SSRF in ColdFusion/CFML Tags and Functions
https://ift.tt/3A84Pxl
Submitted June 28, 2021 at 06:23PM by albinowax
via reddit https://ift.tt/2U27LLz
https://ift.tt/3A84Pxl
Submitted June 28, 2021 at 06:23PM by albinowax
via reddit https://ift.tt/2U27LLz
Blogspot
SSRF in ColdFusion/CFML Tags and Functions
TL;DR: Several ColdFusion/CFML tags and functions can process URLs as file path arguments -- including some tags and and functions that you...
Open source Salesforce object access auditor - which Profiles and Permissions Sets (with active users) have some combination of read/edit/delete permissions to ALL records for a given set of objects, based on their effective sharing and objects settings.
https://ift.tt/2SBWFwy
Submitted June 29, 2021 at 12:29AM by digicat
via reddit https://ift.tt/3dmUCne
https://ift.tt/2SBWFwy
Submitted June 29, 2021 at 12:29AM by digicat
via reddit https://ift.tt/3dmUCne
GitHub
GitHub - nccgroup/raccoon: Salesforce object access auditor
Salesforce object access auditor. Contribute to nccgroup/raccoon development by creating an account on GitHub.
Netsec eBooks Bundle by Packt
https://ift.tt/3h2b1Qg
Submitted June 29, 2021 at 12:26AM by reps_up
via reddit https://ift.tt/3x3CQ05
https://ift.tt/3h2b1Qg
Submitted June 29, 2021 at 12:26AM by reps_up
via reddit https://ift.tt/3x3CQ05
Medium
Make yourself digitally invulnerable with the Cybersecurity 2021 eBooks Bundle from Packt
Humble Book Bundle: Cybersecurity 2021 from Packt
Google Compute Engine (GCE) VM "remote" root exploit via DHCP flood
https://ift.tt/3y2ZFkx
Submitted June 29, 2021 at 01:40AM by xdavidhu
via reddit https://ift.tt/3joXWll
https://ift.tt/3y2ZFkx
Submitted June 29, 2021 at 01:40AM by xdavidhu
via reddit https://ift.tt/3joXWll
GitHub
GitHub - irsl/gcp-dhcp-takeover-code-exec: Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting…
Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting SSH keys added by google_guest_agent - irsl/gcp-dhcp-takeover-code-exec
Open source client for free Windscribe proxies
https://ift.tt/2TiyiEr
Submitted June 29, 2021 at 03:26AM by yarmak
via reddit https://ift.tt/3dpP9vP
https://ift.tt/2TiyiEr
Submitted June 29, 2021 at 03:26AM by yarmak
via reddit https://ift.tt/3dpP9vP
GitHub
GitHub - Snawoot/windscribe-proxy: Standalone client for proxies of Windscribe browser extension
Standalone client for proxies of Windscribe browser extension - Snawoot/windscribe-proxy
Databunker - an open-source secure vault
https://ift.tt/3sRsVsf
Submitted June 29, 2021 at 04:07AM by yulistr
via reddit https://ift.tt/3y2Bhzr
https://ift.tt/3sRsVsf
Submitted June 29, 2021 at 04:07AM by yulistr
via reddit https://ift.tt/3y2Bhzr
GitHub
GitHub - securitybunker/databunker: Secure Vault for Customer PII/PHI/PCI/KYC Records
Secure Vault for Customer PII/PHI/PCI/KYC Records. Contribute to securitybunker/databunker development by creating an account on GitHub.
ukncsc/Device-Security-Guidance-Configuration-Packs: This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance.
https://ift.tt/2Tk9Dzl
Submitted June 29, 2021 at 03:31PM by joelgsamuel
via reddit https://ift.tt/3heRYkp
https://ift.tt/2Tk9Dzl
Submitted June 29, 2021 at 03:31PM by joelgsamuel
via reddit https://ift.tt/3heRYkp
GitHub
GitHub - ukncsc/Device-Security-Guidance-Configuration-Packs: This repository contains policy packs which can be used by system…
This repository contains policy packs which can be used by system management software to configure device platforms (such as Windows 10 and iOS) in accordance with NCSC device security guidance. Th...
