Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
dozer.nz
Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
Overview
Trash Panda as a Service: Raccoon Stealer steals cookies, cryptocoins, and more
https://ift.tt/2Vw80iw
Submitted August 04, 2021 at 12:58AM by securehoney
via reddit https://ift.tt/3xlRM9g
https://ift.tt/2Vw80iw
Submitted August 04, 2021 at 12:58AM by securehoney
via reddit https://ift.tt/3xlRM9g
Sophos News
Trash Panda as a Service: Raccoon Stealer steals cookies, cryptocoins, and more
Cookie and credential stealing malware-as-a-service delivered by dropper-as-a-service now packs a “clipper” to steal crypto-transactions, and can drop other malware.
AppSweep, a free & developer friendly android app security scanning tool
https://ift.tt/3yqlivE
Submitted August 04, 2021 at 01:49PM by Floni
via reddit https://ift.tt/3jiqefT
https://ift.tt/3yqlivE
Submitted August 04, 2021 at 01:49PM by Floni
via reddit https://ift.tt/3jiqefT
reddit
AppSweep, a free & developer friendly android app security...
Posted in r/netsec by u/Floni • 4 points and 0 comments
SAML is insecure by design
https://ift.tt/2Vvl6wu
Submitted August 04, 2021 at 01:56PM by albinowax
via reddit https://ift.tt/3ChqCnp
https://ift.tt/2Vvl6wu
Submitted August 04, 2021 at 01:56PM by albinowax
via reddit https://ift.tt/3ChqCnp
joonas.fi
SAML is insecure by design
What is SAML? Security Assertion Markup Language (SAML) is an open standard for exchanging authentication and authorization data between parties.
Source: Wikipedia
SAML is often used for single-sign on (“Sign in with Google”, “Sign in with Twitter” etc.).…
Source: Wikipedia
SAML is often used for single-sign on (“Sign in with Google”, “Sign in with Twitter” etc.).…
Surveying China’s Digital Silk Road in the Western Balkans
https://ift.tt/3flopxB
Submitted August 04, 2021 at 05:22PM by Fuji_Dragon
via reddit https://ift.tt/3AdV0gT
https://ift.tt/3flopxB
Submitted August 04, 2021 at 05:22PM by Fuji_Dragon
via reddit https://ift.tt/3AdV0gT
War on the Rocks
Surveying China’s Digital Silk Road in the Western Balkans - War on the Rocks
If you walk down the streets of Serbia's capital, Belgrade, your face will almost certainly be recorded by one of the city's 1,000 Huawei security
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
https://ift.tt/3fiConC
Submitted August 04, 2021 at 07:11PM by TheDFIRReport
via reddit https://ift.tt/3rSUPnY
https://ift.tt/3fiConC
Submitted August 04, 2021 at 07:11PM by TheDFIRReport
via reddit https://ift.tt/3rSUPnY
The DFIR Report
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
Intro This report will go through an intrusion that went from an Excel file to domain wide ransomware. The threat actors used BazarCall to install Trickbot in the environment which downloaded and e…
Ubuntu's Snapcraft Packages Come With Extra Baggage: CVE-2020-27348
https://ift.tt/3yrhAls
Submitted August 04, 2021 at 09:02PM by gaasedelen
via reddit https://ift.tt/3rX1ii2
https://ift.tt/3yrhAls
Submitted August 04, 2021 at 09:02PM by gaasedelen
via reddit https://ift.tt/3rX1ii2
RET2 Systems Blog
Snapcraft Packages Come With Extra Baggage
Several months ago I found an issue (now CVE-2020-27348) with Ubuntu’s new package management system, Snapcraft. This bug introduced a classic pattern of ins...
