CVE-2018-13442: SolarWinds NPM SQL Injection 2 Aug 2018 A SQL injection vulnerability has been discovered in SolarWinds’ Network Performance Monitor (NPM). This vulnerability has been designated... Read more
CVE-2017-16245 & CVE-2017-16246: Avecto Defendpoint Multiple Vulnerabilities 30 Jul 2018 This post focuses on the “application control” aspect of Avecto. Last year I discovered two vulnerabilities in the... Read more
Python Server for PoshC2 26 Jul 2018 We are delighted to announce the release of our PoshC2 Python Server, allowing cross-platform support. Read more
COM and the PowerThIEf 10 Jul 2018 Recently, Component Object Model (COM) has come back in a big way, particularly with regards to it being... Read more
CVE-2018-6851 to CVE-2018-6857: Sophos Privilege Escalation Vulnerabilities 25 Jun 2018 We have recently disclosed a list of vulnerabilities to Sophos that allow local attackers to elevate their privileges... Read more
CVE-2018-10956: Unauthenticated Privileged Directory Traversal in IPConfigure Orchid Core... 14 Jun 2018 IPConfigure Orchid Core VMS is a Video Management System that is vulnerable to a directory traversal attack, which... Read more
Introducing Prowl 5 Jun 2018 Prowl was initially designed as an in house tool to aid engagements where there’s a requirement to capture... Read more
Apache mod_python for red teams 31 May 2018 Nettitude’s red team engagements are typically designed to be as highly targeted and as stealthy as possible. For... Read more
WinDbg: using pykd to dump private symbols 11 Apr 2018 We’ve recently been conducting some reverse engineering and vulnerability analysis on an Anti Virus (AV) product and wanted... Read more
CVE-2017-7351: REDCap 7.0.0 - 7.0.10 SQL Injection 8 Feb 2018 A SQL injection vulnerability exists in REDCap versions 7.0.0 – 7.0.10. This has been designated CVE-2017-7351. Read more
Best seller New Price from Limited availability Course type Course length Dates and location x *PLEASE NOTE: Course is available in more countries, languages and dates*