<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Nils Emmerich on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/nils-emmerich/</link>
    <description>Recent content in Nils Emmerich on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 12 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/nils-emmerich/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TIA Project Parser</title>
      <link>https://insinuator.net/2026/08/tia-project-parser/</link>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/tia-project-parser/</guid>
      <description>&lt;p&gt;While working on an OT project, we looked into TIA Portal&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; project files to extract more information about changes, especially timestamps to be able to reconstruct a timeline. The TIA Portal (Totally Integrated Automation Portal) allows to create and upload programs for PLC (Programmable Logic Controller) devices often used in the OT (Operational Technology) landscape. Some attacks are able to find the workstation with the TIA Portal and manipulate the project to reprogram the PLCs. To be able to reconstruct the timeline of these changes we wanted to be able to read the timestamps of events from the TIA project files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Command Injection in Geutebrück Cameras</title>
      <link>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</link>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we identified a command injection&#xA;vulnerability in Geutebrück security cameras that allows authenticated attackers&#xA;to execute arbitrary commands as root through the web interface. The root cause&#xA;is unsanitized user input being passed into a &lt;code&gt;sed&lt;/code&gt; script (and at least 12&#xA;other CGI endpoints). In addition to the injection, we identified an XSS&#xA;vulnerability, an exposed system menu leaking configuration and log data, and an&#xA;insecure GET-parameter-to-environment-variable mapping that enables abuse of&#xA;variables like &lt;code&gt;LD_PRELOAD&lt;/code&gt; and &lt;code&gt;LD_DEBUG&lt;/code&gt;. We reported the findings to&#xA;Geutebrück and a patched firmware was provided. This post walks through how we&#xA;got from a  &lt;code&gt;sed&lt;/code&gt; error message to a root shell.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Assessing Endpoint Protection: Our Approach to EDR/XDR and Supplements Evaluation</title>
      <link>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</guid>
      <description>&lt;p&gt;There is a growing landscape of security products promising to protect an&#xA;organization’s IT infrastructure from attacks. Solutions referred to as EDR, and&#xA;sometimes also as XDR, are designed to protect endpoints from all malicious&#xA;activity. The ever-increasing cases of breaches and the associated costs,&#xA;especially in the realm of&#xA;&lt;a href=&#34;https://www.totalassure.com/blog/ransomware-statistics-by-year-2025-comprehensive-report&#34;&gt;ransomware attacks&lt;/a&gt;,&#xA;raise the question of whether there is more that can be done to add an&#xA;additional layer to traditional endpoint protection concepts. That is why a&#xA;customer of ours commissioned us to evaluate whether EDR supplementing solutions&#xA;provide extended protection against ever-evolving threats, as well as to shine a&#xA;light on the performance overheads those solutions might introduce.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Authentication Bypass in VERTIV Avocent AutoView (Version 2.10.0.0.4736)</title>
      <link>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</link>
      <pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</guid>
      <description>&lt;p&gt;The VERTIV Avocent AutoView switches are analog keyboard, video, and mouse (KVM)&#xA;switches used in data center servers. They also expose a web server in the&#xA;network, which allows for some configuration.&lt;/p&gt;&#xA;&lt;p&gt;During a penetration test for a customer, a device of this type was identified&#xA;in the infrastructure and analyzed, revealing an authentication bypass in the&#xA;web application.&lt;/p&gt;&#xA;&lt;p&gt;The application is written in PHP. To gain access to the PHP scripts, the&#xA;firmware update was downloaded from the vendor’s download page. From the update,&#xA;the PHP files can easily be extracted and analyzed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Multiple Vulnerabilities in X.Org X server prior to 21.1.17 and Xwayland prior to 24.1.7</title>
      <link>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</link>
      <pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</guid>
      <description>&lt;p&gt;The X11 Window System has been used since September 1987 for Unix desktop&#xA;systems, allowing applications to display their windows. Today, one of the&#xA;server implementations of the protocol is the X.Org X server and XWayland, which&#xA;both use the same codebase. While reviewing the X server, several legacy&#xA;security issues were identified. These appear to originate from earlier design&#xA;stages when security considerations were less prominent. Despite the project’s&#xA;maturity and widespread use, some of these issues have persisted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions &lt; 1.32.5 - CVE-2024-55225</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</link>
