Practical MFA Bypass Techniques
https://ift.tt/36tmP7W
Submitted July 13, 2021 at 12:50AM by InfoSecGuy2K14
via reddit https://ift.tt/3hB1b86
https://ift.tt/36tmP7W
Submitted July 13, 2021 at 12:50AM by InfoSecGuy2K14
via reddit https://ift.tt/3hB1b86
Medium
You ain’t got no problem, Jules. I’m on the Multifactor.
Practical Bypasses for MFA with Poor Implementations
Enumerate reverse ports open to reverse shell
https://ift.tt/3kd1NT2
Submitted July 12, 2021 at 08:59PM by piosec
via reddit https://ift.tt/3kaCBwD
https://ift.tt/3kd1NT2
Submitted July 12, 2021 at 08:59PM by piosec
via reddit https://ift.tt/3kaCBwD
GitHub
GitHub - Piosec/Golconda
Contribute to Piosec/Golconda development by creating an account on GitHub.
Examining Crypto and Bypassing Authentication in Schneider Electric PLCs (M340/M580)
https://ift.tt/3yKbQ6e
Submitted July 13, 2021 at 08:16PM by stargravy
via reddit https://ift.tt/3kexeg2
https://ift.tt/3yKbQ6e
Submitted July 13, 2021 at 08:16PM by stargravy
via reddit https://ift.tt/3kexeg2
Medium
Examining Crypto and Bypassing Authentication in Schneider Electric PLCs (M340/M580)
It looks like authentication, but is it really?
ETM v1.0 - How BLS approaches Threat Matrices and how we're improving their effectiveness within the community
https://ift.tt/3eest1T
Submitted July 13, 2021 at 09:22PM by debifrank
via reddit https://ift.tt/2UKSeQN
https://ift.tt/3eest1T
Submitted July 13, 2021 at 09:22PM by debifrank
via reddit https://ift.tt/2UKSeQN
Black Lantern Security
Threat Matrices
How BLS approaches Threat Matrices and how we’re improving their effectiveness within the community
A Golang firewall tool to whitelist ASN IP ranges based on organization name.
https://ift.tt/3xwzToW
Submitted July 13, 2021 at 09:12PM by ok_bye_now_
via reddit https://ift.tt/3k8Y4WK
https://ift.tt/3xwzToW
Submitted July 13, 2021 at 09:12PM by ok_bye_now_
via reddit https://ift.tt/3k8Y4WK
GitHub
GitHub - jordanpotti/goAllowOrgs: A Golang tool to whitelist ASN's based on organization name
A Golang tool to whitelist ASN's based on organization name - GitHub - jordanpotti/goAllowOrgs: A Golang tool to whitelist ASN's based on organization name
Hackers Teaching Hackers conference will be in-person at BrewDog Brewery on November 2-5 this year. Also added Zeek and Burp Suit Pro pre-con training.
https://ift.tt/3AZTWy3
Submitted July 13, 2021 at 09:52PM by technoglowstick
via reddit https://ift.tt/3i4HNQ3
https://ift.tt/3AZTWy3
Submitted July 13, 2021 at 09:52PM by technoglowstick
via reddit https://ift.tt/3i4HNQ3
Hackers Teaching Hackers
Pre-Con Training Courses — Hackers Teaching Hackers
Join us two days before the conference for some pre-con training. Thats right! We are offering two in-person training courses this year; offensive and defensive.
SharpImpersonation release
https://ift.tt/3hCcCws
Submitted July 13, 2021 at 09:37PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3r73McZ
https://ift.tt/3hCcCws
Submitted July 13, 2021 at 09:37PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3r73McZ
s3cur3th1ssh1t.github.io
SharpImpersonation Release | S3cur3Th1sSh1t
This blog is an introduction for my newly released post exploitation / privilege escalation tool SharpImpersonation. The code base makes heavy use of Tokenva...
