Hidden parameters discovery suite wrapper - x8-Burp
https://ift.tt/3eJljTG
Submitted July 23, 2021 at 01:30AM by lmpact_
via reddit https://ift.tt/3kLqwOy
https://ift.tt/3eJljTG
Submitted July 23, 2021 at 01:30AM by lmpact_
via reddit https://ift.tt/3kLqwOy
GitHub
GitHub - Impact-I/x8-Burp: Hidden parameters discovery suite
Hidden parameters discovery suite. Contribute to Impact-I/x8-Burp development by creating an account on GitHub.
OpenSSH ssh-agent Shielded Private Key Extraction (x86_64 Linux)
https://ift.tt/3rwqmfC
Submitted July 23, 2021 at 02:41PM by 0xdea
via reddit https://ift.tt/2TuSKSx
https://ift.tt/3rwqmfC
Submitted July 23, 2021 at 02:41PM by 0xdea
via reddit https://ift.tt/2TuSKSx
hn security
OpenSSH ssh-agent Shielded Private Key Extraction (x86_64 Linux) - hn security
Some notes about retrieving an OpenSSH shielded private key from ssh-agent process memory (gcore dump)
A DDoS weakness assessment tool
https://ift.tt/3kKuwPz
Submitted July 23, 2021 at 07:24PM by alexbodryk
via reddit https://ift.tt/3zpxtcn
https://ift.tt/3kKuwPz
Submitted July 23, 2021 at 07:24PM by alexbodryk
via reddit https://ift.tt/3zpxtcn
GitHub
GitHub - Cyberlands-io/epiphany: A pre-DDoS security assessment tool
A pre-DDoS security assessment tool. Contribute to Cyberlands-io/epiphany development by creating an account on GitHub.
Windows Command-Line Obfuscation
https://ift.tt/3BwqcsZ
Submitted July 23, 2021 at 07:22PM by Wietze-
via reddit https://ift.tt/3eLdPzK
https://ift.tt/3BwqcsZ
Submitted July 23, 2021 at 07:22PM by Wietze-
via reddit https://ift.tt/3eLdPzK
www.wietzebeukema.nl
Windows Command-Line Obfuscation
Many Windows applications have multiple ways in which the same command line can be expressed, usually for compatibility or ease-of-use reasons. As a result, command-line arguments are implemented inconsistently making detecting specific commands harder due…
Meet JWTs Cousin: CBOR Web Tokens (CWTs) - An Introduction
https://ift.tt/3eOO8Ow
Submitted July 23, 2021 at 09:41PM by _SecurityGOAT
via reddit https://ift.tt/3BzbGkk
https://ift.tt/3eOO8Ow
Submitted July 23, 2021 at 09:41PM by _SecurityGOAT
via reddit https://ift.tt/3BzbGkk
Medium
CBOR Web Tokens (CWTs)
Meet JWTs cousin: CWT: machine-friendly, saves processing power, and is especially suitable for IoT devices. Provides same features as…
Windows Command-Line Obfuscation - Use & Discovery
https://ift.tt/3zy7vDF
Submitted July 23, 2021 at 09:20PM by WM-M-GM
via reddit https://ift.tt/37b55yJ
https://ift.tt/3zy7vDF
Submitted July 23, 2021 at 09:20PM by WM-M-GM
via reddit https://ift.tt/37b55yJ
www.wietzebeukema.nl
Windows Command-Line Obfuscation
Many Windows applications have multiple ways in which the same command line can be expressed, usually for compatibility or ease-of-use reasons. As a result, command-line arguments are implemented inconsistently making detecting specific commands harder due…
Timing Analysis of Keystrokes and Timing Attacks on SSH
https://ift.tt/3BtIbjX
Submitted July 23, 2021 at 11:24PM by dontbenebby
via reddit https://ift.tt/2Txx7RJ
https://ift.tt/3BtIbjX
Submitted July 23, 2021 at 11:24PM by dontbenebby
via reddit https://ift.tt/2Txx7RJ
(Foreign Source) The entire Clubhouse phonenumber database (3.8 billion numbers, including contacts) is up for sale on the darknet
https://ift.tt/3BAEkS7
Submitted July 24, 2021 at 05:50PM by Akid0uu
via reddit https://ift.tt/3hYRe4E
https://ift.tt/3BAEkS7
Submitted July 24, 2021 at 05:50PM by Akid0uu
via reddit https://ift.tt/3hYRe4E
futurezone
Clubhouse leakt 3,8 Milliarden Telefonnummern
Auch wenn man die Clubhouse-App gar nicht verwendet, kann die eigene Nummer im Leak enthalten sein.
