Detecting Cowrie in “proxy” Mode.
https://ift.tt/3wolBp9
Submitted July 07, 2021 at 01:41PM by katyushas_lab
via reddit https://ift.tt/3qRg74V
https://ift.tt/3wolBp9
Submitted July 07, 2021 at 01:41PM by katyushas_lab
via reddit https://ift.tt/3qRg74V
Darren Martyn
Detecting Cowrie in “proxy” Mode
So in “proxy” mode, Cowrie is pretty damn powerful. It proxies you through to a backend pool of live systems or virtual machines. It is god damn awesome. My previous detection methods b…
CVE-2021-20595: Unauthenticated XXE in Multiple Mitsubishi Electric Air Conditioner Control Systems | Aon
https://ift.tt/3xpypN5
Submitted July 07, 2021 at 06:31PM by b1x3r
via reddit https://ift.tt/3ho1D9E
https://ift.tt/3xpypN5
Submitted July 07, 2021 at 06:31PM by b1x3r
via reddit https://ift.tt/3ho1D9E
Aon
CVE-2021-20595: Unauthenticated XXE in Multiple Mitsubishi Electric Air Conditioner Control Systems | Aon
Aon’s Cyber Solutions discovered a security vulnerability affecting over 20 Mitsubishi Electric Air Conditioner Control Systems leading to information disclosure and/or denial of service via unauthenticated XML External Entity Injection (XXE). For a complete…
Leveraging Burp Suite extension for finding HTTP Request Smuggling.
https://ift.tt/2SPIkMY
Submitted July 07, 2021 at 08:22PM by myshit11
via reddit https://ift.tt/2TKLL83
https://ift.tt/2SPIkMY
Submitted July 07, 2021 at 08:22PM by myshit11
via reddit https://ift.tt/2TKLL83
Medium
Leveraging Burp Suite extension for finding HTTP Request Smuggling.
HTTP Request Smuggling is often left behind in bug bounty findings. But with the right extension, you can automate the task of finding HTTP…
LibAFL: Rust Library to Develop Customized Fuzzers
https://ift.tt/3hLzsQW
Submitted July 07, 2021 at 08:51PM by domenukk
via reddit https://ift.tt/3ALZ2hF
https://ift.tt/3hLzsQW
Submitted July 07, 2021 at 08:51PM by domenukk
via reddit https://ift.tt/3ALZ2hF
GitHub
GitHub - AFLplusplus/LibAFL: Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For…
Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ... - GitHub - AFLplusplus/LibAFL: Advanced Fuzzing Libra...
Old dog, same tricks. Remote Command Injection as-a-service
https://ift.tt/3dT7b9W
Submitted July 08, 2021 at 01:49AM by pocorgtfoftw
via reddit https://ift.tt/2UsDiGH
https://ift.tt/3dT7b9W
Submitted July 08, 2021 at 01:49AM by pocorgtfoftw
via reddit https://ift.tt/2UsDiGH
Script to help mitigate the PrintNightmare CVE-2021-34527 exploit
https://ift.tt/3dRo8l2
Submitted July 08, 2021 at 04:39AM by jokezone
via reddit https://ift.tt/3jTWasY
https://ift.tt/3dRo8l2
Submitted July 08, 2021 at 04:39AM by jokezone
via reddit https://ift.tt/3jTWasY
GitHub
PowerShell-Scripts/Configure-PrintSpooler.ps1 at main · jokezone/PowerShell-Scripts
Random PowerShell noscripts worth sharing. Contribute to jokezone/PowerShell-Scripts development by creating an account on GitHub.