Hi! I would love to get feedback's: BRUTE-SHARK is a tool I have developed it can extract Kerberos & NTLM tickets from PCAP files, dynamically build a build a visual network diagram, it also extract credentials, hashes, files and more on real time. p.s. contributors are welcome :-)
https://ift.tt/2SDTYXZ
Submitted July 14, 2021 at 02:00AM by BruteShark
via reddit https://ift.tt/3eaAF3p
https://ift.tt/2SDTYXZ
Submitted July 14, 2021 at 02:00AM by BruteShark
via reddit https://ift.tt/3eaAF3p
GitHub
GitHub - odedshimon/BruteShark: Network Analysis Tool
Network Analysis Tool. Contribute to odedshimon/BruteShark development by creating an account on GitHub.
Nessus: Powershell Script to Troubleshoot Credentialed Windows Scans
https://ift.tt/3r7yKBI
Submitted July 14, 2021 at 01:58AM by tecnobabble
via reddit https://ift.tt/3AZGoTy
https://ift.tt/3r7yKBI
Submitted July 14, 2021 at 01:58AM by tecnobabble
via reddit https://ift.tt/3AZGoTy
nessus_win_cred_test
Nessus Credentialed Assessment Readiness Check (Windows)
This Powershell noscript is designed to be run on a supported (by Microsoft) Windows host. It checks for the most common issues that will prevent successful credentialed scans by Nessus.
How the Kaseya VSA Zero Day Exploit Worked
https://ift.tt/3kenHFy
Submitted July 14, 2021 at 03:09AM by usuhids
via reddit https://ift.tt/3yZW73b
https://ift.tt/3kenHFy
Submitted July 14, 2021 at 03:09AM by usuhids
via reddit https://ift.tt/3yZW73b
TRUESEC Blog
How the Kaseya VSA Zero Day Exploit Worked - TRUESEC Blog
This article explains the pre-auth remote code execution exploit against Kaseya VSA that was used in the recent REvil ransomware attack.
Released the code for Sloth 🦥, a coverage guided fuzzing framework for fuzzing Android Native libraries that makes use of libFuzzer and QEMU user-mode emulation. @ant4g0nist
https://ift.tt/3kks2XN
Submitted July 14, 2021 at 08:57AM by ant4g0nist
via reddit https://ift.tt/3B0CWbi
https://ift.tt/3kks2XN
Submitted July 14, 2021 at 08:57AM by ant4g0nist
via reddit https://ift.tt/3B0CWbi
GitHub
GitHub - ant4g0nist/Sloth: Sloth 🦥 is a coverage guided fuzzing framework for fuzzing Android Native libraries that makes use of…
Sloth 🦥 is a coverage guided fuzzing framework for fuzzing Android Native libraries that makes use of libFuzzer and QEMU user-mode emulation - GitHub - ant4g0nist/Sloth: Sloth 🦥 is a coverage guide...
THM offers prizes and coupons until July 15th. Use the referral link if you haven’t signed up in TryHackMe or visit tryhackme
https://ift.tt/3AXA4vE
Submitted July 14, 2021 at 11:30AM by nischalstha07
via reddit https://ift.tt/3kgVyh2
https://ift.tt/3AXA4vE
Submitted July 14, 2021 at 11:30AM by nischalstha07
via reddit https://ift.tt/3kgVyh2
TryHackMe
TryHackMe | Cyber Security Training
An online platform for learning and teaching cyber security, all through your browser.
Analysis of Satisfyer Sex Toys: Discovering an Authentication Bypass with r2 and Frida
https://ift.tt/3wyrosc
Submitted July 14, 2021 at 11:38AM by _CaptainBanana_
via reddit https://ift.tt/3eetQxE
https://ift.tt/3wyrosc
Submitted July 14, 2021 at 11:38AM by _CaptainBanana_
via reddit https://ift.tt/3eetQxE
Email Security (SPF, DKIM, and DMARC)
https://ift.tt/3B2Cn0r
Submitted July 14, 2021 at 05:04PM by 0xdea
via reddit https://ift.tt/2VFZ4HI
https://ift.tt/3B2Cn0r
Submitted July 14, 2021 at 05:04PM by 0xdea
via reddit https://ift.tt/2VFZ4HI
Praetorian
Email Security (SPF, DKIM, and DMARC) - Praetorian
This article on email security demonstrates how administrators can protect email from attackers impersonating its domain
XLS Entanglement. A new offensive VBA that links Office 365 products to create a viable C2 framework
https://ift.tt/3B5Smeq
Submitted July 14, 2021 at 05:39PM by Hubble_BC_Security
via reddit https://ift.tt/3ecYk3d
https://ift.tt/3B5Smeq
Submitted July 14, 2021 at 05:39PM by Hubble_BC_Security
via reddit https://ift.tt/3ecYk3d
A simple security scanner for vulnerabilities and configuration issues in IaC such as Kubernetes, Dockerfile and Terraform
https://ift.tt/2KXkRBL
Submitted July 14, 2021 at 07:14PM by knqyf263
via reddit https://ift.tt/3AWpFAt
https://ift.tt/2KXkRBL
Submitted July 14, 2021 at 07:14PM by knqyf263
via reddit https://ift.tt/3AWpFAt
GitHub
GitHub - aquasecurity/trivy: Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories…
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more - GitHub - aquasecurity/trivy: Find vulnerabilities, misconfigurations, secrets,...
