Hi everyone, I recently spent some time looking at browser parsing differences around malformed HTML, MathML and sanitizers. I was not specifically hunting for a DOMPurify issue when I started. I had a few small parser test cases, I was […]
Trusting the Wrong Pointer: From Kernel Memory Disclosure to SYSTEM in WinCDEmu’s Virtual CD Driver
Hello everyone, In this post, I want to walk through a Windows kernel driver research session that started as a simple curiosity and slowly turned into something much more interesting. The target was WinCDEmu’s kernel driver, BazisVirtualCDBus.sys. WinCDEmu is a […]
Hunting Bugs in ElbyCDIO.sys: From a Simple IOCTL Review to Kernel Pointer Leak, Local DoS and Access Control Bypass
Hello everyone, I recently spent some time looking at ElbyCDIO.sys, the kernel driver installed by Virtual CloneDrive / Elaborate Bytes. My goal was not to throw random IOCTLs at the driver and hope for a crash. I wanted to treat […]
Bypassing SolidCore by Running EXEs Directly from Memory
Hello everyone, Today I’ll walk you through how I bypassed SolidCore, a product I frequently encounter and that often gives me trouble during Red Team/pentest engagements. SolidCore is a product from Trellix that enforces application control and change control by […]
EDR Anatomisi: Savunma Hattının Bilinmeyenleri
Herkese selamlar, bugün sizlere EDR güvenlik ürünlerinin bunca saldırıları tam olarak nasıl kestiğini yani bunları nasıl fark edip saldırı olarak işaretleyebiliyor dilim döndükçe anlatmaya çalışacağım. Red Team çalışmalarında karşılaştığımız en büyük engel genellikle EDR (Endpoint Detection and Response) güvenlik çözümleridir. […]
Esrarengiz Kuzey Kore – 2
Herkese merhaba,Bugün bilinmezler ülkesi olan Kuzey Kore hakkında dilim döndükçe bir şeyler yazacağım. Burada yazılanlar araştırmalar, tecrübeler ve Güney Kore’de yaşayan bazı arkadaşlarımın bilgi birikimlerinin aktarılması ile oluşturulmuştur. Başlamadan önce Kuzey Kore’nin tamamen kapalı kutu olduğunu düşünürsek bunların doğrulanması ne […]
All-in-One WP Migration Plugin Broken Access Vulnerability
Hello everyone, A friend of mine was looking for a plugin to migrate their WordPress site to another location. After a quick Google search, I found the “All-in-One WP Migration” plugin. When I checked its active installations, I was surprised […]
Disabling EDR via PendingFileRenameOperations
Hi everyone, Today, I will try my best to explain how we can disable EDR products that do not have anti-tampering protection. Before diving into the topic, it would be beneficial to briefly touch on some key concepts. Anti-Tampering Protection:Modern […]
X2CRM v8.5 – Stored Cross-Site Scripting (XSS) (Authenticated)
#Exploit Title: X2CRM v8.5 – Stored Cross-Site Scripting (XSS) (Authenticated) #Date: 12 September 2024 #Exploit Author: Okan Kurtulus #Vendor Homepage: https://x2engine.com #Version: v8.5 #Tested on: Ubuntu 22.04 #CVE: 2024-48120 Proof of Concept: Log in to the system with any user […]
Vtiger CRM v8.2.0 – HTML Injection (Authenticated)
#Exploit Title: Vtiger CRM v8.2.0 – HTML Injection (Authenticated) #Date: 12 September 2024 #Exploit Author: Okan Kurtulus #Vendor Homepage: https://www.vtiger.com #Version: v8.2.0 #Tested on: Ubuntu 22.04 #CVE: 2024-48119 Proof of Concept: After logging in as a registered user, it was […]









