Aaivr-bloginaivr.hashnode.dev·Aug 24 · 3 min readSudo Privilege Escalation to Root via Sudoedit Multi-Argument Policy BypassSummary A local user who is permitted to run sudoedit as root via wildcard-limited rule can bypass pathname restriction and use affected C Sudo builds to read or modify files outside of the intended d00
Aaivr-bloginaivr.hashnode.dev·Aug 12 · 2 min readWebmin Help Template Authenticated Remote Command ExecutionSummary Webmin help system accepts template variables via query parameters and processes them through the eval function. This allows an authenticated user to execute commands with root privileges. How00
Aaivr-bloginaivr.hashnode.dev·Jan 26 · 21 min readFinding 0days with AIFor decades, many bug hunters and security pros have used manual testing, static analysis, and fuzzing to find vulnerabilities. Enter the age of AI. Many are skeptical, but when I look around I see mo00
Aaivr-bloginaivr.hashnode.dev·Jan 23 · 3 min readAwesomeBot meets MCPIntro AwesomeBot is an awesome AI Chatbot! It was vibe coded from scratch to have a ton of awesome features without much security in mind so various attacks and offensive methods can be demonstrated. Today, AwesomeBot meets MCP. What happens next? Le...00
Aaivr-bloginaivr.hashnode.dev·Jan 14 · 7 min readAwesomeBot meets Prompt InjectionIntro AwesomeBot is an awesome AI Chatbot! It was vibe coded from scratch to have a ton of awesome features without much security in mind so various attacks and offensive methods can be demonstrated. This series of blog posts serves as a way to under...00