πŸ” Search
Sign in to post
☒️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operatorhttps://www.reddit.com/r/netsec/comments/1vyxx41/philippine_nuclear_agency_and_naval_contractor

The Hunt.io research team found an open directory staging the full toolkit behind an intrusion into a Philippine nuclear research agency and a naval contractor. The ownCloud path is the interesting part technically. CVE-2023-49105 lets you forge pre-signed WebDAV URLs when the signing secret is empty, which is the default state on a fresh install. Five custom Python scripts on the server implement this: the signing routine passes an empty bytes literal as the PBKDF2 salt, sets OC-Credential to the account being impersonated, and issues GET requests against /remote.php/dav/files/ /<pat…

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...