During the past few assessments, Sprocket has encountered improperly configured instances of Lucee 5 and 4. This blog post will detail a straightforward method to execute remote code after acquiring administrative access to a Lucee login panel.
Resources
All Resources
Library
Explore our collection of resources, including blog articles, webcasts, case studies, and eBooks.
In this article, we will look at a few different takeover methods, detail how we find them, show how they are exploited, and the easy solution to fixing this potentially severe vulnerability.
Gordon Flesch Company is committed to securing its customers' data. By partnering with Sprocket, Gordon Flesch Company is now utilizing Sprocket's Internal & External Continuous Penetration Testing.
Citizens Bank is committed to securing its customers' highly sensitive financial data. By partnering with Sprocket, Citizens Bank now stays highly aware of emerging threats that may affect its attack surface. By leveraging Continuous Penetration Testing with Sprocket, identification, and remediation efforts are improved upon seamlessly.
Tools such as dirbuster, gobuster, feroxbuster, dirb, and ffuf have been instrumental in uncovering hidden content on websites. These tools and wordlists designed to discover files and directories have become staples in the toolkits of penetration testers and bug bounty hunters. Now more than ever, technology plays a vital role in cybersecurity practices.
Watch for an insightful webinar as Will merges the worlds of web application penetration testing and Attack Surface Management (ASM) data. Using examples from real life penetration tests, he will demonstrate some of the ways web app vulnerabilities can be exploited using information from ASM data, often from overlooked or underestimated sources. Will will also discuss some of the methodologies...