Open in app

Sign In

Write

Sign In

James Sebree
James Sebree

176 Followers

Home

About

Published in Tenable TechBlog

·Dec 5, 2022

NETGEAR Router Network Misconfiguration

Last Minute Patch Thwarts Pwn2Own Entries Entering Pwn2Own is a daunting endeavor. The targets selected are often popular, already picked over devices with their inclusion in the event only increasing the amount of security researcher eyes pouring over them. Not only that, but it’s not uncommon for vendors to release…

Tenable Research

2 min read

NETGEAR Router Network Misconfiguration
NETGEAR Router Network Misconfiguration
Tenable Research

2 min read


Published in Tenable TechBlog

·Jul 28, 2022

Extracting Ghidra Decompiler Output with Python

Ghidra’s decompiler, while not perfect, is pretty darn handy. Ghidra’s user interface, however, leaves a lot to be desired. …

Tenable Research

4 min read

Extracting Ghidra Decompiler Output with Python
Extracting Ghidra Decompiler Output with Python
Tenable Research

4 min read


Published in Tenable TechBlog

·Jul 19, 2022

Logging Passwords in Plaintext in Azure Arc

Microsoft’s Azure Arc is a management platform designed to bridge multi-cloud and similarly mixed environments together in a convenient way. Tenable Research has discovered that the Jumpstart environments for Arc do not properly use logging utilities common amongst other Azure services. This leads to potentially sensitive information, such as service…

Tenable Research

2 min read

Logging Passwords in Plaintext in Azure Arc
Logging Passwords in Plaintext in Azure Arc
Tenable Research

2 min read


Published in Tenable TechBlog

·Jul 12, 2022

Microsoft Azure Site Recovery DLL Hijacking

Azure Site Recovery is a suite of tools aimed at providing disaster recovery services for cloud resources. It provides utilities for replication, data recovery, and failover services during outages. Tenable Research has discovered that this service is vulnerable to a DLL hijacking attack due to incorrect directory permissions. …

Tenable Research

3 min read

Microsoft Azure Site Recovery DLL Hijacking
Microsoft Azure Site Recovery DLL Hijacking
Tenable Research

3 min read


Published in Tenable TechBlog

·Jun 13, 2022

Microsoft Azure Synapse Pwnalytics

Synapse Analytics is a platform used for machine learning, data aggregation, and other such computational work. One of the primary developer-oriented features of this platform is the use of Jupyter notebooks. …

Tenable Research

11 min read

Microsoft Azure Synapse Pwnalytics
Microsoft Azure Synapse Pwnalytics
Tenable Research

11 min read


Published in Tenable TechBlog

·Jan 31, 2022

TrendNET AC2600 RCE via WAN

This blog provides a walkthrough of how to gain RCE on the TrendNET AC2600 (model TEW-827DRU specifically) consumer router via the WAN interface. There is currently no publicly available patch for these issues; therefore only a subset of issues disclosed in TRA-2021–54 will be discussed in this post. …

Tenable Research

3 min read

TrendNET AC2600 RCE via WAN
TrendNET AC2600 RCE via WAN
Tenable Research

3 min read


Published in Tenable TechBlog

·Nov 11, 2021

New World’s Botting Problem

New World, Amazon’s latest entry into the gaming world, is a massive multiplayer online game with a sizable player base. For those unfamiliar, think something in the vein of World of Warcraft or Runescape. After many delays and an arguably bumpy launch… well, we’ve got a nice glimpse at some…

Infosec

8 min read

New World’s Botting Problem
New World’s Botting Problem
Infosec

8 min read


Published in Tenable TechBlog

·Sep 8, 2021

ARRIS CABLE MODEM TEARDOWN

Picked up one of these a little while back at the behest of a good friend. It’s an Arris Surfboard SB8200 and is one of the most popular cable modems out there. …

Tenable Research

6 min read

ARRIS CABLE MODEM TEARDOWN
ARRIS CABLE MODEM TEARDOWN
Tenable Research

6 min read


Published in Tenable TechBlog

·Aug 31, 2021

Cisco WebEx Universal Links Redirect

What’s dumber than an open redirect? This. The following is a quick and dirty companion write-up for TRA-2021–34. The issue described has been fixed by the vendor. After being forced to use WebEx a little while back, I noticed that the URIs and protocol handlers for it on macOS contained…

Tenable Research

3 min read

Cisco WebEx Universal Links Redirect
Cisco WebEx Universal Links Redirect
Tenable Research

3 min read


Published in Tenable TechBlog

·Jun 3, 2021

More macOS Installer Flaws

Back in December, we wrote about attacking macOS installers. Over the last couple of months, as my team looked into other targets, we kept an eye on the installers of applications we were using and interacting with regularly. …

Tenable Research

10 min read

More macOS Installer Flaws
More macOS Installer Flaws
Tenable Research

10 min read

James Sebree

James Sebree

176 Followers
Following
  • April Wright

    April Wright

  • Sai Krishna Kothapalli

    Sai Krishna Kothapalli

  • David Wells

    David Wells

  • Chris Lyne

    Chris Lyne

  • Javier Olmedo

    Javier Olmedo

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech