Rhino Security Labs

Strategic & Technical Blog

CVE-2020-5377: Dell OpenManage Server Administrator File Read

David Yesland

This blog explores a file read vulnerability in Dell OpenManage Server Administrator (OMSA) we found during an internal network penetration test, tracked as CVE-2020-5377 and a bypass for the fix tracked as CVE-2021-21514. 
When this Dell…

Java Deserialization Exploitation With
Customized Ysoserial Payloads

GKE Kubelet TLS Bootstrap Privilege Escalation

Fuzzing Left4Dead 2 with CERT’s
Basic Fuzzing Framework

Hunter Stanton

If you saw my previous blog post on the buffer overflow I found in Left4Dead 2, you know that I found that vulnerability through fuzzing. 
Modern game engines usually have a very large attack surface within which vulnerabilities could…