EBCDIC is coming back in 2022 :)
I have a feeling @[email protected] 's https://www.mdsec.co.uk/2021/09/nsa-meeting-proposal-for-proxyshell/ about @[email protected] & @[email protected] bugs might still be relevant for #ProxyNotShell - Can't we just bypass the @[email protected] rule `(?=.*autodiscover)(?=.*powershell)` by Request Encoding e.g. https://gist.github.com/irsdl/0f61ed38a4cc7a86b1b48180b6af15ba 🔮 https://twitter.com/wdormann/status/1578751627598888962
Confession: I *hated* this book.
The best time to learn C was 50 years ago. The second best time is now.
Condolences to the fellow who had to manage Azure API permissions for this ;)
Fancy Bear (APT28) abusing Microsoft Graph API for C2 operations and using OneDrive to download Encrypted payload then executed in-memory. I extracted the decrypted payload, details can be seen in below. @[email protected]
Oh, I used computers around that time!
Are you confused about the term "Universal XSS"?
We are looking at the history of these issues from BEFORE they got their modern name! Maybe it helps to understand what it actually is about ;)
Let's go back to ~1998!
https://www.youtube.com/watch?v=gVblb-QhZa4