Free Charging + RCE: Authentication bypass & Remote code execution in Schneider Electric EVlink Charging Stations
https://ift.tt/3kjyG0j
Submitted July 14, 2021 at 08:48PM by dionas
via reddit https://ift.tt/3idhl6E
https://ift.tt/3kjyG0j
Submitted July 14, 2021 at 08:48PM by dionas
via reddit https://ift.tt/3idhl6E
SEC Consult
Authentication bypass & Remote code execution in Schneider Electric EVlink Charging Stations
The Schneider Electric electric car charging stations product line "EVlink" is affected by two vulnerabilities that allow a remote attacker to execute arbitrary commands on the system. Attackers can change the charging station configuration arbitrarily, charge…
Release AIL Framework version 3.6 released with new features (such as YARA retrohunt) and many bugs fixed · ail-project/ail-framework
https://ift.tt/2Ub67Yj
Submitted July 14, 2021 at 08:43PM by adulau
via reddit https://ift.tt/3kmAR3l
https://ift.tt/2Ub67Yj
Submitted July 14, 2021 at 08:43PM by adulau
via reddit https://ift.tt/3kmAR3l
GitHub
Release AIL Framework version 3.6 released with new features (such as YARA retrohunt) and many bugs fixed · ail-project/ail-framework
AIL Framework released version 3.6
AIL Framework version 3.6 released with new features (such as YARA retrohunt), significant performance improvements, refactoring of the modules and many bugs wer...
AIL Framework version 3.6 released with new features (such as YARA retrohunt), significant performance improvements, refactoring of the modules and many bugs wer...
uBlock Origin (and uMatrix) DoS with strict-blocking filter and crafted URL
https://ift.tt/3wEXq5V
Submitted July 14, 2021 at 09:20PM by vtriolet
via reddit https://ift.tt/3ibJGKM
https://ift.tt/3wEXq5V
Submitted July 14, 2021 at 09:20PM by vtriolet
via reddit https://ift.tt/3ibJGKM
GitHub
writings/ublock_origin_and_umatrix_denial_of_service.adoc at main · vtriolet/writings
Assorted writings. Contribute to vtriolet/writings development by creating an account on GitHub.
15 years old heap out-of-bounds write vulnerability in Linux Netfilter powerful enough to bypass all modern security mitigations and achieve kernel code execution
https://ift.tt/3B6SkTe
Submitted July 15, 2021 at 07:43AM by trenno
via reddit https://ift.tt/3zd5c8X
https://ift.tt/3B6SkTe
Submitted July 15, 2021 at 07:43AM by trenno
via reddit https://ift.tt/3zd5c8X
security-research
CVE-2021-22555: Turning \x00\x00 into 10000$
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
Hashing Phone Numbers For 2-Factor Authentication
https://ift.tt/3B4zj3Q
Submitted July 15, 2021 at 11:57AM by theabbiee
via reddit https://ift.tt/3ekBLtq
https://ift.tt/3B4zj3Q
Submitted July 15, 2021 at 11:57AM by theabbiee
via reddit https://ift.tt/3ekBLtq
TheAbbie
Hashing Phone Numbers For 2-Factor Authentication
With the rise of internet and increasing risks of getting hacked, it's more than necessary nowadays that we have an extra layer of security on our accounts, since password alone is not enough. Thus, using Phone numbers for 2FA sounds much more secure, but…