<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web Attack on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/web-attack/</link><description>Recent content in Web Attack on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 16 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/web-attack/index.xml" rel="self" type="application/rss+xml"/><item><title>CDEF-EtherRAT</title><link>https://hexpysya.github.io/investigations/cdef-etherrat/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-etherrat/</guid><description>An attacker breached Maromalix&amp;rsquo;s public-facing web application by exploiting CVE-2025-55182 (Next.js Deserialization RCE). They deployed a multi-stage implant dubbed EtherRAT, which utilizes a blockchain-based C2 mechanism via Ethereum smart contracts to dynamically resolve infrastructure. The attacker exfiltrated sensitive data, established multiple persistence mechanisms, and ultimately patched the vulnerability to lock out other actors.</description></item><item><title>LD-Javascript Code Detected in Requested URL</title><link>https://hexpysya.github.io/blue_team/ld-javascript-code-detected-in-requested-url/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-javascript-code-detected-in-requested-url/</guid><description>An external IP performed XSS reconnaissance against the /search/ endpoint, cycling through multiple injection payloads. All requests except the first returned HTTP 302, indicating server-side sanitization blocked execution. The attack did not succeed.</description></item><item><title>LD-Passwd Found in Requested URL - Possible LFI Attack</title><link>https://hexpysya.github.io/blue_team/ld-passwd-found-in-requested-url---possible-lfi-attack/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-passwd-found-in-requested-url---possible-lfi-attack/</guid><description>An external Tencent Cloud IP sent a single LFI request targeting /etc/passwd via path traversal. The server returned HTTP 500 with an empty response body, confirming the attack did not succeed.</description></item><item><title>LD-Possible IDOR Attack Detected</title><link>https://hexpysya.github.io/blue_team/ld-idor/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-idor/</guid><description>External IP enumerated the /get_user_info/ endpoint via sequential IDOR requests, all returning HTTP 200 - confirming successful data exfiltration across five user accounts.</description></item><item><title>LD-Whoami Command Detected in Request Body</title><link>https://hexpysya.github.io/blue_team/ld-whoami-command-detected-in-request-body/</link><pubDate>Thu, 02 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-whoami-command-detected-in-request-body/</guid><description>An external attacker from a CHINANET-hosted IP (61.177.172.87) exploited a command injection vulnerability on WebServer1004, executing five OS commands via the ?c= parameter against /video/ - including cat /etc/passwd and cat /etc/shadow - all of which returned HTTP 200 with distinct response sizes, confirming successful remote code execution. The case was escalated to Tier 2.</description></item><item><title>LD-Arbitrary File Read on Checkpoint Security Gateway (CVE-2024-24919)</title><link>https://hexpysya.github.io/blue_team/ld-arbitrary-file-read-on-checkpoint-security-gateway-cve-2024-24919/</link><pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-arbitrary-file-read-on-checkpoint-security-gateway-cve-2024-24919/</guid><description>An attacker exploited CVE-2024-24919 against a Check Point Security Gateway, successfully reading /etc/passwd via a path traversal payload. A second request targeting /etc/shadow from a related IP was blocked. The attack succeeded and the endpoint was escalated to Tier 2.</description></item><item><title>LD-CVE-2025-53770 SharePoint ToolShell Auth Bypass and RCE</title><link>https://hexpysya.github.io/blue_team/ld-cve202553770-sharepoint-toolshell-auth-bypass-and-rce/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-cve202553770-sharepoint-toolshell-auth-bypass-and-rce/</guid><description>An attacker exploited CVE-2025-53770 against a SharePoint server, achieving unauthenticated RCE via .NET deserialization. The attacker extracted the MachineKey, compiled and dropped a payload, planted a webshell in the SharePoint layouts directory, and established a reverse connection to the attacker-controlled server.</description></item><item><title>LD-Possible SQL Injection Payload Detected</title><link>https://hexpysya.github.io/blue_team/ld-possible-sql-injection-payload-detected/</link><pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/blue_team/ld-possible-sql-injection-payload-detected/</guid><description>An external IP hosted on DigitalOcean performed a manual SQL injection reconnaissance against an internal web server, cycling through classic SQLi payloads. All requests returned HTTP 500, confirming the attack did not succeed.</description></item></channel></rss>