      <pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we briefly assessed &lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt;, an open-source online password safe. In June 2024, the German Federal Office for Information Security (BSI) published results&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of a static and dynamic test of the Vaultwarden server component. Therefore, only a partial source code audit was performed during our assessment. However, a quick look was needed to find some glaring issues with the authentication.&lt;/p&gt;&#xA;&lt;h2 id=&#34;vaultwarden&#34;&gt;Vaultwarden&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt; is an alternative online password safe server to Bitwarden and exposes the same API so that Bitwarden clients can connect to the Vaultwarden server. Since Bitwarden has a Browser client and Mobile clients, they can all connect to Vaultwarden, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lua-Resty-JWT Authentication Bypass</title>
      <link>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</link>
      <pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</guid>
      <description>&lt;p&gt;I was writing some challenges for PacketWars at&#xA;&lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS22&lt;/a&gt;. One was intended to be a JWT key confusion&#xA;challenge where the public key from an RSA JWT should be recovered and used to&#xA;sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT&#xA;key confusion by default and found &lt;em&gt;lua-resty-jwt&lt;/em&gt;. The original repository by&#xA;&lt;em&gt;SkyLothar&lt;/em&gt; is not maintained and different from the library that is installed&#xA;with the LuaRocks package manager. The investigated library is a&#xA;&lt;a href=&#34;https://github.com/cdbattags/lua-resty-jwt&#34;&gt;fork&lt;/a&gt; of the original repository,&#xA;maintained by &lt;em&gt;cdbattags&lt;/em&gt; in version 0.2.3 and was downloaded more than&#xA;&lt;a href=&#34;https://luarocks.org/modules/cdbattags/lua-resty-jwt&#34;&gt;4.8 million times&lt;/a&gt;&#xA;according to LuaRocks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java Buffer Overflow with ByteBuffer (CVE-2020-2803) and Mutable MethodType (CVE-2020-2805) Sandbox Escapes</title>
      <link>https://insinuator.net/2020/09/java-buffer-overflow-with-bytebuffer-cve-2020-2803-and-mutable-methodtype-cve-2020-2805-sandbox-escapes/</link>
      <pubDate>Wed, 02 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/java-buffer-overflow-with-bytebuffer-cve-2020-2803-and-mutable-methodtype-cve-2020-2805-sandbox-escapes/</guid>
      <description>&lt;p&gt;Years ago, Java could be used on websites trough applets. To make these applets secure and not let them access files or do other dangerous stuff, Java introduced the SecurityManager. Before some action was performed, the SecurityManager was asked if the code is privileged to perform this action. However, since the SecurityManager lives in the same running program and can be accessed via System.getSecurityManager(), there &lt;a href=&#34;http://www.phrack.org/papers/escaping_the_java_sandbox.html&#34;&gt;existed some ways to remove it&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins – Groovy Sandbox breakout (SECURITY-1538 / CVE-2019-10393, CVE-2019-10394, CVE-2019-10399, CVE-2019-10400)</title>
      <link>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</link>
      <pubDate>Fri, 20 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</guid>
      <description>&lt;p&gt;Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We responsibly disclosed this vulnerability and in the current version of Jenkins it has been fixed and the according &lt;a href=&#34;https://jenkins.io/security/advisory/2019-09-12/&#34;&gt;Jenkins Security Advisory 2019-09-12&lt;/a&gt; has been published. In this blogpost I want to report a bit on the technical details of the vulnerability.&lt;/p&gt;&#xA;&lt;h1 id=&#34;description&#34;&gt;Description&lt;/h1&gt;&#xA;&lt;p&gt;The groovy sandbox transforms some AST nodes of the script to add security checks. For example&lt;/p&gt;</description>
    </item>
    <item>
      <title>LibreOffice – A Python Interpreter (code execution vulnerability CVE-2019-9848)</title>
      <link>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</link>
      <pubDate>Fri, 26 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</guid>
      <description>&lt;p&gt;While waiting for a download to complete, I stumbled across an interesting &lt;a href=&#34;https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html&#34;&gt;blogpost&lt;/a&gt;. The author describes a flaw in LibreOffice that allowed an attacker to execute code. Since this was quite recent, I was interested if my version is vulnerable to this attack and how they fixed it. Thus, I looked at the sources and luckily it was fixed. What I didn’t know before however was, that macros shipped with LibreOffice are executed without prompting the user, even on the highest macro security setting. So, if there would be a system macro from LibreOffice with a bug that allows to execute code, the user would not even get a prompt and the code would be executed right away. Therefor, I started to have a closer look at the source code and found out that exactly this is the case!&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
