Client Port Scanning — Using WebAssembly And Go
https://ift.tt/3wYGzes
Submitted July 25, 2021 at 11:47PM by cov_id19
via reddit https://ift.tt/3y7bZR4
https://ift.tt/3wYGzes
Submitted July 25, 2021 at 11:47PM by cov_id19
via reddit https://ift.tt/3y7bZR4
Medium
Identify Website Users By Client Port Scanning — Using WebAssembly And Go
Websites tend to scan the open ports of their users, from the browser, to identify new/returning users better.
Can ‘localhost’ be abused…
Can ‘localhost’ be abused…
Browsers — A Localhost Gateway: Client Port Scanning Using WebAssembly And Go
https://ift.tt/3wYGzes
Submitted July 26, 2021 at 12:11AM by cov_id19
via reddit https://ift.tt/3i1aSwT
https://ift.tt/3wYGzes
Submitted July 26, 2021 at 12:11AM by cov_id19
via reddit https://ift.tt/3i1aSwT
Medium
Identify Website Users By Client Port Scanning — Using WebAssembly And Go
Websites tend to scan the open ports of their users, from the browser, to identify new/returning users better.
Can ‘localhost’ be abused…
Can ‘localhost’ be abused…
A Python Input Validation Bypass Technique
https://ift.tt/3zqI3Qm
Submitted July 26, 2021 at 02:44AM by theMiddleBlue
via reddit https://ift.tt/3kUg1IN
https://ift.tt/3zqI3Qm
Submitted July 26, 2021 at 02:44AM by theMiddleBlue
via reddit https://ift.tt/3kUg1IN
Secjuice
A Python Input Validation Bypass Technique
Sometimes, functions included in Python RE are misused by developers and when you see this it can be possible to bypass weak input validation functions.
When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure
https://ift.tt/3BtXOYw
Submitted July 26, 2021 at 05:07PM by securehoney
via reddit https://ift.tt/3iQOzsL
https://ift.tt/3BtXOYw
Submitted July 26, 2021 at 05:07PM by securehoney
via reddit https://ift.tt/3iQOzsL
Microsoft News
When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure
LemonDuck, an actively updated and robust malware that’s primarily known for its botnet and cryptocurrency mining objectives, adopted more sophisticated behavior and escalated its operations. Today, beyond using resources for its traditional bot and mining…
Non-conventional WAF/IDS/Firewall evasion techniques - a guide
https://ift.tt/2UM4pwY
Submitted July 26, 2021 at 05:26AM by 0daywizard
via reddit https://ift.tt/2TDzFha
https://ift.tt/2UM4pwY
Submitted July 26, 2021 at 05:26AM by 0daywizard
via reddit https://ift.tt/2TDzFha
0xFFFF@blog:~$
A guide to non-conventional WAF/IDS evasion techniques
This is a tutorial detailing various non-conventional methods of circumventing signature based WAF or IDS software. Rather than focusing on signature evasion, and bypassing of blacklisted character…
Scanning your iPhone for Pegasus, NSO Group's malware
https://ift.tt/3iSwMkW
Submitted July 26, 2021 at 09:41PM by arkadiyt
via reddit https://ift.tt/3eT4vtB
https://ift.tt/3iSwMkW
Submitted July 26, 2021 at 09:41PM by arkadiyt
via reddit https://ift.tt/3eT4vtB
Arkadiyt
Scanning your iPhone for Pegasus, NSO Group's malware
Scan your iPhone for NSO Group's Pegasus malware using Mobile Verification Toolkit (MVT) by Amnesty International
CVE-2020-28653 Pre-Auth RCE in ManageEngine OPManager
https://ift.tt/3BCM3zb
Submitted July 26, 2021 at 11:54PM by haxolotls
via reddit https://ift.tt/3i2uDEm
https://ift.tt/3BCM3zb
Submitted July 26, 2021 at 11:54PM by haxolotls
via reddit https://ift.tt/3i2uDEm
Haxolot
Pre-Auth RCE in ManageEngine OPManager
Vulnerability Summary ManageEngine OpManager is a popular Java-based network monitoring solution used by large companies such as NASA, DHL or Siemens. Among other things, it allows the monitoring of network devices such as routers, webcams, servers, firewalls…
Mattermost server v5.32 > v5.36 Reflected XSS in OAuth flow - Shielder
https://ift.tt/2WmVbrw
Submitted July 26, 2021 at 06:39PM by smaury
via reddit https://ift.tt/3iT8Vl8
https://ift.tt/2WmVbrw
Submitted July 26, 2021 at 06:39PM by smaury
via reddit https://ift.tt/3iT8Vl8
Shielder
Shielder - Mattermost server v5.32 > v5.36 Reflected XSS in OAuth flow
The OAuth flow implemented in Mattermost server v5.32 > v5.36 is affected by a reflected XSS. An unauthenticated attacker might gain access to the victim's session.
