XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem

A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.

2024-04-05 · 4 min · 665 words · lcz

MOVEit Transfer (CVE-2023-34362): From SQL Injection to Web Shell

How a pre-authentication SQL injection in a managed file transfer product became one of the largest data theft campaigns of 2023.

2023-06-05 · 3 min · 605 words · lcz

Spring4Shell (CVE-2022-22965): A Practical Exploitation Walkthrough

How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.

2022-03-30 · 3 min · 492 words · lcz

Log4Shell (CVE-2021-44228): Exploitation, Detection, and Mitigation

A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.

2021-12-15 · 3 min · 505 words · lcz

ProxyLogon (CVE-2021-26855): Dissecting the Exchange SSRF Chain

Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.

2021-03-10 · 3 min · 524 words · lcz