Black & White Path
Author

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

611
Articles
0
Likes
3.4k
Views
0
Comments
Recent Articles

Latest from Black & White Path

100 recent articles max
Black & White Path
Black & White Path
Aug 28, 2026 · Information Security

A Single Missing ‘!’ in nf_tables Triggers Full Root Compromise (CVE‑2026‑23111)

CVE‑2026‑23111 is a local privilege escalation in the Linux kernel’s nf_tables subsystem caused by a reversed conditional in nft_map_catchall_activate(), where the absence of a ‘!’ leads to a use‑after‑free, enabling an attacker to chain UAF, leak kernel addresses, build a ROP payload and gain root.

CVE-2026-23111Linux KernelROP
0 likes · 9 min read
A Single Missing ‘!’ in nf_tables Triggers Full Root Compromise (CVE‑2026‑23111)
Black & White Path
Black & White Path
Aug 26, 2026 · Information Security

How to Discover Unauthorized Access on Edu.cn Sites Using Hunter Queries

The article walks through using a Hunter.io query to locate edu.cn domains with registration pages, then demonstrates step‑by‑step vulnerability hunting—including login probing, directory scanning with the findsomething plugin, exposing an unauthenticated admin backend, and leveraging Burp and WPScan to gather sensitive data.

directory scanninghunter.ioinformation security
0 likes · 3 min read
How to Discover Unauthorized Access on Edu.cn Sites Using Hunter Queries
Black & White Path
Black & White Path
Aug 25, 2026 · Information Security

Bot and Fraud Detection Complete Guide: Dissecting a Six‑Layer Defense System

The article breaks down bot and fraud detection into a six‑layer onion model, explains the distinction between bots (automation) and fraud (intent), compares manual and automated abuse, and details concrete technical checks—from browser flags and anti‑detection engines to network fingerprints, behavioral biometrics, and business‑logic analysis—illustrated with code snippets, timing attacks, and real‑world examples.

Automationanti-botanti‑detection engine
0 likes · 28 min read
Bot and Fraud Detection Complete Guide: Dissecting a Six‑Layer Defense System
Black & White Path
Black & White Path
Aug 24, 2026 · Information Security

No‑Credentials RCE: One POST request grants root on Pakistan’s largest bank

A security analysis reveals that an unauthenticated Java deserialization flaw (CVE‑2017‑10271) in Oracle WebLogic's WS‑AT endpoint lets an attacker obtain a root shell on HBL’s internet‑facing banking nodes with a single POST request, then harvest credentials, hijack sessions, persist, and move laterally, while additional related bugs amplify the risk.

CVE-2017-10271Java DeserializationRemote Code Execution
0 likes · 10 min read
No‑Credentials RCE: One POST request grants root on Pakistan’s largest bank
Black & White Path
Black & White Path
Aug 21, 2026 · Information Security

One‑Click Telegram Proxy Link Can Reveal Your Real IP Address

Security researchers found that Telegram's Android and iOS clients automatically connect to specially crafted proxy links without user confirmation, allowing an attacker to capture the victim's real IP address in a single click, and Telegram has pledged to add a warning.

IP leakageTelegraminformation security
0 likes · 6 min read
One‑Click Telegram Proxy Link Can Reveal Your Real IP Address
Black & White Path
Black & White Path
Aug 20, 2026 · Information Security

Deep Dive into cPanel Auth Bypass CVE‑2026‑41940: CRLF Injection and the “Sorry” Ransomware Storm

The article provides a comprehensive technical analysis of the critical cPanel authentication bypass vulnerability CVE‑2026‑41940, detailing its CRLF‑injection root cause, public PoC, large‑scale GitHub Actions abuse, ties to the “Sorry” ransomware, impact on hosted services, and recommended patching and mitigation steps.

Authentication BypassCRLF InjectionCVE-2026-41940
0 likes · 13 min read
Deep Dive into cPanel Auth Bypass CVE‑2026‑41940: CRLF Injection and the “Sorry” Ransomware Storm
Black & White Path
Black & White Path
Aug 20, 2026 · Information Security

Dahua Cameras Compromised: 14,500 Devices Hijacked via Three Critical Vulnerabilities

In a 35‑day campaign dubbed CameraSwarm, attackers breached over 14,500 Dahua IP cameras using default‑exposed port 37777, exploiting CVE‑2021‑33044/45 with a persistent p2pwn backdoor, and leveraging a cloud SDK design flaw to gain unauthenticated remote access, especially targeting Ukraine and Russia.

Brute-force attackCVE-2021-33044CVE-2021-33045
0 likes · 9 min read
Dahua Cameras Compromised: 14,500 Devices Hijacked via Three Critical Vulnerabilities