<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>vdp on Christian Niel Angel</title>
    <link>https://ctulhu.me/tags/vdp/</link>
    <description>Recent content in vdp on Christian Niel Angel</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2024 Christian Niel Angel</copyright>
    <lastBuildDate>Tue, 29 Oct 2019 00:00:00 +0000</lastBuildDate><atom:link href="https://ctulhu.me/tags/vdp/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Exposed S3 Credentials of QuadX</title>
      <link>https://ctulhu.me/security/exposed-s3-credentials-of-quadx/</link>
      <pubDate>Tue, 29 Oct 2019 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/exposed-s3-credentials-of-quadx/</guid>
      <description>I found a exposed sensitive credential in the website and was able to access the Amazon S3 Bucket of Paylink, One of the digital platforms of QuadX. This allowed me to retrieve, upload and remove all files in the S3 Bucket.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/exposed-s3-credentials-of-quadx/featured.png" />
    </item>
    
    <item>
      <title>CVE-2018-19937</title>
      <link>https://ctulhu.me/security/cve-2018-19937/</link>
      <pubDate>Wed, 30 Jan 2019 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/cve-2018-19937/</guid>
      <description>A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone. Product: VLC for Mobile IOS Vendor: VideoLAN/Open Source Software Version: 3.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/cve-2018-19937/featured-vlc.png" />
    </item>
    
  </channel>
</rss>