HITB lockdown 002 takes place tomorrow. Grab your drinks, food and enjoy the talks, labs and ctf lined up
https://ift.tt/30JSVZH
Submitted July 24, 2021 at 06:20PM by LouisOve
via reddit https://ift.tt/3zAK10H
https://ift.tt/30JSVZH
Submitted July 24, 2021 at 06:20PM by LouisOve
via reddit https://ift.tt/3zAK10H
Hack In The Box Security Conference
HITB Lockdown 002 - Hack In The Box Security Conference
July 25 & 26 10am – 10pm sgt HITB LOCKDOWN 002 Days Hours Minutes Presentation materials https://conference.hitb.org/hitblockdown002/materials/ HITB Lockdown Livestream 25th & 26th July 10am - 10pm SGT AGENDA HITB Virtual Labs 25th & 26th July 2pm - 6pm SGT…
Reconky is an amazing Content Discovery tool for bug bounty hunters which automate lot of task and organized in the well mannered form which help them to look forward.
https://ift.tt/3x3InD0
Submitted July 25, 2021 at 06:02PM by shivamrai24
via reddit https://ift.tt/3iFOFn8
https://ift.tt/3x3InD0
Submitted July 25, 2021 at 06:02PM by shivamrai24
via reddit https://ift.tt/3iFOFn8
GitHub
GitHub - ShivamRai2003/Reconky-Automated_Bash_Script: Reconky is an great Content Discovery bash noscript for bug bounty hunters…
Reconky is an great Content Discovery bash noscript for bug bounty hunters which automate lot of task and organized in the well mannered form which help them to look forward. - GitHub - ShivamRai200...
Client Port Scanning — Using WebAssembly And Go
https://ift.tt/3wYGzes
Submitted July 25, 2021 at 11:47PM by cov_id19
via reddit https://ift.tt/3y7bZR4
https://ift.tt/3wYGzes
Submitted July 25, 2021 at 11:47PM by cov_id19
via reddit https://ift.tt/3y7bZR4
Medium
Identify Website Users By Client Port Scanning — Using WebAssembly And Go
Websites tend to scan the open ports of their users, from the browser, to identify new/returning users better.
Can ‘localhost’ be abused…
Can ‘localhost’ be abused…
Browsers — A Localhost Gateway: Client Port Scanning Using WebAssembly And Go
https://ift.tt/3wYGzes
Submitted July 26, 2021 at 12:11AM by cov_id19
via reddit https://ift.tt/3i1aSwT
https://ift.tt/3wYGzes
Submitted July 26, 2021 at 12:11AM by cov_id19
via reddit https://ift.tt/3i1aSwT
Medium
Identify Website Users By Client Port Scanning — Using WebAssembly And Go
Websites tend to scan the open ports of their users, from the browser, to identify new/returning users better.
Can ‘localhost’ be abused…
Can ‘localhost’ be abused…
A Python Input Validation Bypass Technique
https://ift.tt/3zqI3Qm
Submitted July 26, 2021 at 02:44AM by theMiddleBlue
via reddit https://ift.tt/3kUg1IN
https://ift.tt/3zqI3Qm
Submitted July 26, 2021 at 02:44AM by theMiddleBlue
via reddit https://ift.tt/3kUg1IN
Secjuice
A Python Input Validation Bypass Technique
Sometimes, functions included in Python RE are misused by developers and when you see this it can be possible to bypass weak input validation functions.
