Playing with ImageTragick like it's 2016
https://ift.tt/3p3kF7o
Submitted May 31, 2021 at 07:26AM by Gallus
via reddit https://ift.tt/34wPact
https://ift.tt/3p3kF7o
Submitted May 31, 2021 at 07:26AM by Gallus
via reddit https://ift.tt/34wPact
Synacktiv
Playing with ImageTragick like it's 2016
You probably already have encountered document converting features that deal with ImageMagick during engagements but for some reason you were not able to exploit them. This article will mention some t
CVE-2021-21985 (another NSE quick checker)
https://ift.tt/2TuDp49
Submitted May 31, 2021 at 11:24AM by alt3kx
via reddit https://ift.tt/2TwbssI
https://ift.tt/2TuDp49
Submitted May 31, 2021 at 11:24AM by alt3kx
via reddit https://ift.tt/2TwbssI
GitHub
GitHub - alt3kx/CVE-2021-21985_PoC
Contribute to alt3kx/CVE-2021-21985_PoC development by creating an account on GitHub.
HardenedVault's whitepaper on building the digital bunker
https://ift.tt/3vBnAql
Submitted May 31, 2021 at 11:58AM by hardenedvault
via reddit https://ift.tt/3fPJfo0
https://ift.tt/3vBnAql
Submitted May 31, 2021 at 11:58AM by hardenedvault
via reddit https://ift.tt/3fPJfo0
Analysis report of the Facefish rootkit
https://ift.tt/2TmWuFn
Submitted May 31, 2021 at 12:41PM by c0r3dump3d
via reddit https://ift.tt/2S0JmoV
https://ift.tt/2TmWuFn
Submitted May 31, 2021 at 12:41PM by c0r3dump3d
via reddit https://ift.tt/2S0JmoV
360 Netlab Blog - Network Security Research Lab at 360
Analysis report of the Facefish rootkit
Background
In Feb 2021, we came across an ELF sample using some CWP’s Ndays exploits, we did some analysis, but after checking with a partner who has some nice visibility in network traffic in some China areas, we discovered there is literarily 0 hit for…
In Feb 2021, we came across an ELF sample using some CWP’s Ndays exploits, we did some analysis, but after checking with a partner who has some nice visibility in network traffic in some China areas, we discovered there is literarily 0 hit for…
.NET Managed Injector Library
https://ift.tt/2RXFIMD
Submitted May 31, 2021 at 04:26PM by aparata_s4tan
via reddit https://ift.tt/3wJoH7F
https://ift.tt/2RXFIMD
Submitted May 31, 2021 at 04:26PM by aparata_s4tan
via reddit https://ift.tt/3wJoH7F
GitHub
GitHub - enkomio/ManagedInjector: A C# DLL injection library
A C# DLL injection library. Contribute to enkomio/ManagedInjector development by creating an account on GitHub.
Overwolf 1-Click Remote Code Execution - CVE-2021-33501
https://ift.tt/3wL35Ia
Submitted May 31, 2021 at 09:04PM by Nhoty
via reddit https://ift.tt/3p5YyNG
https://ift.tt/3wL35Ia
Submitted May 31, 2021 at 09:04PM by Nhoty
via reddit https://ift.tt/3p5YyNG
Overwolf 1-Click Remote Code Execution - CVE-2021-33501 | SwordBytes Security
SwordBytes researchers have identified an Unauthenticated Remote Code Execution (RCE) vulnerability in Overwolf’s Client Application by abusing a Reflected Cross-Site Scripting (XSS) issue present in the “overwolfstore://” URL handler. This vulnerability…
AppCache's forgotten tales
https://ift.tt/34AUZFK
Submitted June 01, 2021 at 02:31AM by herrera_
via reddit https://ift.tt/3c44qlu
https://ift.tt/34AUZFK
Submitted June 01, 2021 at 02:31AM by herrera_
via reddit https://ift.tt/3c44qlu
blog.lbherrera.me
AppCache's forgotten tales
Leveraging AppCache's network section to leak the complete URL of cross-origin redirects.