Pre-auth RCE in ForgeRock OpenAM (CVE-2021-35464)
https://ift.tt/3jp5x3v
Submitted June 29, 2021 at 05:10PM by artsploit
via reddit https://ift.tt/35Zy8EB
https://ift.tt/3jp5x3v
Submitted June 29, 2021 at 05:10PM by artsploit
via reddit https://ift.tt/35Zy8EB
Beating layer 7 DDoS attacks for free, using CrowdSec+Cloudflare
https://ift.tt/3qwXrHA
Submitted June 29, 2021 at 07:25PM by philippe_crowdsec
via reddit https://ift.tt/3vYGDKM
https://ift.tt/3qwXrHA
Submitted June 29, 2021 at 07:25PM by philippe_crowdsec
via reddit https://ift.tt/3vYGDKM
The open-source & multiplayer security solution
How to beat application DDoS attacks with CrowdSec & Cloudflare
A simple guide explaining how to beat applicative-layer DDoS attacks using CrowdSec and Cloudflare.
LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries
https://ift.tt/364mOHa
Submitted June 29, 2021 at 07:22PM by magenta_placenta
via reddit https://ift.tt/3qwDSzg
https://ift.tt/364mOHa
Submitted June 29, 2021 at 07:22PM by magenta_placenta
via reddit https://ift.tt/3qwDSzg
9to5Mac
LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries
A second massive LinkedIn breach reportedly exposes the data of 700M users, which is more than 92% of the total 756M users. The database ...
PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service
https://ift.tt/3jqM42g
Submitted June 29, 2021 at 11:13PM by 0xdea
via reddit https://ift.tt/2UaosVl
https://ift.tt/3jqM42g
Submitted June 29, 2021 at 11:13PM by 0xdea
via reddit https://ift.tt/2UaosVl
Binary code-coverage Fuzzer for macOS (supports Intel & M1) by @ant4g0nist
https://ift.tt/2UaowEz
Submitted June 29, 2021 at 11:09PM by ant4g0nist
via reddit https://ift.tt/3w6W8jE
https://ift.tt/2UaowEz
Submitted June 29, 2021 at 11:09PM by ant4g0nist
via reddit https://ift.tt/3w6W8jE
GitHub
GitHub - ant4g0nist/ManuFuzzer: Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM
Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM - GitHub - ant4g0nist/ManuFuzzer: Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM
Detecting SSH Honeypots with non-persistent filesystems.
https://ift.tt/3hjQ95R
Submitted June 30, 2021 at 04:06AM by katyushas_lab
via reddit https://ift.tt/3AbFrXJ
https://ift.tt/3hjQ95R
Submitted June 30, 2021 at 04:06AM by katyushas_lab
via reddit https://ift.tt/3AbFrXJ
Darren Martyn
Detecting SSH Honeypots with non-persistent filesystems.
A lot has been written on the topic of detecting SSH honeypots in the past, usually using their canned responses against them, SSH protocol quirks, them accepting every password, etc. While experim…
Oramfs: Resizable ORAM, Remote Storage Agnostic, Written in Rust
https://ift.tt/2Tp7KkK
Submitted June 30, 2021 at 05:26PM by tmlxs
via reddit https://ift.tt/3h3fimi
https://ift.tt/2Tp7KkK
Submitted June 30, 2021 at 05:26PM by tmlxs
via reddit https://ift.tt/3h3fimi
Kudelski Security Research
Oramfs: Resizable ORAM, Remote Storage Agnostic, Written in Rust
Today we are excited to release oramfs, a simple, flexible, Free Software ORAM implementation for Linux written in Rust. It is designed to support different ORAM schemes and encryption ciphers. It …
Detecting the new crypto mining attack targeting Kubeflow and TensorFlow - How the attack works + Steps to mitigate + Detect using Falco rules or Prometheus metrics
https://ift.tt/3x6Uznr
Submitted June 30, 2021 at 05:58PM by capitangolo
via reddit https://ift.tt/3hre7fI
https://ift.tt/3x6Uznr
Submitted June 30, 2021 at 05:58PM by capitangolo
via reddit https://ift.tt/3hre7fI
Sysdig
Detecting New Crypto-Mining Attack targeting Kubeflow and TensorFlow
A new large-scale attack targets Kubeflow and TensorFlow to mine Monero cryptocurrency in Kubernetes cluster environments.
