How to detect and exploit CVE-2021-26084, the Confluence Server RCEThinking like an attacker is the right mindset that can help you better cope with this staggering growth of RCE vulnerabilities. As a pentester, you know it better than anyone. You’re also the best positioned to use your experience and know-how to detect exposed critical assets before malicious actors do. To help you help others, I’ll explore a critical RCE vulnerability in the Atlassian Confluence server across Linux and Windows in this practical guide packed with detection tactics and mitigation methods.Author(s)Iulian TitaPublished at31 Jan 2022Updated at24 Mar 2023
How to exploit the VMware vCenter RCE with Pentest-Tools.com (CVE-2021-21985)More high-risk vulnerabilities mean more work for you. The good news? You won’t be out of work anytime soon. The bad news? You’ll probably work a lot more than you anticipate. So how do you balance the good and the not-so-great? By having a replicable process for when a high-risk CVE that leads to RCE hits your targets (the likes of CVE-2021-21985).Author(s)Stefan IridonPublished at25 Jan 2022Updated at13 Apr 2023
December updates: 6 new ways to make your workflow smootherHope 2022 is off to a great start for you! Supporting your security efforts is what we do, so here’s a fresh batch of platform updates we rolled out at the end of 2021. Why check them out? Because they’ll help you get more work done, faster with the same tools and features you know (and hopefully love!).Author(s)Ioana RijnetuPublished at20 Jan 2022Updated at21 Jul 2022
Year in review: 2021 on Pentest-Tools.comSecurity is the gift that keeps on giving and never have we felt it like we did this year.Author(s)Andra ZahariaPublished at28 Dec 2021Updated at17 Jul 2023
How we detect and exploit Log4Shell to help you find targets using vulnerable Log4j versionsWe’re breaking down our technique for detecting CVE-2021-44228 (Log4Shell) because we believe our users should understand what’s happening behind the scanners so they can avoid a false sense of security.Author(s)Adrian FurtunaPublished at17 Dec 2021Updated at11 May 2023
November updates for powerful workflows, including detection for Log4ShellGiving you the tools you need right now to speed up detection and reporting is always our top priority. Especially when your work is essential to effectively prioritize remediation. So, with every monthly update, we strive to do just that.Author(s)Ioana RijnetuPublished at16 Dec 2021Updated at05 Oct 2022
Log4Shell scanner: detect and exploit Log4j CVE-2021-44228 in your network and web appsWe almost made it to a much-needed holiday break… and then Log4Shell happened.Author(s)Daniel BecheneaPublished at14 Dec 2021Updated at13 Apr 2023
How to detect the Zoho ManageEngine ADSelfService Plus RCE (CVE-2021-40539)Overwhelmed by so many high-risk vulnerabilities that emerge? Thousands of them are disclosed every year and 2021 is no exception. Systems are complex, cyber attacks get more sophisticated, and patching is still a challenge for many organizations. As infosec pros, it’s our responsibility to help companies (and individuals) understand the real implications and impact of a critical vulnerability and help them find it before it gets worse.Author(s)Catalin FilipPublished at13 Dec 2021Updated at18 Jul 2023
Detect and exploit Gitlab CE/EE RCE with Pentest-Tools.com (CVE-2021-22205)“Just patch it!” is the usual advice when a vulnerability hits (and it’s not a zero-day). But it’s never that simple in organizations that have to manage layers upon layers of infrastructure. When you have to deal with a critical CVE like the latest unauthenticated RCE in Gitlab (CVSSv3 10.0), the tangled, messy process of patching bubbles to the surface.Author(s)Daniel BecheneaPublished at05 Nov 2021Updated at12 Jul 2023
We’re leveling up! Check out the new website and brand update!As an ethical hacker, you know there’s always more to a piece of technology than meets the eye.Author(s)Andra ZahariaPublished at03 Nov 2021Updated at05 Oct 2022
Detect & exploit the latest CVEs + more automation updates“Great and getting even better” is what we commit to with each monthly update we roll out on Pentest-Tools.com.Author(s)Ioana RijnetuPublished at05 Oct 2021Updated at11 May 2023
How to detect CVE-2021-22986 RCE with Pentest-Tools.comAs a pentester, when you see a major critical vulnerability persist for months in unpatched systems (like Log4Shell), you have a responsibility to help others understand its severity and how they can fix it. This is exactly why this article exists.Author(s)Cristian CorneaPublished at21 Sep 2021Updated at09 Jun 2023