EndlessMason
mastodon 4.7.3A whimsical, neurospicy #perl developer looking to be #fedihired.
@Kuchenschwarte@fnordon.de @LoganFive@beige.party I have, at times, fallen back on my call centre training during an in-person exchange:
Hey, have you noticed all the foreigners in here tonight, kinda stinks in here
[my dominant hand on their opposite shoulder] I'm hanging up now... umm, in person [walk away from person]
(in keeping with the thread, if you take this as advice — and that seems ill advised — at best it's unsolicited, and at worst it's not great. Heck, we weren't even supposed to hang up on people at the call centre.)
Eggs do not lay eggs
I need to know how they managed to get a goose without knowing where geese come from
@thecybersecguru@infosec.exchange Maybe I wasn't clear, or I'm misreading the situation...
The diagram says:
- rest endpoint
- route confusion
- sqli
- rce
but the way you get from 3 to 4 is by cracking the admin password
The vuln itself isn't an RCE - it's information disclosure⸸...
The code execution comes from "logging in as admin and installing an evil plugin", right?
__ ⸸. ... of the hashed admin password, but still