Improving Git protocol security on GitHub
https://ift.tt/3DBkd7i
Submitted September 01, 2021 at 11:09PM by pimterry
via reddit https://ift.tt/38uhSwv
https://ift.tt/3DBkd7i
Submitted September 01, 2021 at 11:09PM by pimterry
via reddit https://ift.tt/38uhSwv
The GitHub Blog
Improving Git protocol security on GitHub
We’re changing which keys are supported in SSH and removing unencrypted Git protocol. If you’re an SSH user, read on for the details and timeline.
DHCP Games with Smart Router Devices
https://ift.tt/38CzaYB
Submitted September 02, 2021 at 12:55PM by anvilventures
via reddit https://ift.tt/3jyMm74
https://ift.tt/38CzaYB
Submitted September 02, 2021 at 12:55PM by anvilventures
via reddit https://ift.tt/3jyMm74
Anvil Secure
DHCP Games with Smart Router Devices - Anvil Secure
During a recent engagement, we identified a recurring and interesting scenario involving smart router devices. We define smart router devices as devices with functionality that requires them to provide services beyond basic routing to an internal LAN network…
Crashing SIP Clients With a Single Slash by Claroty Research
https://ift.tt/3jAbzOu
Submitted September 02, 2021 at 09:47PM by n0llbyte
via reddit https://ift.tt/3zHM8zY
https://ift.tt/3jAbzOu
Submitted September 02, 2021 at 09:47PM by n0llbyte
via reddit https://ift.tt/3zHM8zY
Claroty
Crashing SIP IoT Clients with a Single Malformed Header
Claroty Team82 discloses details on a vulnerability that can be used to crash a SIP IoT Client with a single malformed header packet.
Security Advisory // Multiple vulnerabilities in EMC VNX NAS 8.1.9-232
https://ift.tt/3BBiNbg
Submitted September 02, 2021 at 10:17PM by gquere
via reddit https://ift.tt/3jBIVfW
https://ift.tt/3BBiNbg
Submitted September 02, 2021 at 10:17PM by gquere
via reddit https://ift.tt/3jBIVfW
reddit
Security Advisory // Multiple vulnerabilities in EMC VNX NAS 8.1.9-232
Posted in r/netsec by u/gquere • 1 point and 0 comments
An Empirical Cybersecurity Evaluation of GitHub Copilot's Code Contributions
https://ift.tt/3mprvVs
Submitted September 03, 2021 at 02:13AM by sanitybit
via reddit https://ift.tt/38B7tzl
https://ift.tt/3mprvVs
Submitted September 03, 2021 at 02:13AM by sanitybit
via reddit https://ift.tt/38B7tzl
reddit
An Empirical Cybersecurity Evaluation of GitHub Copilot's Code...
Posted in r/netsec by u/sanitybit • 3 points and 1 comment
A deep-dive into the SolarWinds Serv-U SSH vulnerability
https://ift.tt/3n2JW2C
Submitted September 03, 2021 at 12:00PM by 0xdea
via reddit https://ift.tt/38DCiU4
https://ift.tt/3n2JW2C
Submitted September 03, 2021 at 12:00PM by 0xdea
via reddit https://ift.tt/38DCiU4
Microsoft Security Blog
A deep-dive into the SolarWinds Serv-U SSH vulnerability | Microsoft Security Blog
We're sharing technical information about the vulnerability tracked as CVE-2021-35211, which was used to attack the SolarWinds Serv-U FTP software in limited and targeted attacks.
A library for reading PST files (written in Go/Golang).
https://ift.tt/2VUw13K
Submitted September 03, 2021 at 05:22PM by Mundane-Low-1502
via reddit https://ift.tt/3BE7m2t
https://ift.tt/2VUw13K
Submitted September 03, 2021 at 05:22PM by Mundane-Low-1502
via reddit https://ift.tt/3BE7m2t
GitHub
GitHub - mooijtech/go-pst: A library for reading PST files (written in Go/Golang).
A library for reading PST files (written in Go/Golang). - GitHub - mooijtech/go-pst: A library for reading PST files (written in Go/Golang).
From RpcView to PetitPotam
https://ift.tt/3n43PGz
Submitted September 03, 2021 at 05:17PM by 0xdea
via reddit https://ift.tt/3n1uJ1Q
https://ift.tt/3n43PGz
Submitted September 03, 2021 at 05:17PM by 0xdea
via reddit https://ift.tt/3n1uJ1Q
itm4n.github.io
From RpcView to PetitPotam | itm4n's blog
In the previous post we saw how to set up a Windows 10 machine in order to manually analyze Windows RPC with RpcView. In this post, we will see how the infor...
