<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vulnerability Research on lcz's Blog</title><link>https://book.llcczz.org/categories/vulnerability-research/</link><description>Recent content in Vulnerability Research on lcz's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 05 Apr 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://book.llcczz.org/categories/vulnerability-research/index.xml" rel="self" type="application/rss+xml"/><item><title>XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem</title><link>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</guid><description>A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.</description></item><item><title>MOVEit Transfer (CVE-2023-34362): From SQL Injection to Web Shell</title><link>https://book.llcczz.org/posts/moveit-cve-2023-34362/</link><pubDate>Mon, 05 Jun 2023 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/moveit-cve-2023-34362/</guid><description>How a pre-authentication SQL injection in a managed file transfer product became one of the largest data theft campaigns of 2023.</description></item><item><title>Spring4Shell (CVE-2022-22965): A Practical Exploitation Walkthrough</title><link>https://book.llcczz.org/posts/spring4shell-cve-2022-22965/</link><pubDate>Wed, 30 Mar 2022 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/spring4shell-cve-2022-22965/</guid><description>How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.</description></item><item><title>Log4Shell (CVE-2021-44228): Exploitation, Detection, and Mitigation</title><link>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</link><pubDate>Wed, 15 Dec 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</guid><description>A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.</description></item><item><title>ProxyLogon (CVE-2021-26855): Dissecting the Exchange SSRF Chain</title><link>https://book.llcczz.org/posts/proxylogon-cve-2021-26855/</link><pubDate>Wed, 10 Mar 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/proxylogon-cve-2021-26855/</guid><description>Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.</description></item></channel></rss>