ASProtect embedded runtime DLL memory corruption aka Windows Defender RCE
https://ift.tt/3jVBKQe
Submitted July 08, 2021 at 10:04AM by 0xdea
via reddit https://ift.tt/3AIfD5Y
https://ift.tt/3jVBKQe
Submitted July 08, 2021 at 10:04AM by 0xdea
via reddit https://ift.tt/3AIfD5Y
Reddit
From the netsec community on Reddit: ASProtect embedded runtime DLL memory corruption aka Windows Defender RCE
Posted by 0xdea - 33 votes and 4 comments
Security Scorecards - Security health metrics for Open Source
https://ift.tt/32tFWwX
Submitted July 08, 2021 at 11:44AM by mycall
via reddit https://ift.tt/3yxR9dx
https://ift.tt/32tFWwX
Submitted July 08, 2021 at 11:44AM by mycall
via reddit https://ift.tt/3yxR9dx
GitHub
GitHub - ossf/scorecard: Security Scorecards - Security health metrics for Open Source
Security Scorecards - Security health metrics for Open Source - GitHub - ossf/scorecard: Security Scorecards - Security health metrics for Open Source
hacker5.org is a blog providing bite-size information about five recent things happened in netsec that update not so frequently as compared with other security news site. Data are mostly collected from here (r/netsec) and ycombinator hackernews.
https://hacker5.org/
Submitted July 08, 2021 at 12:36PM by MilonMaze
via reddit https://ift.tt/3dPDRBl
https://hacker5.org/
Submitted July 08, 2021 at 12:36PM by MilonMaze
via reddit https://ift.tt/3dPDRBl
reddit
hacker5.org is a blog providing bite-size information about five...
Posted in r/netsec by u/MilonMaze • 0 points and 0 comments
A series of free interactive AWS security training modules that teach developers how to identify and mitigate security vulnerabilities in their AWS hosted cloud applications.
https://ift.tt/2SW8j5r
Submitted July 08, 2021 at 08:03PM by Cool-Return
via reddit https://ift.tt/3hrW3Dn
https://ift.tt/2SW8j5r
Submitted July 08, 2021 at 08:03PM by Cool-Return
via reddit https://ift.tt/3hrW3Dn
Kontra
Application Security Training For Developers | Kontra
Kontra is an Application Security Training platform built for modern development teams.
Global Phishing Campaign Targets Energy Sector and its Suppliers
https://ift.tt/36plE9s
Submitted July 08, 2021 at 08:03PM by Milafasents
via reddit https://ift.tt/3yyidta
https://ift.tt/36plE9s
Submitted July 08, 2021 at 08:03PM by Milafasents
via reddit https://ift.tt/3yyidta
Intezer
Global Phishing Campaign Targets Energy Sector and its Suppliers
Attack also targets oil & gas suppliers likely as a stepping-stone to infect companies that work with the suppliers.
Conti Unpacked | Understanding Ransomware Development As a Response to Detection
https://ift.tt/3jYsR8o
Submitted July 08, 2021 at 09:32PM by Cyberthere
via reddit https://ift.tt/3qVVJzK
https://ift.tt/3jYsR8o
Submitted July 08, 2021 at 09:32PM by Cyberthere
via reddit https://ift.tt/3qVVJzK
SentinelOne
Conti Unpacked | Understanding Ransomware Development As a Response to Detection - SentinelLabs
Conti's rapid encryption speed is matched only by its rapid evolution. SentinelLabs' deep dive explores its development in unprecedented detail.
NIST CSF Framework Benchmark (85 open source controls for AWS)
https://ift.tt/3wv6Mku
Submitted July 09, 2021 at 12:51AM by CloudSpout
via reddit https://ift.tt/3k1rlT4
https://ift.tt/3wv6Mku
Submitted July 09, 2021 at 12:51AM by CloudSpout
via reddit https://ift.tt/3k1rlT4
Steampipe Hub
AWS Compliance Mod for Steampipe
Run individual configuration, compliance and security controls or full compliance benchmarks for CIS, PCI, NIST, HIPAA, RBI CSF, and AWS Foundational Security Best Practices controls across all your AWS accounts using Steampipe.
Sneaky malware reconfigures Hive OS wallet so attacker gets mined coins
https://ift.tt/3dYcTY8
Submitted July 09, 2021 at 02:07AM by securehoney
via reddit https://ift.tt/2T1svTE
https://ift.tt/3dYcTY8
Submitted July 09, 2021 at 02:07AM by securehoney
via reddit https://ift.tt/2T1svTE
Secure Honey
Sneaky Malware Reconfigures Hive OS Wallet for Profit | Secure Honey
I recently observed some malware (uploaded to my honeypot) that targets Hive OS's wallet configuration -- to redirect mined coins to the attacker.