Arbitrary file write in node tar - CVE-2021-32804
https://ift.tt/3il6WqU
Submitted August 04, 2021 at 09:42PM by Photogurt
via reddit https://ift.tt/3fwwEqG
https://ift.tt/3il6WqU
Submitted August 04, 2021 at 09:42PM by Photogurt
via reddit https://ift.tt/3fwwEqG
reddit
Arbitrary file write in node tar - CVE-2021-32804
Posted in r/netsec by u/Photogurt • 2 points and 1 comment
Hotcobalt - New Cobalt Strike DoS Vulnerability That Lets You Halt Operations - SentinelLabs
https://ift.tt/37gGSHc
Submitted August 04, 2021 at 08:08PM by digicat
via reddit https://ift.tt/3lwsrXC
https://ift.tt/37gGSHc
Submitted August 04, 2021 at 08:08PM by digicat
via reddit https://ift.tt/3lwsrXC
SentinelOne
Hotcobalt - New Cobalt Strike DoS Vulnerability That Lets You Halt Operations - SentinelLabs
CVE-2021-36798 is a vulnerability in Cobalt Strike server that could allow victims to register a fake Beacon and DoS attackers.
Possible security issue involving the Firebase JWT library for PHP (Algorithm Confusion with Key IDs)
https://ift.tt/3jo2VkD
Submitted August 04, 2021 at 11:02PM by paragon_init
via reddit https://ift.tt/3Cji3sa
https://ift.tt/3jo2VkD
Submitted August 04, 2021 at 11:02PM by paragon_init
via reddit https://ift.tt/3Cji3sa
GitHub
Possibility of Reintroducing HS256/RSA256 Type Confusion · Issue #351 · firebase/php-jwt
This is a follow-up to the HS256/RS256 Type Confusion attack against the JWT protocol. Now, firebase/php-jwt attempts to side-step this risk by forcing the user to hard-code the algorithms they wis...
Playing with PuTTY
https://ift.tt/3jfvukh
Submitted August 05, 2021 at 12:02AM by 0xdea
via reddit https://ift.tt/3io6CI7
https://ift.tt/3jfvukh
Submitted August 05, 2021 at 12:02AM by 0xdea
via reddit https://ift.tt/3io6CI7
Facebook SSRF
https://ift.tt/37aU9Rq
Submitted August 05, 2021 at 12:21AM by mangojangofett
via reddit https://ift.tt/3jlMm9g
https://ift.tt/37aU9Rq
Submitted August 05, 2021 at 12:21AM by mangojangofett
via reddit https://ift.tt/3jlMm9g
There aren't the access_tokens you're looking for
Facebook SSRF - There aren't the access_tokens you're looking for
Facebook Server Side Request Forgery (SSRF)The following could have given the ability to make arbitrary HTTP requests to servers within Facebook’s production network Facebook SSRF via /me/personas There exists a SSRF in the graph.facebook.com/me/personas…
Exploring the SameSite cookie attribute for preventing CSRF
https://ift.tt/37gajcv
Submitted August 05, 2021 at 04:19AM by ScottContini
via reddit https://ift.tt/3A8Rt3i
https://ift.tt/37gajcv
Submitted August 05, 2021 at 04:19AM by ScottContini
via reddit https://ift.tt/3A8Rt3i
simonwillison.net
Exploring the SameSite cookie attribute for preventing CSRF
In reading Yan Zhu’s excellent write-up of the JSON CSRF vulnerability she found in OkCupid one thing puzzled me: I was under the impression that browsers these days default to …
How to Create Unlimited Rotating Proxies in AWS
https://ift.tt/3kfTNhA
Submitted August 05, 2021 at 05:07AM by AlexandriaLazos
via reddit https://ift.tt/2Vg1BZn
https://ift.tt/3kfTNhA
Submitted August 05, 2021 at 05:07AM by AlexandriaLazos
via reddit https://ift.tt/2Vg1BZn
Medium
How to Create Unlimited Rotating IP Addresses with AWS
We can increase our capabilities to distribute our HTTP requests over a larger and larger pool of networks.
