Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ✅ Expertenwissen über das Thema "High+CVE"

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Keybase: SOP bypass using browser cache


💡 Newskategorie: Sicherheitslücken
🔗 Quelle: vulners.com


image
Summary An attacker has the ability to extract sensitive information from user's accounts, due to a CORS issue. On a minor note, this also is a cross-site leak as we can fingerprint what exact keybase user has accessed the attacker's website. Information disclosed: "passphrase_generation":4,"random_pw":false}, "invitation_stats":{"available":60,"used":40,"power":100,"open":0}, "profile":"emails":{"emails":[{"email":"x86sec@yahoo.ie","is_primary":1,"is_verified":1,"when_verified":"2016-03-08T22:44:39.000Z","visibility":1,"last_verify_email_date":null}],"primary":{"email":"x86sec@yahoo.ie","is_primary":1,"is_verified":1,"when_verified":"2016-03-08T22:44:39.000Z","visibility":1,"last_verify_email_date":null}},"billing_and_quotas":{"plan":{"plan_id":"b40ff8cf58afb4fa7e8dd4dc2c5f651a","plan_name":"BASIC","price_pennies":0,"gigabytes":250,"num_groups":0,"folders_with_writes":500,"billing_status":0,"test_mode":null},"usage","lks_server_half":"a42d3be100454cc98df58d90acd402af57e40119d6a02580edc47128454a47dc","passphrase_generation":4,"last_used_time":1566400369},"private_keys":{"all":{}} I tested this on my own account, and while there is some serious information disclosure here, I am most concerned by "private_keys" field. I do not believe I have a private key stored on keybase.io however if it turns out that a private key is disclosed here for people that do, I believe this is near critical impact. Issue Overview Users can interact with the following endpoint:... ...



📌 Keybase: SOP bypass using browser cache


📈 72.35 Punkte

📌 Keybase: Keybase /AppData/Local/Keybase/uploadtemps folder stores pasted photos


📈 63.22 Punkte

📌 [local] Keybase keybase-redirector - '$PATH' Local Privilege Escalation


📈 42.15 Punkte

📌 #0daytoday #Keybase keybase-redirector - '$PATH' Local Privilege Escalati [#0day #Exploit]


📈 42.15 Punkte

📌 #0daytoday #Keybase keybase-redirector - '$PATH' Local Privilege Escalati [#0day #Exploit]


📈 42.15 Punkte

📌 [remote] Samsung Internet Browser - SOP Bypass (Metasploit)


📈 35.85 Punkte

📌 Samsung Internet Browser SOP Bypass


📈 35.85 Punkte

📌 Samsung Internet Browser SOP Bypass


📈 35.85 Punkte

📌 #0daytoday #Samsung Internet Browser - SOP Bypass Exploit CVE-2017-17692 [remote #exploits #0day #Exploit]


📈 35.85 Punkte

📌 Samsung Internet Browser SOP Bypass (Metasploit)


📈 35.85 Punkte

📌 Samsung Internet Browser 6.2.01.12 SOP Bypass / UXSS


📈 35.85 Punkte

📌 Samsung Internet Browser 6.2.01.12 SOP Bypass / UXSS


📈 35.85 Punkte

📌 #0daytoday #Samsung Internet Browser 6.2.01.12 SOP Bypass / UXSS Vulnerabilities [#0day #Exploit]


📈 35.85 Punkte

📌 Keybase Desktop Client Cache information disclosure [CVE-2021-23827]


📈 31.39 Punkte

📌 WP Super Cache Plugin up to 1.7.1 on WordPress Cache Settings wp-cache-config.php cache_path code injection


📈 30.96 Punkte

📌 Dell SonicWALL Global Management System GMS 8.1 Adobe Flex SOP Bypass


📈 30.47 Punkte

📌 Dell SonicWALL Global Management System GMS 8.1 Adobe Flex SOP Bypass


📈 30.47 Punkte

📌 SOP Bypass in Microsoft Edge Leads to Credential Theft


📈 30.47 Punkte

📌 BTFS: misconfigured CORS let to HPP and SOP bypass


📈 30.47 Punkte

📌 Keybase Browser Extension Does Not Encrypt Messages


📈 26.46 Punkte

📌 Keybase Browser Extension Could Allow Sites to See Messages


📈 26.46 Punkte

📌 Keybase browser extension weakness discovered


📈 26.46 Punkte

📌 How to Cache Expensive Database Queries Using the Momento Serverless Cache


📈 25.75 Punkte

📌 Facebook's Clear History Privacy Option: Boon or Sop?


📈 24.22 Punkte

📌 SOP in this department...


📈 24.22 Punkte

📌 http://sop.bppkad.grobogan.go.id/stress.php


📈 24.22 Punkte

📌 http://sop.bppkad.grobogan.go.id/kz.html


📈 24.22 Punkte

📌 Separation of Privilege (SoP) 101: Definition and Best Practices


📈 24.22 Punkte

📌 Indian government issues SOP to employees on Cyber Attacks


📈 24.22 Punkte

📌 Denial of Service in rust-sequoia-sop (Fedora)


📈 24.22 Punkte

📌 Keybase Chat: Verschlüsselt chatten mit dem Github-Account


📈 21.07 Punkte

📌 Keybase Chat: Verschlüsselt chatten mit dem Github-Account


📈 21.07 Punkte

📌 Keybase Chat & A Hak5 Host Takeover! - Hak5 2203


📈 21.07 Punkte











matomo