Previous WhyNotWin11 Releases Vulnerable to DLL Hijacking, Priviledge Escalatoin
https://ift.tt/3wsECXm
Submitted July 09, 2021 at 12:10PM by rcmaehl
via reddit https://ift.tt/3ATsi6b
https://ift.tt/3wsECXm
Submitted July 09, 2021 at 12:10PM by rcmaehl
via reddit https://ift.tt/3ATsi6b
GitHub
Vulnerability Disclosure 07 09 2021
Detection Script to help identify why your PC isn't Windows 11 Release Ready - rcmaehl/WhyNotWin11
Previous WhyNotWin11 Releases Vulnerable to DLL Hijacking, Privilege Escalation
https://ift.tt/3wsECXm
Submitted July 09, 2021 at 12:13PM by rcmaehl
via reddit https://ift.tt/3AKwrsP
https://ift.tt/3wsECXm
Submitted July 09, 2021 at 12:13PM by rcmaehl
via reddit https://ift.tt/3AKwrsP
GitHub
Vulnerability Disclosure 07 09 2021
Detection Script to help identify why your PC isn't Windows 11 Release Ready - rcmaehl/WhyNotWin11
UDP Technology IP Camera vulnerabilities - unauthenticated RCE Root.
https://ift.tt/2TJIiXH
Submitted July 09, 2021 at 02:35PM by M0t0k0Kus4n4g1
via reddit https://ift.tt/3jWfxSd
https://ift.tt/2TJIiXH
Submitted July 09, 2021 at 02:35PM by M0t0k0Kus4n4g1
via reddit https://ift.tt/3jWfxSd
Hacking Rendertron and Puppeteer, what to expect if you put a browser on the internet. - even recent version of Rendertron runs outdated browser with no-sandbox by default; you have to keep it safe
https://ift.tt/3ejAu63
Submitted July 09, 2021 at 05:48PM by 4lreadytekken
via reddit https://ift.tt/3yH2XKw
https://ift.tt/3ejAu63
Submitted July 09, 2021 at 05:48PM by 4lreadytekken
via reddit https://ift.tt/3yH2XKw
Medium
Hacking Rendertron and Puppeteer— What to expect if you put a browser on the internet
tldr: do not expose Rendertron! If you run headless browsers for things other than testing, design the infra expecting they will get owned.
"Surveilling the Gamers": New research paper illustrates how video games can be exploited for illegitimate surveillance and user profiling
https://ift.tt/3hVJHSG
Submitted July 09, 2021 at 05:44PM by bayashad
via reddit https://ift.tt/3hN8tEG
https://ift.tt/3hVJHSG
Submitted July 09, 2021 at 05:44PM by bayashad
via reddit https://ift.tt/3hN8tEG
Ssrn
Surveilling the Gamers: Privacy Impacts of the Video Game Industry by Jacob Leon Kröger, Philip Raschke, Jessica Percy Campbell…
With many million users across all age groups and income levels, video games have become the world’s leading entertainment industry. Behind the fun experience t
Analysing an O.MG cable
https://ift.tt/3dXy78r
Submitted July 09, 2021 at 06:52PM by kev-thehermit
via reddit https://ift.tt/2UCGgbS
https://ift.tt/3dXy78r
Submitted July 09, 2021 at 06:52PM by kev-thehermit
via reddit https://ift.tt/2UCGgbS
TechAnarchy
Analysing an O.MG cable
Setting up an O.MG cable for keystroke injection attacks, and then forensically dumping the firmware for analysis.
I wrote a local browser tool to query Nessus reports via SQL for easy analysis and reporting.
https://ift.tt/3htVfxC
Submitted July 10, 2021 at 06:38PM by The_Login
via reddit https://ift.tt/3xwhGYH
https://ift.tt/3htVfxC
Submitted July 10, 2021 at 06:38PM by The_Login
via reddit https://ift.tt/3xwhGYH
GitHub
GitHub - The-Login/nessSQL: Query nessus reports via SQL!
Query nessus reports via SQL! Contribute to The-Login/nessSQL development by creating an account on GitHub.