GitHub - GhostPack/ForgeCert: "Golden" certificates
https://ift.tt/2TXBiXa
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3Aamnbx
https://ift.tt/2TXBiXa
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3Aamnbx
GitHub
GitHub - GhostPack/ForgeCert: "Golden" certificates
"Golden" certificates. Contribute to GhostPack/ForgeCert development by creating an account on GitHub.
GitHub - GhostPack/Certify: Active Directory certificate abuse.
https://ift.tt/3fxf8Tj
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3xqypvq
https://ift.tt/3fxf8Tj
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3xqypvq
GitHub
GitHub - GhostPack/Certify: Active Directory certificate abuse.
Active Directory certificate abuse. Contribute to GhostPack/Certify development by creating an account on GitHub.
Analysis of Prometheus Traffic Direction System (TDS): an underground service that distributes malicious files and redirects visitors to phishing and malicious sites
https://ift.tt/3xtHdAO
Submitted August 05, 2021 at 03:52PM by securehoney
via reddit https://ift.tt/3fy8axi
https://ift.tt/3xtHdAO
Submitted August 05, 2021 at 03:52PM by securehoney
via reddit https://ift.tt/3fy8axi
Group-IB
Prometheus TDS
Group-IB TI analysts examined Prometheus TDS — an underground service designed to distribute malicious files and redirect users to phishing and malicious sites.
Bitdefender Anti-Virus Engine Incorporated in SpamTitan v7.00 - SpamTitan Email Security
https://ift.tt/37kYZf1
Submitted August 05, 2021 at 04:51PM by Aystrological
via reddit https://ift.tt/3rV5UFe
https://ift.tt/37kYZf1
Submitted August 05, 2021 at 04:51PM by Aystrological
via reddit https://ift.tt/3rV5UFe
SpamTitan Email Security
Bitdefender Anti-Virus Engine Incorporated in SpamTitan v7.00 - SpamTitan Email Security
A new version of TitanHQ’s cloud-based anti-spam service and anti-spam software was released on March 5, 2018. SpamTitan version 7.00 includes patches for recently identified vulnerabilities in the ClamAV antivirus engine and a change to the primary AV engine…
I2P Chat for Windows 10 instant messenger allows chat anonymously. Get I2P here ->> https://geti2p.net/en/ You need to enable SAM by visiting 127.0.0.1:7657/configclients
https://ift.tt/30J82TA
Submitted August 05, 2021 at 07:28PM by ComprehensiveFudge22
via reddit https://ift.tt/3im2Fn8
https://ift.tt/30J82TA
Submitted August 05, 2021 at 07:28PM by ComprehensiveFudge22
via reddit https://ift.tt/3im2Fn8
geti2p.net
I2P Anonymous Network
Anonymous peer-to-peer distributed communication layer built with open source tools and designed to run any traditional Internet service such as email, IRC or web hosting.
HTTP/2: The Sequel is Always Worse - more HTTP request smuggling attacks from albinowax
https://ift.tt/2WPVg7a
Submitted August 06, 2021 at 12:39AM by virodoran
via reddit https://ift.tt/3fCM50m
https://ift.tt/2WPVg7a
Submitted August 06, 2021 at 12:39AM by virodoran
via reddit https://ift.tt/3fCM50m
PortSwigger Research
HTTP/2: The Sequel is Always Worse
In this research paper James Kettle introduces multiple new classes of HTTP/2-exclusive attacks, demonstrated on popular websites and servers.
Knock knock, who's there? Your new DA!
https://ift.tt/3yy6POo
Submitted August 06, 2021 at 11:28AM by m8urn
via reddit https://ift.tt/3fxPgGz
https://ift.tt/3yy6POo
Submitted August 06, 2021 at 11:28AM by m8urn
via reddit https://ift.tt/3fxPgGz
Truesec
From Stranger to DA // Using PetitPotam to NTLM relay to Domain Administrato - Truesec