Rotten Apples MacOS Codesigning Translocation Vulnerability
https://ift.tt/3zVm702
Submitted July 30, 2021 at 01:16AM by gh0stlazers
via reddit https://ift.tt/3CbvCds
https://ift.tt/3zVm702
Submitted July 30, 2021 at 01:16AM by gh0stlazers
via reddit https://ift.tt/3CbvCds
Department of Justice Statement on SolarWinds Update
https://ift.tt/3xgr41N
Submitted July 31, 2021 at 10:43PM by hi5eyes
via reddit https://ift.tt/2VcLqf4
https://ift.tt/3xgr41N
Submitted July 31, 2021 at 10:43PM by hi5eyes
via reddit https://ift.tt/2VcLqf4
www.justice.gov
Department of Justice Statement on SolarWinds Update
Shadow Credentials: Abusing Key Trust Account Mapping for Takeover
https://ift.tt/3gSUnRE
Submitted August 01, 2021 at 12:21PM by disclosure5
via reddit https://ift.tt/3ig1i9B
https://ift.tt/3gSUnRE
Submitted August 01, 2021 at 12:21PM by disclosure5
via reddit https://ift.tt/3ig1i9B
Medium
Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover
The techniques for DACL-based attacks against User and Computer objects in Active Directory have been established for years. If we…
Github phath0m/JadedWraith - New light-weight ICMP backdoor for UNIX systems
https://ift.tt/3yhL7xT
Submitted August 01, 2021 at 12:35AM by unphath0mable
via reddit https://ift.tt/3llx72r
https://ift.tt/3yhL7xT
Submitted August 01, 2021 at 12:35AM by unphath0mable
via reddit https://ift.tt/3llx72r
GitHub
GitHub - phath0m/JadedWraith: Light-weight UNIX backdoor
Light-weight UNIX backdoor. Contribute to phath0m/JadedWraith development by creating an account on GitHub.
Thinking about “traceability”
https://ift.tt/3C53fh2
Submitted August 02, 2021 at 09:32AM by feross
via reddit https://ift.tt/3fhuueb
https://ift.tt/3C53fh2
Submitted August 02, 2021 at 09:32AM by feross
via reddit https://ift.tt/3fhuueb
A Few Thoughts on Cryptographic Engineering
Thinking about “traceability”
A few weeks back, the messaging service WhatsApp sued the Indian government over new legislation that could undermine its end-to-end encryption (E2EE) software. The legislation requires, among othe…
A Large-Scale Security-Oriented Static Analysis of Python Packages in PyPI
https://ift.tt/3zKEEfi
Submitted August 02, 2021 at 02:21PM by hermajordoctor
via reddit https://ift.tt/3iguTQ4
https://ift.tt/3zKEEfi
Submitted August 02, 2021 at 02:21PM by hermajordoctor
via reddit https://ift.tt/3iguTQ4
reddit
A Large-Scale Security-Oriented Static Analysis of Python Packages...
Posted in r/netsec by u/hermajordoctor • 1 point and 1 comment
CyberDefenders- HoneyPot : WireShark PCAP Analysis
https://ift.tt/3fionGv
Submitted August 02, 2021 at 03:18PM by thatmemforensicsguy
via reddit https://ift.tt/3fm5xhV
https://ift.tt/3fionGv
Submitted August 02, 2021 at 03:18PM by thatmemforensicsguy
via reddit https://ift.tt/3fm5xhV
reddit
CyberDefenders- HoneyPot : WireShark PCAP Analysis
Posted in r/netsec by u/thatmemforensicsguy • 7 points and 0 comments
Potential remote code execution in PyPI
https://ift.tt/3lffB03
Submitted August 02, 2021 at 04:17PM by _vavkamil_
via reddit https://ift.tt/3A0yPdL
https://ift.tt/3lffB03
Submitted August 02, 2021 at 04:17PM by _vavkamil_
via reddit https://ift.tt/3A0yPdL
blog.ryotak.me
Potential remote code execution in PyPI
Preface (日本語版も公開されています。) While PyPI has a security page, they don’t have a clear policy for vulnerability assessments.1 This article describes the vulnerabilities that were reported as potential vulnerabilities, using publicly available information. This…
Universal Privilege Escalation and Persistence – Print Spooler
https://ift.tt/3BYOagK
Submitted August 02, 2021 at 04:47PM by netbiosX
via reddit https://ift.tt/3foXr86
https://ift.tt/3BYOagK
Submitted August 02, 2021 at 04:47PM by netbiosX
via reddit https://ift.tt/3foXr86
Penetration Testing Lab
Universal Privilege Escalation and Persistence – Printer
The Print Spooler is responsible to manage and process printer jobs. It runs as a service with SYSTEM level privileges on windows environments. Abuse of the Print Spooler service is not new and suc…
Almost 10 million BGP route leaks and more than 7 million BGP hijacks occured in Q2 2021
https://ift.tt/3jcdlnE
Submitted August 02, 2021 at 06:17PM by shapelez
via reddit https://ift.tt/2VbXRYA
https://ift.tt/3jcdlnE
Submitted August 02, 2021 at 06:17PM by shapelez
via reddit https://ift.tt/2VbXRYA
blog.qrator.net
Blog — Q2 2021 DDoS attacks and BGP incidents
The second quarter of 2021 was expected to be much quieter than the Q1 in DDoS attacks; hence we're looking at the late spring and early summer months of April, May and June, with somewhat cooled business buzz globally. Although, some attacking activity was…
