services / Console Session Hijacking can lead to Privilege Escalation. Vulnerability Details. A privileged user, which can gain command execution with NT AUTHORITY/SYSTEM rights can hijack any currently logged in user's session, without any knowledge about his credentials. Terminal Servi