Yunhai Zhang
@_f0rgetting_
Security Researcher
Dit vind je misschien leuk
Can't believe that Microsoft not fix Win 10 network printer issue but break Win 11 too. So, is that actually a feature not a bug?
Just found that not publish slides of conference for years, so upload recent ones: github.com/f0rgetting/Pre… And I will talk at #POC2021 next week, would you join the talk? ^_^
It seems that session pool is removed in WIP. @aionescu @tiraniddo did you have any idea why?
Did you realize that all #printnightmare fix are try to restrict to administrators? It essentially allow UAC bypass. Of course UAC is not a security boundary, so this is not a security issue.
OK, @gentilkiwi found the 3rd one. I have no doubt that he will find the remains soon, just hope that won't be too soon.
But my favorite (for now) #printnightmare dirty trick is: *as a standard user* the way to *force* all other users/admins of workstation/server to install printers😂 rundll32 printui,PrintUIEntry /ga /n"\\print.lab.local\Kiwi Legit Printer" Rpc(Asyn)cAddPerMachineConnection
Now we got CVE-2021-36958, is it for the not fixed one? or just another one again?
Initial patch analysis show that CVE-2021-34481 only fix @Junior_Baines 's driver install issue, which is not necessary to copy file. Now, 2 of them is public, one is fixed, one not.
However, they just pay $5k for #printernightmare , actually it is $0 if I not tweet the demo video. OK, they do not recognize that CVE-2021-1675 is PrinterNightmare, maybe that is why. Well Done! Guess who will report Next Printer Nightmare?
Microsoft Bug Bounty Programs awarded $13.6M to 341 security researchers in the last 12 months. Thank you to everyone for your continued work to help secure millions of customers. msrc-blog.microsoft.com/2021/07/08/mic…
United States Trends
- 1. Cheney 81.1K posts
- 2. Sedition 159K posts
- 3. Lamelo 4,713 posts
- 4. Seditious 87.7K posts
- 5. First Take 46.5K posts
- 6. Jeanie 1,850 posts
- 7. Mark Walter 1,363 posts
- 8. Constitution 110K posts
- 9. Coast Guard 21.4K posts
- 10. Seager 1,021 posts
- 11. Commander in Chief 50.3K posts
- 12. Elon Musk 279K posts
- 13. Trump and Vance 36.3K posts
- 14. UNLAWFUL 75.3K posts
- 15. Cam Newton 4,281 posts
- 16. Shayy 13.4K posts
- 17. UCMJ 9,825 posts
- 18. Nano Banana Pro 23.9K posts
- 19. #WeekndTourLeaks 1,450 posts
- 20. Dameon Pierce N/A
Dit vind je misschien leuk
-
Zhihua Yao
@hackyzh -
KevinLu
@K3vinLuSec -
Ivan Fratric 💙💛
@ifsecure -
Vitaly Nikolenko
@vnik5287 -
rthhh
@rthhh17 -
Jeremy Fetiveau
@__x86 -
zenhumany
@zenhumany -
k0shl
@KeyZ3r0 -
Xiaoliang Liu
@flame36987044 -
Lays
@_L4ys -
Jioundai
@Jioun_dai -
TinySec
@TinySecEx -
Angelboy
@scwuaptx -
just a script kid.
@hjy79425575 -
Đào Trọng Nghĩa
@nghiadt1098
Something went wrong.
Something went wrong.