ZeroDay in 'Commercial Stalkerware' - The Disclosure Dilemma
https://ift.tt/3C2nJHb
Submitted August 03, 2021 at 12:19AM by kev-thehermit
via reddit https://ift.tt/3rPjcTI
https://ift.tt/3C2nJHb
Submitted August 03, 2021 at 12:19AM by kev-thehermit
via reddit https://ift.tt/3rPjcTI
Immersivelabs
Disclosure Dilemmas: Vulnerable Stalkerware - Immersive Labs
Our Director of Cyber Threat Research, Kev Breen, recently discovered a vulnerability in a piece of stalkerware. What followed was a dilemma that has lasted months. Together, the Immersive Labs team has decided to help educate people on the dangers of stalkerware…
The Ultimate Guide to Phishing: Learn how to Phish without spending a single ₹
https://ift.tt/3C6GWaB
Submitted August 03, 2021 at 08:31AM by alt-glitch
via reddit https://ift.tt/3A2B3td
https://ift.tt/3C6GWaB
Submitted August 03, 2021 at 08:31AM by alt-glitch
via reddit https://ift.tt/3A2B3td
computer insecurities
The Ultimate Guide to Phishing
Learn how to Phish using EvilGinx2 and GoPhish
A bunch of different edge-case recon ideas for uncovering well-hidden hostnames
https://ift.tt/3fa7BcL
Submitted August 03, 2021 at 09:40AM by hakluke
via reddit https://ift.tt/3frt6G5
https://ift.tt/3fa7BcL
Submitted August 03, 2021 at 09:40AM by hakluke
via reddit https://ift.tt/3frt6G5
Securitytrails
SecurityTrails | How I Lost the SecurityTrails #ReconMaster Contest, and How You Can Win: Edge-Case Recon Ideas
A while back, SecurityTrails announced that they would be running a contest dubbed
How to boost your popularity on OkCupid using CSRF and a JSON type confusion
https://ift.tt/37ea6WW
Submitted August 03, 2021 at 03:41PM by pimterry
via reddit https://ift.tt/3CdUMI6
https://ift.tt/37ea6WW
Submitted August 03, 2021 at 03:41PM by pimterry
via reddit https://ift.tt/3CdUMI6
reddit
How to boost your popularity on OkCupid using CSRF and a JSON type...
Posted in r/netsec by u/pimterry • 303 points and 30 comments
Escaping from a truly air gapped network via Apple AWDL
https://ift.tt/3loqI6H
Submitted August 03, 2021 at 06:02PM by oherrala
via reddit https://ift.tt/3xnz294
https://ift.tt/3loqI6H
Submitted August 03, 2021 at 06:02PM by oherrala
via reddit https://ift.tt/3xnz294
Medium
Escaping from a truly air gapped network via Apple AWDL
In the following post I go through how to escape from a truly air gapped network using Apple Wireless Direct Link -network and leveraging…
AppSweep, mobile application scanning for developers!
https://ift.tt/3jmxSpH
Submitted August 03, 2021 at 06:13PM by dznn
via reddit https://ift.tt/3Cb1EWJ
https://ift.tt/3jmxSpH
Submitted August 03, 2021 at 06:13PM by dznn
via reddit https://ift.tt/3Cb1EWJ
Guardsquare
Mobile Application Security Testing | AppSweep
Find and fix security issues in your Android app’s code with AppSweep: a mobile application security testing solution, based on ProGuard technology.
AppSec - Account Takeover (ATO) Checklist
https://ift.tt/2VdXQDu
Submitted August 03, 2021 at 06:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3frcjTB
https://ift.tt/2VdXQDu
Submitted August 03, 2021 at 06:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3frcjTB
GitHub
ato-checklist/README.md at master · magoo/ato-checklist
A checklist of practices for organizations dealing with account takeover (ATO) - ato-checklist/README.md at master · magoo/ato-checklist
How to set up GoPhish to evade security controls.
https://ift.tt/3CcBT8r
Submitted August 03, 2021 at 07:59PM by _meatball_
via reddit https://ift.tt/3lz8LlU
https://ift.tt/3CcBT8r
Submitted August 03, 2021 at 07:59PM by _meatball_
via reddit https://ift.tt/3lz8LlU
Bypassing Authentication on 20+ Arcadyan Routers with CVE-2021–20090 and rooting some Buffalo
https://ift.tt/3ym5QAV
Submitted August 03, 2021 at 07:57PM by stargravy
via reddit https://ift.tt/3rOx0hc
https://ift.tt/3ym5QAV
Submitted August 03, 2021 at 07:57PM by stargravy
via reddit https://ift.tt/3rOx0hc
Medium
Bypassing Authentication on Arcadyan Routers with CVE-2021–20090 and rooting some Buffalo
A walkthrough of my first experience in router hacking
Variant analysis of the ‘Sequoia’ bug
https://ift.tt/3yArXDT
Submitted August 03, 2021 at 10:15PM by JordyZomer
via reddit https://ift.tt/3frdaUu
https://ift.tt/3yArXDT
Submitted August 03, 2021 at 10:15PM by JordyZomer
via reddit https://ift.tt/3frdaUu
pwning.systems
Variant analysis of the 'Sequoia' bug
I imagine we've all heard about the recent 'Sequoia' bug discovered by the Qualys Research team. It's a fascinating bug so I decided to do variant analysis using CodeQL!
Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
dozer.nz
Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
Overview