IoT/Connected device discovery and vulnerability assessment API (IoTVAS) released with nmap integration example
https://ift.tt/3yFrC2y
Submitted August 16, 2021 at 05:47PM by ucbrl
via reddit https://ift.tt/2UoXp92
https://ift.tt/3yFrC2y
Submitted August 16, 2021 at 05:47PM by ucbrl
via reddit https://ift.tt/2UoXp92
GitHub
GitHub - firmalyzer/iotvas-nmap: This is a NSE noscript that uses IoTVAS API and enables NMAP port scanner to perform connected device…
This is a NSE noscript that uses IoTVAS API and enables NMAP port scanner to perform connected device discovery and security risk assessment - GitHub - firmalyzer/iotvas-nmap: This is a NSE noscript th...
Integer Overflow to RCE — ManageEngine Asset Explorer Agent (CVE-2021–20082)
https://ift.tt/3yWe9mZ
Submitted August 18, 2021 at 05:42AM by MalwareSeattle
via reddit https://ift.tt/3zatjFH
https://ift.tt/3yWe9mZ
Submitted August 18, 2021 at 05:42AM by MalwareSeattle
via reddit https://ift.tt/3zatjFH
Medium
Integer Overflow to RCE — ManageEngine Asset Explorer Agent (CVE-2021–20082)
A couple months back, Chris Lyne and I had a look at ManageEngine ServiceDesk Plus. This product consists of a server / agent model in…
New osint podcast with the harvester
https://ift.tt/2XCREGa
Submitted August 18, 2021 at 11:40PM by bsdinvoid
via reddit https://ift.tt/3sr5LJU
https://ift.tt/2XCREGa
Submitted August 18, 2021 at 11:40PM by bsdinvoid
via reddit https://ift.tt/3sr5LJU
Anchor
Osint Special with Jay Townsend by Security Headlines
In this episode of Security Headlines, we are joined by Jay Townsend who is
maintaining several infosec tools such as the harvester and discover.
The harvester is a very popular tool for doing Osint analysis. Tune into this episode
as we deep dive into…
maintaining several infosec tools such as the harvester and discover.
The harvester is a very popular tool for doing Osint analysis. Tune into this episode
as we deep dive into…
Sophos UTM Preauth RCE: A Deep Dive into CVE-2020-25223
https://ift.tt/3iY08zZ
Submitted August 19, 2021 at 01:37AM by juken
via reddit https://ift.tt/3iYp6yV
https://ift.tt/3iY08zZ
Submitted August 19, 2021 at 01:37AM by juken
via reddit https://ift.tt/3iYp6yV
Atredis Partners
Sophos UTM Preauth RCE: A Deep Dive into CVE-2020-25223 — Atredis Partners
Note: Sophos fixed this issue in September 2020. Information about patch availability is in their security advisory .
Stored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus
https://ift.tt/3k32zjX
Submitted August 19, 2021 at 12:07AM by lynerc
via reddit https://ift.tt/2W3stvx
https://ift.tt/3k32zjX
Submitted August 19, 2021 at 12:07AM by lynerc
via reddit https://ift.tt/2W3stvx
Medium
Stored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus
Gaining SYSTEM access via the help desk software
Introducing GoKart, a Smarter Go Security Scanner
https://ift.tt/3iWmT7i
Submitted August 19, 2021 at 03:46PM by 0xdea
via reddit https://ift.tt/3iVLuJo
https://ift.tt/3iWmT7i
Submitted August 19, 2021 at 03:46PM by 0xdea
via reddit https://ift.tt/3iVLuJo
Praetorian
Introducing GoKart, a Smarter Go Security Scanner - Praetorian
Introducing GoKart, a next-generation open source Golang static analysis security tool (SAST) with taint tracking.
