<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Lateral Movement on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/lateral-movement/</link>
    <description>Recent content in Lateral Movement on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Tue, 15 Apr 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/lateral-movement/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CVE-2025-52287 WSUS Deserialization to RCE: Four-Stage Exploitation via SimpleAuth Cookie Chain</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-04-15-cve-2025-52287-wsus-deserialize/</link>
      <pubDate>Tue, 15 Apr 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-04-15-cve-2025-52287-wsus-deserialize/</guid>
      
      <description>&lt;p&gt;WSUS treats the SimpleAuth plugin&amp;rsquo;s authentication Cookie as &amp;ldquo;verified trust&amp;rdquo;, but the chain that generates the Cookie has no strict deserialization protection — attackers use a 4-stage attack (obtain session ID, get auth Cookie, use Cookie to trigger SimpleAuth, inject malicious .NET deserialization payload) to gain RCE on the patch distribution center.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>Lazarus Group APT Attack on Cryptocurrency Exchanges: IOC &amp; TTP Disclosure</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-02-23-lazarus-apt-attack/</link>
      <pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-02-23-lazarus-apt-attack/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;Cybersecurity is a war of endurance. This article is co-authored by me (Thinking) and 23pds.&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2022-41082 Microsoft Exchange RCE: The SSRF Pre-Stage of ProxyNotShell</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-10-04-cve-2022-41082-exchange-rce/</link>
      <pubDate>Tue, 04 Oct 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-10-04-cve-2022-41082-exchange-rce/</guid>
      
      <description>&lt;p&gt;The SSRF pre-stage of the ProxyNotShell attack chain — when CVE-2022-41082 exists alone, it only lets the attacker hit Exchange&amp;rsquo;s internal PowerShell Remoting, but combined with CVE-2022-41040 it becomes full-network RCE.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2020-10770 Keycloak SSRF: One OIDC Parameter Exposes Internal Servers</title>
      <link>https://blog.1sec.day/en-gb/posts/2021-07-15-cve-2020-10770-keycloak-ssrf/</link>
      <pubDate>Wed, 18 Nov 2020 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2021-07-15-cve-2020-10770-keycloak-ssrf/</guid>
      
      <description>&lt;p&gt;A single OIDC parameter — &lt;code&gt;request_uri&lt;/code&gt; — is enough to turn Keycloak into a proxy. With no proper validation, any URL the attacker controls becomes a request Keycloak will fire for them.&lt;/p&gt;</description>
      
    </item>
    
    <item>
      <title>CVE-2016-3053 IBM AIX Privilege Escalation: A Missing Trust Check in libc System Calls</title>
      <link>https://blog.1sec.day/en-gb/posts/2016-11-15-cve-2016-3053-aix-privesc/</link>
      <pubDate>Tue, 15 Nov 2016 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2016-11-15-cve-2016-3053-aix-privesc/</guid>
      
      <description>&lt;p&gt;A missing identity check on a libc system call in IBM AIX gives any local unprivileged account a direct path to a root shell.&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
