<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://wingertries.net/</id><title>wingerBijay</title><subtitle>Cybersecurity research, CTF writeups, pentesting notes and security experiments.</subtitle> <updated>2026-06-18T20:04:32+10:00</updated> <author> <name>Bijay Upreti</name> <uri>https://wingertries.net/</uri> </author><link rel="self" type="application/atom+xml" href="https://wingertries.net/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://wingertries.net/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Bijay Upreti </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>CVE-2021-27876/77/78 — Veritas Backup Exec: Dissecting an Unauthenticated RCE Chain</title><link href="https://wingertries.net/posts/veritas-backup-exec-rce-cve-2021-27876/" rel="alternate" type="text/html" title="CVE-2021-27876/77/78 — Veritas Backup Exec: Dissecting an Unauthenticated RCE Chain" /><published>2026-06-18T09:00:00+10:00</published> <updated>2026-06-18T19:59:00+10:00</updated> <id>https://wingertries.net/posts/veritas-backup-exec-rce-cve-2021-27876/</id> <content type="text/html" src="https://wingertries.net/posts/veritas-backup-exec-rce-cve-2021-27876/" /> <author> <name>Bijay Upreti</name> </author> <category term="Research" /> <category term="CVE" /> <summary>During a recent engagement I ran into a Veritas Backup Exec Agent sitting on TCP/10000 with no authentication enforced. Three CVEs, one custom exploit script, and a SYSTEM shell — all without touching a single credential. This post breaks down why the vulnerability exists, how the chain works at the protocol level, and why I wrote a custom exploit rather than reaching for Metasploit. This w...</summary> </entry> </feed>
