1. Reverse Engineering >
  2. Exploits >
  3. Socket.io up to 0.9.6 on Node.js Math.random() privilege escalation


Socket.io up to 0.9.6 on Node.js Math.random() privilege escalation

Exploits vom | Direktlink: vuldb.com Nachrichten Bewertung

A vulnerability, which was classified as critical, was found in Socket.io up to 0.9.6 on Node.js (JavaScript Library). Affected is the function Math.random(). There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product....

Externe Webseite mit kompletten Inhalt öffnen


Team Security Social Media

➤ Weitere Beiträge von Team Security | IT Sicherheit

  • Venom - A Multi-hop Proxy For Penetration Testers

    vom 367.56 Punkte ic_school_black_18dp
    Venom is a multi-hop proxy tool developed for penetration testers using Go. You can use venom to easily proxy network traffic to a multi-layer intranet, and easily manage intranet nodes.Features network topology multi-hop socks5 proxy multi-hop port forward port r
  • Shellver - Reverse Shell Cheat Sheet Tool

    vom 273.49 Punkte ic_school_black_18dp
    Reverse Shell Cheat Sheet ToolInstall NoteClone the repository:git clone https://github.com/0xR0/shellver.gitThen go inside:cd shellver/Then install it:python setup.py -irun shellver -h or "shellver bash or perl {} python {} php {} ruby {} netcat {} xterm {} shell {
  • MyEtherWallet: Local Storage Custom Node Credentials Leak

    vom 270.84 Punkte ic_school_black_18dp
    Summary Credentials for a custom node are stored in plain text inside Local Storage on the user's machine. If this node is configured in a certain way this could lead to the theft of any funds in accounts attached to this node, by a local attacker. A
  • Pwn2Own Returns to Vancouver for 2020

    vom 269.77 Punkte ic_school_black_18dp
    Jump to the contest rules As each new year starts, we at the Zero Day Initiative begin to think of spring and the Vancouver edition of the Pwn2Own contest. It was in Vancouver where the contest began back in 2007 and continues to be where we push the
  • Socket.io bis 0.9.6 auf Node.js Math.random() erweiterte Rechte

    vom 263.67 Punkte ic_school_black_18dp
    Es wurde eine Schwachstelle in Socket.io bis 0.9.6 auf Node.js gefunden. Sie wurde als kritisch eingestuft. Es betrifft die Funktion Math.random(). Durch Beeinflussen mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werd
  • How to Upgrade to TypeScript without anybody noticing, Part 2

    vom 232.14 Punkte ic_school_black_18dp
    This guide will show you how to fix Typescript compile errors in Javascript project that recently added Typescript support via a tsconfig.json. It assumes that the tsconfig.json is configured according to the description in part 1 of this post, and that you also installed types for some of your dependencies from the @types/* namespace. This guide
  • HPR2848: Random numbers in Haskell

    vom 200.33 Punkte ic_school_black_18dp
    There’s lots of random and similar sounding words in this episode. I hope you can still follow what I’m trying to explain, but I’m aware that it might be hard. Haskell functions are pure, meaning that they will always produce same values for same
  • Local Privilege Escalation in Win32k.sys Through Indexed Color Palettes

    vom 179.92 Punkte ic_school_black_18dp
    This is the second in our series of Top 5 interesting cases from 2019. Each of these bugs has some element that sets them apart from the more than 1,000 advisories released by the program this year. Today’s blog looks a local privilege escalation in t
  • The February 2020 Security Update Review

    vom 156.32 Punkte ic_school_black_18dp
    February is here, and with it comes some significant security patches from Adobe and Microsoft. Take a break from your regularly scheduled activities and join us as we review the details for security patches for this month. Adobe Patches for February 2020The Adobe
  • HPR2918: Selecting random item from weighted list

    vom 148.4 Punkte ic_school_black_18dp
    Intro We’re going to have a look how to select random item from weighted list. There isn’t that much code this time, but it certainly took many tries to get it working and looking nice. Analogy Imagine stack of building blocks of different heights
  • Scanner-Cli - A Project Security/Vulnerability/Risk Scanning Tool

    vom 148.31 Punkte ic_school_black_18dp
    The Hawkeye scanner-cli is a project security, vulnerability and general risk highlighting tool. It is meant to be integrated into your pre-commit hooks and your pipelines.Running and configuring the scannerThe Hawkeye scanner-cli assumes that your dir

    vom 135.42 Punkte ic_school_black_18dp
    Highest Rated Created by Stephen Grider Last updated 4/2018 English What Will I Learn? Absolutely master the Event Loop and understand each of its stages Utilize Worker Threads and Clustering to dramatically improve the performance of Node servers Sp

Team Security Diskussion über Socket.io up to 0.9.6 on Node.js Math.random() privilege escalation