Threat Hunting AMSI Bypasses
https://ift.tt/3fDpotF
Submitted June 01, 2021 at 02:43PM by netbiosX
via reddit https://ift.tt/34CicaA
https://ift.tt/3fDpotF
Submitted June 01, 2021 at 02:43PM by netbiosX
via reddit https://ift.tt/34CicaA
Pentest Laboratories
Threat Hunting AMSI Bypasses
The Antimalware Scan Interface (AMSI) was developed to provider an additional layer of security towards the execution of malicious noscripts on Windows environments. AMSI can be utilized by different…
Defeating Code Obfuscation with Angr
https://ift.tt/3i9mSN5
Submitted June 01, 2021 at 03:01PM by NapongiZero
via reddit https://ift.tt/2SJeM3d
https://ift.tt/3i9mSN5
Submitted June 01, 2021 at 03:01PM by NapongiZero
via reddit https://ift.tt/2SJeM3d
NapongiZero’s Blog
Defeating Code Obfuscation with Angr
A few weeks back I encountered an obfuscated piece of code. Reversing it seemed very tedious.
New AWS attack technique - Attackers can spoof their IP address on CloudTrail logs
https://ift.tt/3oKFSCW
Submitted May 30, 2021 at 08:32PM by Sayag_Security
via reddit https://ift.tt/2Tw6v38
https://ift.tt/3oKFSCW
Submitted May 30, 2021 at 08:32PM by Sayag_Security
via reddit https://ift.tt/2Tw6v38
www.hunters.security
Hunters Research: Detecting Obfuscated Attacker IPs in AWS
Hunters' research team discovers obfuscation technique using AWS VPC feature. Attackers could change the IP address written to AWS CloudTrail logs.
what do you think guys, is it OK to hook API call to get key or part of the key which is generated from a ransomware side.
https://ift.tt/3c92TKS
Submitted June 01, 2021 at 04:26PM by vah_13
via reddit https://ift.tt/3i51zwb
https://ift.tt/3c92TKS
Submitted June 01, 2021 at 04:26PM by vah_13
via reddit https://ift.tt/3i51zwb
French Quebec/Quebecker passwords list for your pentest!
https://ift.tt/3wRakxZ
Submitted June 01, 2021 at 08:13PM by pathetiq
via reddit https://ift.tt/3uE1emT
https://ift.tt/3wRakxZ
Submitted June 01, 2021 at 08:13PM by pathetiq
via reddit https://ift.tt/3uE1emT
Reddit
From the netsec community on Reddit: French Quebec/Quebecker passwords list for your pentest!
Posted by pathetiq - No votes and no comments
Configure AWS DNS Firewall to Control DNS Traffic in VPCs (Terraform and CloudFormation Templates)
https://ift.tt/3fZOim6
Submitted June 01, 2021 at 08:42PM by elitistAlmond
via reddit https://ift.tt/3fYqyP7
https://ift.tt/3fZOim6
Submitted June 01, 2021 at 08:42PM by elitistAlmond
via reddit https://ift.tt/3fYqyP7
asecure.cloud
Route53 Resolver Security: Route53 Resolver DNS Firewall Custom Template
CloudFormation, Terraform, and AWS CLI Templates: Configuration templates to deploy an AWS Route53 Resolver Firewall and related settings including firewall rule groups, custom domain lists, and VPC associations. This configuration can be used to block DNS…
Technical analysis of two RCE in Grav CMS 1.7.10 (CVE-2021-29439, CVE-2021-29440)
https://ift.tt/3i7WuDn
Submitted June 01, 2021 at 08:35PM by monoimpact
via reddit https://ift.tt/3g0YTgz
https://ift.tt/3i7WuDn
Submitted June 01, 2021 at 08:35PM by monoimpact
via reddit https://ift.tt/3g0YTgz
Sonarsource
SonarSource Blog
SonarSource builds world-class Code Quality & Code Security tools. Our products, SonarLint, SonarQube, and SonarCloud are trusted by 200k+ organizations globally.
