Using GitLab to monitor and hijack domains in mass quantity.
https://hackerone.com/reports/312118
🕴 @Phantasm_Lab
https://hackerone.com/reports/312118
🕴 @Phantasm_Lab
HackerOne
GitLab disclosed on HackerOne: Using GitLab to monitor and hijack...
# Vulnerability Denoscription
There is a logic flaw in how GitLab pages can set custom domains that allows an attacker to actively monitor domains and hijack them as soon as they point to...
There is a logic flaw in how GitLab pages can set custom domains that allows an attacker to actively monitor domains and hijack them as soon as they point to...
Assuntos relacionados a open hardware, robotica e estudos sobre TI em geral.https://news.1rj.ru/str/Undeth
🕴 @Phantasm_Lab
Telegram
Undeth - TI
Canal focado em Tools e Skills destinados a tecnológia da informação e suas derivações...
- LPI
- Robótica
- Automação
- Open Hardware
- Coders
- Makers
- Hacktivismo
- Segurança da Informação
Parceiros:
https://news.1rj.ru/str/TeresinaHC
@phantomgroup
- LPI
- Robótica
- Automação
- Open Hardware
- Coders
- Makers
- Hacktivismo
- Segurança da Informação
Parceiros:
https://news.1rj.ru/str/TeresinaHC
@phantomgroup
Forwarded from Undeth - TI (Dan)
#CSS #Keylogger #DOM
CSS Keylogger - old is new again
https://www.youtube.com/watch?v=oJ6t7AImTdE
🕴 https://github.com/maxchehab/CSS-Keylogging
🕴 @Phantasm_Lab
CSS Keylogger - old is new again
This is "well known" research that resurfaces every other year. Let me tell you a story how I have heard about this in 2012 and putting it into perspective.https://www.youtube.com/watch?v=oJ6t7AImTdE
🕴 https://github.com/maxchehab/CSS-Keylogging
🕴 @Phantasm_Lab
YouTube
CSS Keylogger - old is new again
This is "well known" research that resurfaces every other year. Let me tell you a story how I have heard about this in 2012 and putting it into perspective.
Research "Scriptless Attacks –
Stealing the Pie Without Touching the Sill" (2012):
+ Paper: htt…
Research "Scriptless Attacks –
Stealing the Pie Without Touching the Sill" (2012):
+ Paper: htt…
#SSH #Logs #Honeypot
Fake sshd that logs ip addresses, usernames, and passwords.
https://github.com/x0rz/ssh-honeypot
🕴 @Phantasm_Lab
Fake sshd that logs ip addresses, usernames, and passwords.
This program listens for incoming ssh connections and logs the ip address, username, and password used. This was written to gather rudimentary intelligence on brute force attacks.https://github.com/x0rz/ssh-honeypot
🕴 @Phantasm_Lab
GitHub
GitHub - x0rz/ssh-honeypot: Fake sshd that logs ip addresses, usernames, and passwords.
Fake sshd that logs ip addresses, usernames, and passwords. - GitHub - x0rz/ssh-honeypot: Fake sshd that logs ip addresses, usernames, and passwords.
#mitm #exploitation Bettercap É um canivete suíço para ataques de rede e monitoramento... https://www.bettercap.org/
#mitm #exploitation Xerosploit é um kit de ferramentas de teste de penetração e ataque main the midle... https://github.com/LionSec/xerosploit