Sinisterly
Zebra.py (CVE-2013-7091) - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Zebra.py (CVE-2013-7091) (/Thread-Zebra-py-CVE-2013-7091)

Pages: 1 2 3


Re: RE: Zebra.py (CVE-2013-7091) - Satan - 05-10-2014

(05-10-2014, 11:33 AM)BreShiE Wrote: Fair warning to SL members, don't ever run random scripts without reading the source code first.

Reading the source code and understanding what it does*


RE: Zebra.py (CVE-2013-7091) - BreShiE - 05-10-2014

(05-10-2014, 11:36 AM)Six Wrote: Reading the source code and understanding what it does*

Yeah no shit... Otherwise it'd be like reading a book of scribbles?


Re: RE: Zebra.py (CVE-2013-7091) - Satan - 05-10-2014

(05-10-2014, 11:38 AM)BreShiE Wrote: Yeah no shit... Otherwise it'd be like reading a book of scribbles?

I never underestimate the stupidity of people online.


RE: Zebra.py (CVE-2013-7091) - Dyme - 05-10-2014

(05-10-2014, 08:20 AM)Six Wrote: I dont understand the animal reference to be quite honest, anyone care to explain?

Every PoC I make gets named after some animal, usually one that sounds like the vendor/product. Why? Fun.

(05-10-2014, 11:33 AM)BreShiE Wrote: Fair warning to SL members, don't ever run random scripts without reading the source code first.

Well Breshie, how does this one check out?

(05-10-2014, 09:17 AM)chF Wrote: Nice move, Matthew. I guess you're losing your job.. what a shame. It lasted a few months, too!

For what exactly? Disclosing a PoC for a public vulnerability that was patched over a year ago? I see you're as desperate and illogical as ever.

>matthew
>omg he said my name run


RE: Zebra.py (CVE-2013-7091) - BreShiE - 05-10-2014

(05-10-2014, 02:15 PM)Dyme Wrote: Well Breshie, how does this one check out?

To me it seems fine, but it doesn't mean others still shouldn't check it out for themselves. Wink


RE: Zebra.py (CVE-2013-7091) - Dyme - 05-10-2014

(05-10-2014, 02:23 PM)BreShiE Wrote: To me it seems fine, but it doesn't mean others still shouldn't check it out for themselves. Wink

That's ok, it's only your stamp of approval that I really wanted Wink


RE: Zebra.py (CVE-2013-7091) - Adorapuff - 05-10-2014

It seems the only possible place he could have backdoored this would be in the .jsp shell that gets uploaded. If you don't trust it, just use your own .jsp shell.
Also, what window theme is that?


RE: Zebra.py (CVE-2013-7091) - BreShiE - 05-10-2014

(05-10-2014, 04:52 PM)Adorapuff Wrote: It seems the only possible place he could have backdoored this would be in the .jsp shell that gets uploaded. If you don't trust it, just use your own .jsp shell.
Also, what window theme is that?

It's not a theme, it's hardcore ricing.


RE: Zebra.py (CVE-2013-7091) - Z0le - 05-11-2014

This one is very similiar to HoodedRobin's Zimbra exploiter (It's made in ruby).


RE: Zebra.py (CVE-2013-7091) - superMAUS - 05-12-2014

(05-11-2014, 02:41 PM)Z0le Wrote: This one is very similiar to HoodedRobin's Zimbra exploiter (It's made in ruby).

Ruby < Python < Perl