blog.atucom.net
Atucom: May 2016
http://blog.atucom.net/2016_05_01_archive.html
A blog about coding, Infosec, penetration testing, and random topics. Tuesday, May 17, 2016. Exploiting HipChat with ImageTragick. Hipchat uses the Imagemagick library to resize your custom emoticons. If you have access to upload your own emoticon image files to the server using the web interface (or API probably), you can use the Imagetragick vulnerability. To get shell on the machine. It turns out the ImageTragick's PoC didn't work on our server:. The reverse shell I used. Python -c 'import socket,subp...
docs.bigbluebutton.org
BigBlueButton : Install
http://docs.bigbluebutton.org/install/install.html
Open Source Web Conferencing. Deskshare TLS over Stunnel. Welcome to the installation guide for BigBlueButton 1.0. BigBlueButton is an open source web conferencing system for on-line learning. For an overview what new in this release, see overview. If you already have a BigBlueButton 0.81 server running Ubuntu 10.04, we recommend not. Trying to upgrade your server. Start with a clean Ubuntu 14.04 64-bit server, install BigBlueButton using the steps below, and then copy over the recordings. Port 80 is not.
imageflow.io
imageflow = libimageflow + imageflow-server
http://www.imageflow.io/index.html
Imageflow Platinum Plus Integration Contract. Imageflow is open-source software which scales, edits, and optimizes images. Unlike most tools, it does. Have a visual interface; it is designed to be embedded into software like Wordpress, Ebay, Craigslist, or Facebook. Libimageflow can be used directly over FFI. By any mainstream language. The second component, imageflow-server, speaks HTTP and any networked device can use it. A human can use it from their web browser by adding. Yet puts security first.
willgenovese.com
May 2016 – Will Genovese
http://willgenovese.com/2016/05
Hacker, Cracker, Breaker, Maker. Monthly Archives: May 2016. How not to roll out a website. May 31, 2016. February 10, 2017. I’m posting this now because the hosting company has seem to finally fix the issues, I tried emailing and tweeting to them but got no response from any of the parties. SSH Tunneling RDP Using Putty. May 7, 2016. May 7, 2016. Through a secure ssh session and get to the internal Win7 without port forwarding on the router. I had access to SSH account on the Debian web-server, so I was...
anetcomputers.com
Aaron B | Anet Computers
http://www.anetcomputers.com/author/anetcomp
VIRUS AND SPYWARE REMOVAL. All posts by Aaron B. Hello, my name is Aaron B and I’m owner of this website. For over thirteen years, I worked for fortune 500 companies and the United States Federal government supporting computers. I always wanted to become self employed for most of those years and finally made a jump in 2007. WordPress – Release Maintenance & Security Update 4.5.3 For 17 Bugs. June 29, 2016. If your WordPress site was configured with automatic background updates, then you should already be...
hyper-text.org
Web Development カテゴリーの記事一覧(1 / 11 ページ) | WWW WATCH
https://hyper-text.org/archives/web_development
1 / 11 ページ. Movable Type 6.3 がリリース、PHP 7 と MySQL 5.7 に対応、画像品質自動調整機能の有無が設定可能に. シックス アパート社より、Movable Type の最新版となる、Movable Type 6.3 のリリースが発表されました。 すでに Movable Type 6 のライセンスを持っているユーザーは、無償で Movable Type 6.3 にアップグレードすることができます。 PHP 7 と MySQL 5.7 に対応した最新版 Movable Type 6.3 の提供を開始 Movable Type ニュース. Movable Type 6.3 リリースノート Movable Type 6 ドキュメント. HTML 5.2 の First Public Working Draft FPWD が公開される. HTML 5.1 が今年 9月の勧告に向けて勧告候補への移行検討段階へ、HTML 5.2 の策定も開始. 将来 Firefox から 404 Not Found が消える Test Pilot に No More 404s が追加.
hyper-text.org
Security カテゴリーの記事一覧(1 / 2 ページ) | WWW WATCH
https://hyper-text.org/archives/security
1 / 2 ページ. アフィリエイト サービス プロバイダ各社はいい加減配信する広告を SSL に対応させろと思っていたらバリューコマースさんが対応した件. いや、もうタイトルで言い切ってるんですけども、大手のアフィリエイト サービス プロバイダ各社は、HTTPS による広告配信に未だ対応していないところが多く、当 Blog のように Web サイトを SSL 対応させた際にそのままでは混在コンテンツ Mixed Content が発生してしまいとてもやっかいでした。 2016年にもなっていつまで対応しないんだよ、いい加減対応して欲しろ. もとい、そろそろ対応して欲しいなぁと思っていたらバリューコマースさんがやっと SSL に対応したそうです。 ついでに他のアフィリエイト サービス プロバイダさんも調べてみたら A8.net さんもいつの間にか SSL 対応していましたという話。 ケータイキット for Movable Type に OS コマンドインジェクションの脆弱性. プレスリリース - 重要 ケータイキット for Movable Typeの脆弱性について アイデアマンズ株式会社. Apache...
imageflow.io
Kickstarter Rewards
http://www.imageflow.io/kickstarter
Imageflow Platinum Plus Integration Contract. June 1st, 2016. Imageflow is open-source software which scales, edits, and optimizes images. It’s similar to our existing software, ImageResizer. But is faster, produces better results, and is not bound to the Windows API. Imageflow supports Linux, Mac, and Windows and can be used from any programming language. Imageflow is the first solution to offer uncompromising security and visual quality - but it also trounces competitors in benchmarks. With imageflow-s...
hethical.io
Trello bug bounty: Access server's files using ImageTragick
https://www.hethical.io/trello-bug-bounty-access-servers-files-using-imagetragick
Trello bug bounty: Access server's files using ImageTragick. As you may know, an ImageMagick vulnerability has recently been disclosed following the research of Stewie. You can read more on the dedicated website. The vulnerability appears when ImageMagick is used to convert an image from one format to another. To load the resource. The external resource url is not sanitised correctly, it means that following the. Command, any Shell command with the url will be executed. ImageMagick will take the. Image x...
SOCIAL ENGAGEMENT