Oct. 28, 2023, 5:24 p.m. | /u/CyberBarbier

cybersecurity www.reddit.com

Hello, I'm partaking in a private bounty, I have found a base64 deserialization command injection.
I'm able to execute certutil.exe and ping -n 1 -l 1 [10.10.10.10](https://10.10.10.10) for example,
I get both dns and http request to the correct endpoint using certutil, while an icmp dump shows the ping so the command injection is pretty much confirmed.
Thing is, I haven't been able to go past that,
the server should be [ASP.NET](https://ASP.NET) but the deserialization is in Java and the …

base64 bounty certutil command command injection cybersecurity deserialization dns endpoint found hello http icmp injection java java deserialization ping private request

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)