Blog
All blog posts from modzero.
-
PLAYGROUND
Tutorial: How we learned to love the doc(umentation)
October 14, 2024
Just read documentation to get RCE?! Our colleague Theresa designed a tutorial guiding you through an OpenVPN exploit scenario — for you to try at home!
-
DISCLOSURE
Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes
June 7, 2024
We exploited an unauthenticated command injection within the spam filter appliance MailCleaner that can be triggered through a malicious email address.
-
DISCLOSURE
Multiple Vulnerabilities in Poly VoIP Products
December 29, 2023
We uncovered several vulnerabilities allowing an attacker in the network to take over a Poly VoIP device and turn it into a bug hidden in plain sight.
-
COMPANY
12th Anniversary
April 29, 2023
Today we celebrate our 12th anniversary.
-
DISCLOSURE
Better Make Sure Your Password Manager Is Secure
December 19, 2022
We examined the password management solution Passwordstate of Click Studios and identified multiple high severity vulnerabilities.
-
COMPANY
Ridiculous Vulnerability Disclosure Process with CrowdStrike Falcon Sensor
August 22, 2022
We publish a new advisory for a vulnerability in CrowdStrike Falcon Sensor as well as share our thoughts about the ridiculous disclosure process.
1 of 2
Next ⟶
All blog posts from modzero.
-
PLAYGROUND
Tutorial: How we learned to love the doc(umentation)
October 14, 2024
Just read documentation to get RCE?! Our colleague Theresa designed a tutorial guiding you through an OpenVPN exploit scenario — for you to try at home!
-
DISCLOSURE
Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes
June 7, 2024
We exploited an unauthenticated command injection within the spam filter appliance MailCleaner that can be triggered through a malicious email address.
-
DISCLOSURE
Multiple Vulnerabilities in Poly VoIP Products
December 29, 2023
We uncovered several vulnerabilities allowing an attacker in the network to take over a Poly VoIP device and turn it into a bug hidden in plain sight.
-
COMPANY
12th Anniversary
April 29, 2023
Today we celebrate our 12th anniversary.
-
DISCLOSURE
Better Make Sure Your Password Manager Is Secure
December 19, 2022
We examined the password management solution Passwordstate of Click Studios and identified multiple high severity vulnerabilities.
-
COMPANY
Ridiculous Vulnerability Disclosure Process with CrowdStrike Falcon Sensor
August 22, 2022
We publish a new advisory for a vulnerability in CrowdStrike Falcon Sensor as well as share our thoughts about the ridiculous disclosure process.