Alexander Constantinou
Penetration tester with 9+ years in offensive security. CVE analysis, Hack The Box writeups, and red team research.
// Latest
Recent Posts
CVE analysis, Hack The Box writeups, and security research.
amavisd falls back to cpio to unpack attachments → traversal path in the archive → JSP webshell in the webroot → RCE as zimbra, just by sending an email. CVSS 9.8.
Read morePassword spray → Kerberoast a weak service account → GenericWrite over a computer object → RBCD to local admin → cached DA credential → DCSync → Domain Admin.
Read moreA Groovy coercion the Script Security sandbox forgot to intercept lets a low-priv Job/Configure user escape the sandbox and run code on the controller → full CI/CD compromise.
Read moreJinja2 SSTI in a Flask preview feature → RCE as the web user → leaked config password reused on SSH → cap_setuid on python3 → root in one line.
Read moreT3/IIOP listener deserializes before auth → a gadget chain outside Oracle's blocklist triggers a JNDI lookup → code execution. The latest bypass of the same decade-old filter. CVSS 9.8.
Read moreLicensing servlet calls readObject() before verifying the bundle signature, reachable pre-auth → ysoserial gadget chain against bundled libs → RCE as the service. CVSS 9.8.
Read more// Contact
Get In Touch
Questions, opportunities, or just want to talk security.