Windows Command-Line Obfuscation
https://ift.tt/3zy7vDF
Submitted July 27, 2021 at 07:17AM by sanitybit
via reddit https://ift.tt/3BMa3zW
https://ift.tt/3zy7vDF
Submitted July 27, 2021 at 07:17AM by sanitybit
via reddit https://ift.tt/3BMa3zW
www.wietzebeukema.nl
Windows Command-Line Obfuscation
Many Windows applications have multiple ways in which the same command line can be expressed, usually for compatibility or ease-of-use reasons. As a result, command-line arguments are implemented inconsistently making detecting specific commands harder due…
Plz challenge secguide for fintech founders
https://ift.tt/3eZeHAN
Submitted July 27, 2021 at 10:52AM by alexbodryk
via reddit https://ift.tt/3iSVDVP
https://ift.tt/3eZeHAN
Submitted July 27, 2021 at 10:52AM by alexbodryk
via reddit https://ift.tt/3iSVDVP
www.cyberlands.io
Get to Know How to Secure Your FinTech MVP
What to take into account when you developing MVP with front-end \ web, mobile, back-end \ api and cloud pieces - and need to securely store at least some customer data
CVE-2021-30807 (iOS IOMobileFrameBuffer LPE): Finding and Exploiting the Vulnerability
https://ift.tt/3f0yhwu
Submitted July 27, 2021 at 10:48AM by 0xdea
via reddit https://ift.tt/3l0YOxG
https://ift.tt/3f0yhwu
Submitted July 27, 2021 at 10:48AM by 0xdea
via reddit https://ift.tt/3l0YOxG
reddit
CVE-2021-30807 (iOS IOMobileFrameBuffer LPE): Finding and...
Posted in r/netsec by u/0xdea • 57 points and 4 comments
IRGC leaked reports show Iran's research into cargo ships, fuel pumps, maritime communications, smart buildings
https://ift.tt/3i1S68C
Submitted July 27, 2021 at 02:40PM by dim23
via reddit https://ift.tt/3BKddUL
https://ift.tt/3i1S68C
Submitted July 27, 2021 at 02:40PM by dim23
via reddit https://ift.tt/3BKddUL
Sky News
Iran's secret cyber files on how cargo ships and petrol stations could be attacked
Assortment of sneaky htaccess tricks for hacking
https://ift.tt/2WrgTus
Submitted July 26, 2021 at 05:20AM by 0daywizard
via reddit https://ift.tt/3BOghPB
https://ift.tt/2WrgTus
Submitted July 26, 2021 at 05:20AM by 0daywizard
via reddit https://ift.tt/3BOghPB
0xFFFF@blog:~$
Utilizing .htaccess for exploitation purposes
This is the first of a two-part series regarding uses of htaccess for exploitation purposes. I will cover some basic and somewhat well-known methods here, along with a few lesser known me…
A crowd sourced compendium of modern Linux malware and offensive techniques
https://ift.tt/2WliOk5
Submitted July 27, 2021 at 04:17PM by timb_machine
via reddit https://ift.tt/3l2z4km
https://ift.tt/2WliOk5
Submitted July 27, 2021 at 04:17PM by timb_machine
via reddit https://ift.tt/3l2z4km
GitHub
GitHub - timb-machine/linux-malware: Tracking interesting Linux (and UNIX) malware. Send PRs
Tracking interesting Linux (and UNIX) malware. Send PRs - GitHub - timb-machine/linux-malware: Tracking interesting Linux (and UNIX) malware. Send PRs
We’re in the Uncanny Valley of Information Security
https://ift.tt/3l0AHit
Submitted July 27, 2021 at 06:14PM by tucows_carl
via reddit https://ift.tt/2UKqOed
https://ift.tt/3l0AHit
Submitted July 27, 2021 at 06:14PM by tucows_carl
via reddit https://ift.tt/2UKqOed
Medium
We’re in the Uncanny Valley of Information Security
As technology evolves, so too must information security.
Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth
https://ift.tt/3zLliXz
Submitted July 27, 2021 at 07:26PM by haxolotls
via reddit https://ift.tt/3rD5za6
https://ift.tt/3zLliXz
Submitted July 27, 2021 at 07:26PM by haxolotls
via reddit https://ift.tt/3rD5za6
Haxolot
Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth
It was found that the Shibboleth authentication module of Moodle suffers from a beautiful Remote Code Execution vulnerability from the unauthenticated perspective. This is widely used among universities to allow students from one university to authenticate…
Generating Secure Passwords for Linux Servers
https://ift.tt/3zF2Qj9
Submitted July 27, 2021 at 07:37PM by Unprotectedtxt
via reddit https://ift.tt/2VbCB4Y
https://ift.tt/3zF2Qj9
Submitted July 27, 2021 at 07:37PM by Unprotectedtxt
via reddit https://ift.tt/2VbCB4Y
Linux Systems Analyst | Hayden James
Generating Secure Passwords for your Linux Server
Sysadmins will often have to set up new servers or harden existing server passwords during security audits. As a result, secure passwords have to be
Google launches new vulnerability reward platform
https://ift.tt/3BKkh3G
Submitted July 27, 2021 at 08:17PM by pimterry
via reddit https://ift.tt/3i8NhdS
https://ift.tt/3BKkh3G
Submitted July 27, 2021 at 08:17PM by pimterry
via reddit https://ift.tt/3i8NhdS
Google Online Security Blog
A new chapter for Google’s Vulnerability Reward Program
Posted by Jan Keller, Technical Program Manager, Google VRP A little over 10 years ago , we launched our Vulnerability Rewards Program (VR...
Oscorp evolves into UBEL: an Android malware spreading across the globe | Cleafy Labs
https://ift.tt/2UNZonM
Submitted July 27, 2021 at 08:07PM by f3d_0x0
via reddit https://ift.tt/3l1rDKn
https://ift.tt/2UNZonM
Submitted July 27, 2021 at 08:07PM by f3d_0x0
via reddit https://ift.tt/3l1rDKn
Cleafy
Oscorp evolves into UBEL: an Android malware spreading across the globe | Cleafy Labs
The Android malware Oscorp keeps evolving. UBEL was born, a new advanced threat targeting banks across the globe: here is the full technical report
Tokyo 2020 Olympic Games event volunteers and ticket holders' credentials were allegedly stolen after a data breach❗
https://ift.tt/3yaj3fQ
Submitted July 27, 2021 at 09:18PM by Aggressive_Project
via reddit https://ift.tt/3f053xI
https://ift.tt/3yaj3fQ
Submitted July 27, 2021 at 09:18PM by Aggressive_Project
via reddit https://ift.tt/3f053xI
VPNRanks
Tokyo 2020 Olympics Hit By Data Breach - Information Leaked Online
Tokyo 2020 Olympics Game hit by a massive data breach, where username and passwords of ticketholders and volunteers were reportedly compromised.
Our shared common weaknesses - A breakdown of CVEs in 2021 so far
https://ift.tt/3BOXdAM
Submitted July 28, 2021 at 12:30AM by Photogurt
via reddit https://ift.tt/3eZG1is
https://ift.tt/3BOXdAM
Submitted July 28, 2021 at 12:30AM by Photogurt
via reddit https://ift.tt/3eZG1is
GitHub Security Lab
Our shared common weaknesses
An overview of 2021’s vulnerabilities so far.