My FirsReportt Instagram Bug Bounty
https://ift.tt/3lgDBzX
Submitted August 19, 2021 at 04:06PM by banginpadr
via reddit https://ift.tt/3AUgbER
https://ift.tt/3lgDBzX
Submitted August 19, 2021 at 04:06PM by banginpadr
via reddit https://ift.tt/3AUgbER
Medium
My First Instagram Bug Bounty Report
Something is better than nothing, even if it is less than one wanted.
AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality [Windows Subsystem/PowerShell]
https://ift.tt/2SV9vA8
Submitted August 19, 2021 at 06:47PM by rootsh3ll
via reddit https://ift.tt/3y0FJhQ
https://ift.tt/2SV9vA8
Submitted August 19, 2021 at 06:47PM by rootsh3ll
via reddit https://ift.tt/3y0FJhQ
GitHub
GitHub - iamrootsh3ll/AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem
A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem - GitHub - iamrootsh3ll/AnchorWatch: A Rogue Device Detection Script with Email Alerts Functionality for Window...
Figuring out user behavior on Windows
https://ift.tt/3ATp0i9
Submitted August 19, 2021 at 07:19PM by oddvarmoe
via reddit https://ift.tt/3CYHWOp
https://ift.tt/3ATp0i9
Submitted August 19, 2021 at 07:19PM by oddvarmoe
via reddit https://ift.tt/3CYHWOp
TrustedSec
Oh, Behave! Figuring Out User Behavior
I decided to embark on a journey to understand user behavior without knowing exactly how I would gather details about user activity as a research topic. A…
ShadowPad | A Masterpiece of Privately Sold Malware in Chinese Espionage
https://ift.tt/3y5Emym
Submitted August 19, 2021 at 08:18PM by Cyberthere
via reddit https://ift.tt/3mhWYco
https://ift.tt/3y5Emym
Submitted August 19, 2021 at 08:18PM by Cyberthere
via reddit https://ift.tt/3mhWYco
SentinelOne
ShadowPad | A Masterpiece of Privately Sold Malware in Chinese Espionage - SentinelLabs
Supplying a custom backdoor to a cluster of APT groups, the personas behind ShadowPad have maintained a cloak of secrecy, until now.
T-Mobile allegedly hacked, claims no sensitive data stolen
https://ift.tt/3iYT4CU
Submitted August 19, 2021 at 11:51PM by Pm_dat_bootyhole
via reddit https://ift.tt/2XKLOmh
https://ift.tt/3iYT4CU
Submitted August 19, 2021 at 11:51PM by Pm_dat_bootyhole
via reddit https://ift.tt/2XKLOmh
T-Mobile
Our Response to the Data Breach (Aug 2021) | T-Mobile
Learn more about our response to the recent cybersecurity incident and the steps we're taking to ensure our customers' data is safe.
Independent Peer Review (from Cititzen Lab) of Amnesty International’s Forensic Methods for Identifying Pegasus Spyware
https://ift.tt/3eylaCB
Submitted August 20, 2021 at 02:40AM by Turbulent_Froyo9385
via reddit https://ift.tt/3swUJTn
https://ift.tt/3eylaCB
Submitted August 20, 2021 at 02:40AM by Turbulent_Froyo9385
via reddit https://ift.tt/3swUJTn
The Citizen Lab
Independent Peer Review of Amnesty International's Forensic Methods for Identifying Pegasus Spyware - The Citizen Lab
Citizen Lab's peer review of Amnesty International's forensic techniques to identify Pegasus spyware concludes they are sound.