Pwning Cisco ISE: from XSS to a root shell (w/ exploit video)
https://ift.tt/2UU1jH1
Submitted June 30, 2021 at 02:00PM by ChoiceGrapefruit0
via reddit https://ift.tt/3dpUuDm
https://ift.tt/2UU1jH1
Submitted June 30, 2021 at 02:00PM by ChoiceGrapefruit0
via reddit https://ift.tt/3dpUuDm
GitHub
PoC/cisco_ise_rce.md at master · pedrib/PoC
Advisories, proof of concept files and exploits that have been made public by @pedrib. - PoC/cisco_ise_rce.md at master · pedrib/PoC
PrintNightmare (CVE-2021-1675) PoC Exploit Code Released
https://ift.tt/3AeseNS
Submitted June 30, 2021 at 07:39PM by ericaedits
via reddit https://ift.tt/3xdM8Xy
https://ift.tt/3AeseNS
Submitted June 30, 2021 at 07:39PM by ericaedits
via reddit https://ift.tt/3xdM8Xy
Blumira
PrintNightmare (CVE-2021-1675 and CVE 2021-34527) Explained
Proof-of-concept exploit code was published on Github on June 29, 2021 for a vulnerability (CVE-2021-1675) in Print Spooler.
Operation Eagle Eye - RCE to Enterprise Man-In-The-Middle
https://ift.tt/3dxuJRM
Submitted June 30, 2021 at 11:03PM by barbarisch
via reddit https://ift.tt/3hpJDua
https://ift.tt/3dxuJRM
Submitted June 30, 2021 at 11:03PM by barbarisch
via reddit https://ift.tt/3hpJDua
Securifera
Operation Eagle Eye
This article is in no way affiliated, sponsored, or endorsed with/by Fidelis Cybersecurity. All graphics are being displayed under fair use for the purposes of this article.
Operation Eagle Eye
Who remembers that movie about 15 years ago called Eagle…
Operation Eagle Eye
Who remembers that movie about 15 years ago called Eagle…
New NETGEAR firmware vulnerabilities that could lead to identity theft and full system compromise
https://ift.tt/3AcsnkN
Submitted July 01, 2021 at 10:43AM by 0xdea
via reddit https://ift.tt/3qH1nps
https://ift.tt/3AcsnkN
Submitted July 01, 2021 at 10:43AM by 0xdea
via reddit https://ift.tt/3qH1nps
reddit
New NETGEAR firmware vulnerabilities that could lead to identity...
Posted in r/netsec by u/0xdea • 332 points and 49 comments
Hacking the dlink DIR-615 for fun and no profit
https://ift.tt/3x8X7S0
Submitted July 01, 2021 at 02:27PM by Noobexploiter
via reddit https://ift.tt/2UXhTFZ
https://ift.tt/3x8X7S0
Submitted July 01, 2021 at 02:27PM by Noobexploiter
via reddit https://ift.tt/2UXhTFZ
Medium
Hacking the dlink DIR-615 for fun and no profit
Hello . In this writeup, i will show you how i found a potential remote code execution (CVE-2019–13561) in the dlink dir-615 firmware.
Building trust without trust.
https://ift.tt/3AfPCul
Submitted July 01, 2021 at 06:12PM by MSP-Kontinuum
via reddit https://ift.tt/3dy8KKa
https://ift.tt/3AfPCul
Submitted July 01, 2021 at 06:12PM by MSP-Kontinuum
via reddit https://ift.tt/3dy8KKa
Buzzsprout
Episode 18 - Building trust without trust. - Cybersecurity: Amplified And Intensified
On this episode we begin to talk about the difference between zero trust and zero knowledge, ransomware groups going dark for the moment and recent tactics and techniques.Eric Taylor | LinkedInTwitter: barricadecyberwww.barricadecyber.comShiva Maharaj | …