ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

Vesta Admin Takeover - Exploiting reduced seed entropy in bash $RANDOM - Adrian Tiron

Автор: OWASP London

Загружено: 2026-03-01

Просмотров: 12

Описание: "Vesta CP Admin Takeover - Exploiting reduced seed entropy in bash $RANDOM" - Adrian Tiron

Vesta is a lightweight, web-based control panel that simplifies Linux server management, appealing to users seeking an intuitive alternative to traditional platforms like cPanel and Plesk. This presentation will examine a critical flaw in Vesta: an admin takeover exploit resulting from reduced seed entropy in the Bash $RANDOM variable. By transforming what was once a theoretical attack into a practical one, we successfully reduced the brute force domain of the seed by over 98%. This allows attackers to generate predictable random values, compromising the security of passwords and tokens. We will discuss the implications of this vulnerability and highlight best practices for enhancing server security in real-world applications.

SPEAKER BIO

Adrian Tiron is a Co-Founder & Principal Pentester/Red Teamer at FORTBRIDGE with 20 years of experience in cybersecurity. He has a proven track record of success working with top companies in the UK, US, and Europe. As a dedicated researcher and blog author, Adrian has uncovered multiple critical vulnerabilities in open-source and commercial software, contributing significantly to improving online security.

This talk was presented at the OWASP London Chapter Meetup on February 26, 2026 kindly hosted by ‪@CivoCloud‬ Tech Junction and kindly sponsored by ‪@Curity‬ . An additional raffle prize was sponsored by ‪@FORTBRIDGE‬

#owasplondon #owasp #pentesting #bugbountytips

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
Vesta Admin Takeover - Exploiting reduced seed entropy in bash $RANDOM  - Adrian Tiron

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

Deep Dive into the OWASP Top 10 for Agentic AI Applications - John Sotiropoulos

Deep Dive into the OWASP Top 10 for Agentic AI Applications - John Sotiropoulos

Securing Vibe Coding: Addressing the Security Challenges of AI-Generated Code - Sonya Moisset

Securing Vibe Coding: Addressing the Security Challenges of AI-Generated Code - Sonya Moisset

OWASP London Chapter  Meetup 26-Feb-2026 Live-Stream

OWASP London Chapter Meetup 26-Feb-2026 Live-Stream

LLM Attacks and Defences - Prompt Hacking - Dominic Whewell

LLM Attacks and Defences - Prompt Hacking - Dominic Whewell

Вместо скриптов на Python! Магия однострочников на Bash (awk, xargs, parallel)

Вместо скриптов на Python! Магия однострочников на Bash (awk, xargs, parallel)

Race Against The Workflows: Stealing GitHub Tokens from Docker Images - Gaëtan Ferry

Race Against The Workflows: Stealing GitHub Tokens from Docker Images - Gaëtan Ferry

Scaling Threat Modeling with a Developer-Centric Approach - Andrew Hainault & Andrea Scaduto

Scaling Threat Modeling with a Developer-Centric Approach - Andrew Hainault & Andrea Scaduto

They Said It Couldn't Be Done - Starling Bank

They Said It Couldn't Be Done - Starling Bank

30 Tips for Secure JavaScript - Tanya Janca

30 Tips for Secure JavaScript - Tanya Janca

The most powerful AI Agent I’ve ever used in my life

The most powerful AI Agent I’ve ever used in my life

Databricks Connect + Spark Connect: How you can build on Spark from anywhere

Databricks Connect + Spark Connect: How you can build on Spark from anywhere

Advancing Spark - Data Lakehouse Star Schemas with Dynamic Partition Pruning!

Advancing Spark - Data Lakehouse Star Schemas with Dynamic Partition Pruning!

Код Клода: НОВЫЙ пульт дистанционного управления, автоматическое запоминание, плагины и многое др...

Код Клода: НОВЫЙ пульт дистанционного управления, автоматическое запоминание, плагины и многое др...

Securing AI Agents: Identity Strategies for Safe API Access - Gary Archer

Securing AI Agents: Identity Strategies for Safe API Access - Gary Archer

⚡НАКИ: Путин СРОЧНО ВЫЗВАЛ СОВЕТ НОЧЬЮ в Кремль! Бюджет УМИРАЕТ. Набиуллина АЖ РАСТЕРЯЛАСЬ

⚡НАКИ: Путин СРОЧНО ВЫЗВАЛ СОВЕТ НОЧЬЮ в Кремль! Бюджет УМИРАЕТ. Набиуллина АЖ РАСТЕРЯЛАСЬ

KXCON23 | The Science of Price Impact Modeling | kdb at Imperial College

KXCON23 | The Science of Price Impact Modeling | kdb at Imperial College

How Starling Built Their Own Card Processor

How Starling Built Their Own Card Processor

MLOps in action: Operationalize your ML workflow using pipeline templates

MLOps in action: Operationalize your ML workflow using pipeline templates

DNS Based OSINT Techniques for Product and Service Discovery - Rishi C

DNS Based OSINT Techniques for Product and Service Discovery - Rishi C

We Built an AI Render Engine for FREE

We Built an AI Render Engine for FREE

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]