Akamai EAA Impersonation Vulnerability - A Deep Dive
https://ift.tt/3vJVCsO
Submitted June 02, 2021 at 06:07AM by more_muscle_aim
via reddit https://ift.tt/3c7Th36
https://ift.tt/3vJVCsO
Submitted June 02, 2021 at 06:07AM by more_muscle_aim
via reddit https://ift.tt/3c7Th36
Akamai
Akamai Blog | Akamai EAA Impersonation Vulnerability - A Deep Dive
In this post, we cover the technical details of CVE-2021-28091, the vulnerability impacting Akamai's Enterprise Application Access (EAA) platform.
New CVE database that visualizes CVEs and shows exploit price and eco impact
https://ift.tt/3yVEOkA
Submitted June 02, 2021 at 01:53PM by vowie92
via reddit https://ift.tt/3fFcbjV
https://ift.tt/3yVEOkA
Submitted June 02, 2021 at 01:53PM by vowie92
via reddit https://ift.tt/3fFcbjV
Vault1317 protocol: a modern approach for metadata protection with deniability
https://ift.tt/3i8qsaj
Submitted June 02, 2021 at 03:10PM by hardenedvault
via reddit https://ift.tt/3yYlZgk
https://ift.tt/3i8qsaj
Submitted June 02, 2021 at 03:10PM by hardenedvault
via reddit https://ift.tt/3yYlZgk
reddit
Vault1317 protocol: a modern approach for metadata protection with...
Posted in r/netsec by u/hardenedvault • 11 points and 1 comment
Revisiting Realtek – A New Set of Critical Wi-Fi Vulnerabilities Discovered by Automated Zero-Day Analysis
https://ift.tt/3uHHwGT
Submitted June 02, 2021 at 06:02PM by SRMish3
via reddit https://ift.tt/3g06ZGo
https://ift.tt/3uHHwGT
Submitted June 02, 2021 at 06:02PM by SRMish3
via reddit https://ift.tt/3g06ZGo
VDOO
Realtek Critical Wi-Fi Vulnerabilities Discovered
A comprehensive analysis revealing two new critical vulnerabilities discovered in a popular Realtek Wi Fi module by Vdoo’s automated product security platform, including a demonstration of the exploitation.
WE.LOCK: Unlocking Smart Locks with Web Vulnerabilities
https://ift.tt/3g1CCz7
Submitted June 02, 2021 at 07:39PM by CriticalSec
via reddit https://ift.tt/2RXEXTY
https://ift.tt/3g1CCz7
Submitted June 02, 2021 at 07:39PM by CriticalSec
via reddit https://ift.tt/2RXEXTY
GitHub
CriticalSecurity/welock
Contribute to CriticalSecurity/welock development by creating an account on GitHub.
Guide to P-code Injection: Changing the intermediate representation of code on the fly in Ghidra
https://ift.tt/2S3m8i4
Submitted June 02, 2021 at 08:22PM by yarbabin
via reddit https://ift.tt/3ipa8Cv
https://ift.tt/2S3m8i4
Submitted June 02, 2021 at 08:22PM by yarbabin
via reddit https://ift.tt/3ipa8Cv
PT SWARM
Guide to P-code Injection: Changing the intermediate representation of code on the fly in Ghidra
When we were developing the ghidra nodejs module for Ghidra, we realized that it was not always possible to correctly implement V8 (JavaScript engine that is used by Node.js) opcodes in SLEIGH. In such runtime environments as V8 and JVM, a single opcode might…
Exploiting a zero-day WebAssembly Vulnerability (CVE-2021-30734) in Apple Safari
https://ift.tt/2SNnL3q
Submitted June 02, 2021 at 08:44PM by gaasedelen
via reddit https://ift.tt/3fJy8y9
https://ift.tt/2SNnL3q
Submitted June 02, 2021 at 08:44PM by gaasedelen
via reddit https://ift.tt/3fJy8y9
RET2 Systems Blog
32 bits, 32 gigs, 1 click...
In this post we will examine a vulnerability in the WebAssembly subsystem of JavaScriptCore, the JavaScript engine used in WebKit and Apple Safari. The issue...