<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recherche on Fenrisk</title><link>https://fenrisk.com/research/</link><description>Recent content in Recherche on Fenrisk</description><generator>Hugo</generator><language>fr-FR</language><lastBuildDate>Fri, 02 Oct 2026 01:20:13 +0600</lastBuildDate><atom:link href="https://fenrisk.com/research/index.xml" rel="self" type="application/rss+xml"/><item><title>Open Build Service, one year later: command execution through Mercurial argument injection</title><link>https://fenrisk.com/research/open-build-service-2/</link><pubDate>Fri, 02 Oct 2026 01:20:13 +0600</pubDate><guid>https://fenrisk.com/research/open-build-service-2/</guid><description>In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…</description></item><item><title>HTTP Request Smuggling in Hiawatha - CVE-2026-51785</title><link>https://fenrisk.com/research/hiawatha-http-smuggling/</link><pubDate>Thu, 23 Jul 2026 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/hiawatha-http-smuggling/</guid><description>As part of our ongoing research into request smuggling, we identified an HTTP Request Smuggling vulnerability (CWE-444) in Hiawatha ≤ 12.1. Hiawatha is an open-source, security-focused web server for Unix-like systems, used to serve websites and host web applications.</description></item><item><title>MCPwned: a Burp Suite extension for auditing MCP servers</title><link>https://fenrisk.com/research/mcpwned/</link><pubDate>Wed, 22 Apr 2026 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/mcpwned/</guid><description>This blog post quickly outlines the MCP protocol before presenting a Burp Suite extension developed by Fenrisk that enables pentesters to effectively test MCP servers.</description></item><item><title>Remote code execution in CentOS Web Panel - CVE-2025-70951</title><link>https://fenrisk.com/research/rce-centos-web-panel-2/</link><pubDate>Thu, 02 Apr 2026 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/rce-centos-web-panel-2/</guid><description>As part of our ongoing research into web hosting control panels, we recently published an analysis of Control Web Panel (CWP), a widely used open-source administration panel designed to manage web servers running…</description></item><item><title>Detecting Jira &amp; Confluence Versions and Mapping Known CVEs</title><link>https://fenrisk.com/research/atlasscan/</link><pubDate>Tue, 14 Oct 2025 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/atlasscan/</guid><description>This blog post presents a tool that identifies the version of the Atlassian Jira or Confluence application and maps the identified version to a local CVE database. The detection is primarily based on the presence of…</description></item><item><title>Remote code execution in aaPanel - CVE-2025-48702</title><link>https://fenrisk.com/research/rce-aapanel/</link><pubDate>Mon, 08 Sep 2025 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/rce-aapanel/</guid><description>aaPanel is a free and open-source web hosting control panel designed to simplify server management for Linux-based systems. It provides a graphical interface to manage web servers, websites,…</description></item><item><title>Remote code execution in CentOS Web Panel - CVE-2025-48703</title><link>https://fenrisk.com/research/rce-centos-web-panel/</link><pubDate>Mon, 23 Jun 2025 01:00:00 +0600</pubDate><guid>https://fenrisk.com/research/rce-centos-web-panel/</guid><description>CentOS Web Panel (CWP) is a free web hosting control panel used to manage servers based on CentOS and other RPM-based distributions. CWP was first introduced in 2013 as a free, open-source web hosting control panel…</description></item><item><title>Supply Chain Attacks on Linux distributions - OpenSUSE Open Build Service</title><link>https://fenrisk.com/research/open-build-service/</link><pubDate>Mon, 10 Mar 2025 01:20:13 +0600</pubDate><guid>https://fenrisk.com/research/open-build-service/</guid><description>Open Build Service (OBS) is an open-source distribution development platform provided by openSUSE. It allows developers to manage the whole packaging process in order to build a package from a simple software source and…</description></item><item><title>Supply Chain Attacks on Linux distributions - Fedora Pagure</title><link>https://fenrisk.com/research/pagure-fedora/</link><pubDate>Mon, 10 Mar 2025 01:19:13 +0600</pubDate><guid>https://fenrisk.com/research/pagure-fedora/</guid><description>As discussed in the meta-article, we picked Pagure from the Fedora Apps Directory and already had a technical approach in mind. A software forge is likely to be a good target for an argument injection: we can expect the…</description></item><item><title>Supply Chain Attacks on Linux distributions - Overview</title><link>https://fenrisk.com/research/supply-chain-linux/</link><pubDate>Mon, 10 Mar 2025 01:18:13 +0600</pubDate><guid>https://fenrisk.com/research/supply-chain-linux/</guid><description>Supply chain attacks have been a trendy topic in the past years. Rather than directly attacking their primary target, attackers infiltrate less secure assets, such as software dependencies, firmware, or service…</description></item><item><title>Gadget chains in Laravel</title><link>https://fenrisk.com/research/gadget-chains-laravel/</link><pubDate>Thu, 30 Nov 2023 11:18:13 +0600</pubDate><guid>https://fenrisk.com/research/gadget-chains-laravel/</guid><description>As we have seen in the previous article about wordpress gadgets, very simple gadget chains can be found in major projects. But sometimes finding popchain may be more difficult. This article…</description></item><item><title>Gadget chains in Wordpress</title><link>https://fenrisk.com/research/gadget-chains-wordpress/</link><pubDate>Wed, 22 Nov 2023 11:18:13 +0600</pubDate><guid>https://fenrisk.com/research/gadget-chains-wordpress/</guid><description>Exploiting an unserialization vulnerability in WordPress never was a small issue. Unlike other PHP frameworks, and until very recently, WordPress was not known for hosting gadget chains.</description></item></channel></rss>