<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>hacking — LowEndSpirit</title>
        <link>https://lowendspirit.com/index.php?p=/</link>
        <pubDate>Thu, 04 Jun 2026 02:27:56 +0000</pubDate>
        <language>en</language>
            <description>hacking — LowEndSpirit</description>
    <atom:link href="https://lowendspirit.com/index.php?p=/discussions/tagged/hacking/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Critical Apache Guacamole Flaws Put Remote Desktops at Risk of Hacking</title>
        <link>https://lowendspirit.com/index.php?p=/discussion/1372/critical-apache-guacamole-flaws-put-remote-desktops-at-risk-of-hacking</link>
        <pubDate>Thu, 02 Jul 2020 11:38:07 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>mikho</dc:creator>
        <guid isPermaLink="false">1372@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>A new research has uncovered multiple critical <a rel="nofollow" href="https://thehackernews.com/2020/05/reverse-rdp-attack-patch.html" title="reverse RDP vulnerabilities">reverse RDP vulnerabilities</a> in Apache Guacamole, a popular remote desktop application used by system administrators to access and manage Windows and Linux machines remotely.</p>

<p>The reported flaws could potentially let bad actors achieve full control over the Guacamole server, intercept, and control all other connected sessions.</p>

<p>According to a <a rel="nofollow" href="https://blog.checkpoint.com/2020/07/02/hole-y-guacamole-fixing-critical-vulnerabilities-in-apaches-popular-remote-desktop-gateway/" title="report">report </a>published by Check Point Research and shared with The Hacker News, the flaws grant "an attacker, who has already successfully compromised a computer inside the organization, to launch an attack on the Guacamole gateway when an unsuspecting worker tries to connect to an infected machine."</p>

<p>After the cybersecurity firm responsibly disclosed its findings to Apache, the maintainers of Guacamole, on March 31, the company released a <a rel="nofollow" href="https://guacamole.apache.org/releases/1.2.0/" title="patched version">patched version</a> in June 2020.</p>
]]>
        </description>
    </item>
   </channel>
</rss>