CIA: Confidentiality, Integrity and Availability
https://ift.tt/3xWH0GN
Submitted August 20, 2021 at 03:29AM by WeHackPurpleAcademy
via reddit https://ift.tt/3sz1ww8
https://ift.tt/3xWH0GN
Submitted August 20, 2021 at 03:29AM by WeHackPurpleAcademy
via reddit https://ift.tt/3sz1ww8
reddit
CIA: Confidentiality, Integrity and Availability
Posted in r/netsec by u/WeHackPurpleAcademy • 0 points and 1 comment
How to contact Google SRE: Dropping a shell in cloud SQL
https://ift.tt/2CLqeDY
Submitted August 20, 2021 at 06:46AM by NearbyIssue629
via reddit https://ift.tt/3syYTKD
https://ift.tt/2CLqeDY
Submitted August 20, 2021 at 06:46AM by NearbyIssue629
via reddit https://ift.tt/3syYTKD
Offensi
How to contact Google SRE: Dropping a shell in cloud SQL
Note: The vulnerabilities that are discussed in this post were patched quickly and properly by Google. We support responsible disclosure. The research that resulted in this post was done by me and …
DTLS Interception Tool (DIT) | A mitmproxy-like tool for DTLS connections
https://ift.tt/2WceUK9
Submitted August 20, 2021 at 02:43PM by WasZurHecke
via reddit https://ift.tt/3sBJucC
https://ift.tt/2WceUK9
Submitted August 20, 2021 at 02:43PM by WasZurHecke
via reddit https://ift.tt/3sBJucC
GitHub
GitHub - CountablyInfinite/dit: DIT is a DTLS MitM proxy implemented in Python 3. It can intercept, manipulate and suppress datagrams…
DIT is a DTLS MitM proxy implemented in Python 3. It can intercept, manipulate and suppress datagrams between two DTLS endpoints and supports psk-based and certificate-based authentication schemes ...
Dissecting the last version of Conti Ransomware using a step-by-step approach
https://ift.tt/3hOPbP4
Submitted August 20, 2021 at 06:02PM by transt
via reddit https://ift.tt/3y3vzgq
https://ift.tt/3hOPbP4
Submitted August 20, 2021 at 06:02PM by transt
via reddit https://ift.tt/3y3vzgq
reddit
Dissecting the last version of Conti Ransomware using a...
Posted in r/netsec by u/transt • 76 points and 0 comments
[CFP] Call for Papers for Hardwear.io Security Conference Netherlands 2021 is OPEN
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
https://ift.tt/3rD3Ql4
Submitted August 20, 2021 at 07:41PM by hardweario
via reddit https://ift.tt/384oVf6
www.hardwear.io
Call for Papers | hardwear.io | Netherlands 2021
hardwear.io Netherlands 2021 - Hardware Security Conference & Training is seeking innovative research on attacks or mitigation on any hardware. Submit your research paper.
Lobste.rs Password Reset Vulnerability (via Timing Side-Channel)
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
https://ift.tt/2W47V6I
Submitted August 20, 2021 at 08:45PM by Soatok
via reddit https://ift.tt/37XNYAL
Dhole Moments
Timing Attack on SQL Queries Through Lobste.rs Password Reset
Just to assuage any panic, let me state this up front. If you’re reading this blog post wondering if your Lobste.rs account is at risk, good news: I didn’t publish it until after the vu…
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
https://ift.tt/3iYGCDm
Submitted August 20, 2021 at 10:08PM by Snardley
via reddit https://ift.tt/3B00Kek
The Record by Recorded Future
Cloudflare says it mitigated a record-breaking 17.2M rps DDoS attack
Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service (DDoS) attack that was recorded to date.
Facebook tool protects Afghan people who fear becoming Taliban targets
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
https://ift.tt/3k5PBBY
Submitted August 20, 2021 at 10:41PM by No_Fisherman_661
via reddit https://ift.tt/3z4gHQ8
TechnoidHost
Facebook tool protects Afghan people who fear becoming Taliban targets | TechnoidHost
The Latest Facebook tool protects Afghan people who fear becoming Taliban targets. The Facebook toll launched by Facebook will help the people in fear of
Office 365 audit logging and its bypasses
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
https://ift.tt/3z4ZmXf
Submitted August 21, 2021 at 12:41AM by rikvduijn
via reddit https://ift.tt/3DeVVQu
Zolder - Applied Security Research
Office 365 audit logging | Zolder - Applied Security Research
It’s important to enable audit logging for o365 even if you are not monitoring them actively. Atleast if you get...