[FD] Invitation to the World Cryptologic Competition 2023

2023-03-21 Thread Competition Administrator
The WCC 2023 is a fully-online and open competition using GitHub. The language of the competition is English. The WCC 2023 has a total duration of 295 days, from Sunday January 1st 2023 to Monday October 23rd 2023. Teams and Judges must complete registration before Wednesday June 1st. The WCC 202

[FD] Insecure python cgi documentation and tutorials are vulnerable to XSS.

2023-03-21 Thread Georgi Guninski
Is there low hanging fruit for the following observation? The documentation of the python cgi module is vulnerable to XSS (cross site scripting) https://docs.python.org/3/library/cgi.html ``` form = cgi.FieldStorage() print("name:", form["name"].value) print("addr:", form["addr"].value) ``` Fir

Re: [FD] Microsoft PlayReady security research

2023-03-21 Thread Adam Gowdiak
Hello, > I tried to reach out to CANAL+ instead, but without much success. CANAL+ > company > was clearly not interested to talk to me over this (no responses to e-mails > and/or > requests to establish an official communication channel for the reporting, > discussion and vulnerabilities disclos

Re: [FD] Defense in depth -- the Microsoft way (part 83): instead to fix even their most stupid mistaskes, they spill barrels of snakeoil to cover them (or just leave them as-is)

2023-03-21 Thread Arik Seils
Hi there, One can use the Metasploit Framework Module post/windows/local/bypassua _fodhelper to achieve this. Greetings from Germany, A.Seils 17.03.2023 06:26:56 Stefan Kanthak : > Hi @ll, > > with Windows 2000, Microsoft virtualised the [HKEY_CLASSES_ROOT] registry > branch: what was just a

Re: [FD] Microsoft PlayReady security research

2023-03-21 Thread Security Explorations
Hello, > I tried to reach out to CANAL+ instead, but without much success. CANAL+ > company > was clearly not interested to talk to me over this (no responses to e-mails > and/or > requests to establish an official communication channel for the reporting, > discussion and vulnerabilities disclos