Horizon3 Attack Team@Horizon3AttackOur technical deep-dive of the recent #ManageEngine Pre-Auth RCE CVE-2022-47966. POC exploit included for xmlsec <= 1.4.1. Other versions also exploitable.ツイートを翻訳horizon3.aiManageEngine CVE-2022-47966 Technical Deep DiveIntroduction On January 10, 2023, ManageEngine released a security advisory for CVE-2022-47966 (discovered by Khoadha of Viettel Cyber Security) affecting a wide range of products. The vulnerability...午後1:19 · 2023年1月19日·2,240 件の表示13 件のリツイート5 件の引用ツイート43 件のいいね
Horizon3 Attack Team@Horizon3Attack·1時間返信先: @Horizon3AttackさんCheck out the original research by @_l0gg also released todayblog.viettelcybersecurity.comCVE-2022-47966 SAML ShowStopper1. IntroductionSAML(Security Assertion Markup Language) & OIDC (OpenID Connect) is the two main SSO (Single-Sign-On) standards. While OIDC is more popular, SAML is mostly used by enterprise organiz...12245
Horizon3 Attack Team@Horizon3Attack·1時間Also check out @GreyNoiseIO, who we shared the POC with and has a tag available for monitoring it's exploitation.viz.greynoise.ioGreyNoise Trends1189