Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
BillDemirkapi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
BillDemirkapi
3y ago
OP/bug finder here with some clarifying information. It's a common misconception that this issue can only be abused if you use HTTP boot. That is not the case at all, otherwise it wouldn't be Critical. This bug can be abused
2.
▲
by
BillDemirkapi
5y ago
I can assure you the answer clicked before my research ever started. Unless I am using web server software that responds with one site for multiple host names, you generally need to configure each host name that might be used with your web
3.
▲
by
BillDemirkapi
5y ago
Yes, but at the time I already had an existing domain with a web server I could use. You are correct that I could have setup a separate site for hidusi[.]com and then point the domain directly at my web server's IP, but since I already
4.
▲
by
BillDemirkapi
5y ago
Author here. Yes simply editing my hosts file would have been much easier. The reason I went the longer approach of setting up the payload on a remote web server was because there is the concept of security zones in Internet Explorer. Visit
5.
▲
Several Critical Vulnerabilities on most HP machines running Windows
(d4stiny.github.io)
2 points
by
BillDemirkapi
6y ago
|
0 comments
6.
▲
Local Privilege Escalation in most Dell machines running Windows
(d4stiny.github.io)
2 points
by
BillDemirkapi
7y ago
|
0 comments
7.
▲
by
BillDemirkapi
7y ago
Dell SupportAssist comes pre-installed on most new Dell machines. The only reason it wasn't installed on my machine is because the drive I used was not prepared by Dell. Your average Dell user will have SupportAssist installed though y
8.
▲
by
BillDemirkapi
7y ago
Unfortunately Dell doesn't pay bounties no matter how serious the bug is.
9.
▲
by
BillDemirkapi
7y ago
Yep.
10.
▲
by
BillDemirkapi
7y ago
There were a bunch of ways to bypass the check. For example another way would be to use "http:\\" which wouldn't get detected either. The new version isn't vulnerable.