House of Banana
Posted on 2024-10-21
Hijack execution flow by abusing _rtld_global in ld.so
Deserialization for pymatgen & Directory Traversal on aiohttp
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
High level GLIBC I/O operation exploit: Largebin Attack + FSOP
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
ORW ROP chain with magic gadgets to pwn a Sandbox