When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure
https://ift.tt/3BtXOYw
Submitted July 26, 2021 at 05:07PM by securehoney
via reddit https://ift.tt/3iQOzsL
https://ift.tt/3BtXOYw
Submitted July 26, 2021 at 05:07PM by securehoney
via reddit https://ift.tt/3iQOzsL
Microsoft News
When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure
LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives, adopted more sophisticated behavior and escalated its operations. Today, beyond using resources for its traditional bot and mining…
Non-conventional WAF/IDS/Firewall evasion techniques - a guide
https://ift.tt/2UM4pwY
Submitted July 26, 2021 at 05:26AM by 0daywizard
via reddit https://ift.tt/2TDzFha
https://ift.tt/2UM4pwY
Submitted July 26, 2021 at 05:26AM by 0daywizard
via reddit https://ift.tt/2TDzFha
0xFFFF@blog:~$
A guide to non-conventional WAF/IDS evasion techniques
This is a tutorial detailing various non-conventional methods of circumventing signature based WAF or IDS software. Rather than focusing on signature evasion, and bypassing of blacklisted character…
Scanning your iPhone for Pegasus, NSO Group's malware
https://ift.tt/3iSwMkW
Submitted July 26, 2021 at 09:41PM by arkadiyt
via reddit https://ift.tt/3eT4vtB
https://ift.tt/3iSwMkW
Submitted July 26, 2021 at 09:41PM by arkadiyt
via reddit https://ift.tt/3eT4vtB
Arkadiyt
Scanning your iPhone for Pegasus, NSO Group's malware
Scan your iPhone for NSO Group's Pegasus malware using Mobile Verification Toolkit (MVT) by Amnesty International
CVE-2020-28653 Pre-Auth RCE in ManageEngine OPManager
https://ift.tt/3BCM3zb
Submitted July 26, 2021 at 11:54PM by haxolotls
via reddit https://ift.tt/3i2uDEm
https://ift.tt/3BCM3zb
Submitted July 26, 2021 at 11:54PM by haxolotls
via reddit https://ift.tt/3i2uDEm
Haxolot
Pre-Auth RCE in ManageEngine OPManager
Vulnerability Summary ManageEngine OpManager is a popular Java-based network monitoring solution used by large companies such as NASA, DHL or Siemens. Among other things, it allows the monitoring of network devices such as routers, webcams, servers, firewalls…
Mattermost server v5.32 > v5.36 Reflected XSS in OAuth flow - Shielder
https://ift.tt/2WmVbrw
Submitted July 26, 2021 at 06:39PM by smaury
via reddit https://ift.tt/3iT8Vl8
https://ift.tt/2WmVbrw
Submitted July 26, 2021 at 06:39PM by smaury
via reddit https://ift.tt/3iT8Vl8
Shielder
Shielder - Mattermost server v5.32 > v5.36 Reflected XSS in OAuth flow
The OAuth flow implemented in Mattermost server v5.32 > v5.36 is affected by a reflected XSS. An unauthenticated attacker might gain access to the victim's session.
Windows Command-Line Obfuscation
https://ift.tt/3zy7vDF
Submitted July 27, 2021 at 07:17AM by sanitybit
via reddit https://ift.tt/3BMa3zW
https://ift.tt/3zy7vDF
Submitted July 27, 2021 at 07:17AM by sanitybit
via reddit https://ift.tt/3BMa3zW
www.wietzebeukema.nl
Windows Command-Line Obfuscation
Many Windows applications have multiple ways in which the same command line can be expressed, usually for compatibility or ease-of-use reasons. As a result, command-line arguments are implemented inconsistently making detecting specific commands harder due…
Plz challenge secguide for fintech founders
https://ift.tt/3eZeHAN
Submitted July 27, 2021 at 10:52AM by alexbodryk
via reddit https://ift.tt/3iSVDVP
https://ift.tt/3eZeHAN
Submitted July 27, 2021 at 10:52AM by alexbodryk
via reddit https://ift.tt/3iSVDVP
www.cyberlands.io
Get to Know How to Secure Your FinTech MVP
What to take into account when you developing MVP with front-end \ web, mobile, back-end \ api and cloud pieces - and need to securely store at least some customer data
CVE-2021-30807 (iOS IOMobileFrameBuffer LPE): Finding and Exploiting the Vulnerability
https://ift.tt/3f0yhwu
Submitted July 27, 2021 at 10:48AM by 0xdea
via reddit https://ift.tt/3l0YOxG
https://ift.tt/3f0yhwu
Submitted July 27, 2021 at 10:48AM by 0xdea
via reddit https://ift.tt/3l0YOxG
reddit
CVE-2021-30807 (iOS IOMobileFrameBuffer LPE): Finding and...
Posted in r/netsec by u/0xdea • 57 points and 4 comments