Anatomy and Disruption of Metasploit Shellcode
https://ift.tt/3t7GN2s
Submitted September 03, 2021 at 07:31PM by 0xThiebaut
via reddit https://ift.tt/3zL1a86
https://ift.tt/3t7GN2s
Submitted September 03, 2021 at 07:31PM by 0xThiebaut
via reddit https://ift.tt/3zL1a86
NVISO Labs
Anatomy and Disruption of Metasploit Shellcode
In April 2021 we went through the anatomy of a Cobalt Strike stager and how some of its signature evasion techniques ended up being ineffective against detection technologies. In this blog post we …
CVE-2021-26084 - Confluence Server Webwork OGNL injection
https://ift.tt/3t7bLrs
Submitted September 03, 2021 at 08:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3jJ5a3K
https://ift.tt/3t7bLrs
Submitted September 03, 2021 at 08:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3jJ5a3K
reddit
CVE-2021-26084 - Confluence Server Webwork OGNL injection
Posted in r/netsec by u/ZealousidealYogurt41 • 1 point and 0 comments
Rudroid - Writing the World's worst Android Emulator in Rust 🦀 - @ant4g0nist
https://ift.tt/3tdnvsJ
Submitted September 04, 2021 at 09:43PM by ant4g0nist
via reddit https://ift.tt/3h2895x
https://ift.tt/3tdnvsJ
Submitted September 04, 2021 at 09:43PM by ant4g0nist
via reddit https://ift.tt/3h2895x
fuzzing.science
Rudroid - Writing the World's worst Android Emulator in Rust 🦀
Introduction Rudroid - this might arguably be one of the worst Android emulators possible. In this blog, we’ll write an emulator that can run a ‘Hello World’ Android ELF binary. While doing this, we will learn how to go about writing our own emulators.
Writing…
Writing…
VED (Vault Exploit Defense): Protect the Linux kernel
https://ift.tt/2YqPCsZ
Submitted September 06, 2021 at 02:43PM by hardenedvault
via reddit https://ift.tt/3BN1Rym
https://ift.tt/2YqPCsZ
Submitted September 06, 2021 at 02:43PM by hardenedvault
via reddit https://ift.tt/3BN1Rym
reddit
VED (Vault Exploit Defense): Protect the Linux kernel
Posted in r/netsec by u/hardenedvault • 2 points and 0 comments
AppSec measurements are riddled with vanity metrics that don't tell us much. The latest edition talks about metrics that may work.
https://ift.tt/3BMHGAJ
Submitted September 06, 2021 at 07:30PM by jubbaonjeans
via reddit https://ift.tt/3h9klkZ
https://ift.tt/3BMHGAJ
Submitted September 06, 2021 at 07:30PM by jubbaonjeans
via reddit https://ift.tt/3h9klkZ
Substack
Edition 6: Top 4 AppSec metrics and why they are so hard to measure
You can't improve what you cannot measure, but measuring incorrectly can drive incentives in the wrong direction. Here's a hypothesis on "good" AppSec metrics and why they are so hard to measure.
GitHub - duc-nt/RCE-0-day-for-GhostScript-9.50: RCE 0-day for GhostScript 9.50 - Payload generator
https://ift.tt/3jOfk36
Submitted September 06, 2021 at 09:56PM by AffectionateOrchid10
via reddit https://ift.tt/38LsgAk
https://ift.tt/3jOfk36
Submitted September 06, 2021 at 09:56PM by AffectionateOrchid10
via reddit https://ift.tt/38LsgAk
GitHub
GitHub - duc-nt/RCE-0-day-for-GhostScript-9.50: RCE 0-day for GhostScript 9.50 - Payload generator
RCE 0-day for GhostScript 9.50 - Payload generator - duc-nt/RCE-0-day-for-GhostScript-9.50
A personal blog post on open redirect vulnerabilities - why it's bad, examples of vulnerable sites (including one now fixed on the UK's NCSC website), and prevention and detection (example Sigma rule!) advice
https://ift.tt/3yQqCrJ
Submitted September 07, 2021 at 07:26PM by O726564646974
via reddit https://ift.tt/3n7RzVF
https://ift.tt/3yQqCrJ
Submitted September 07, 2021 at 07:26PM by O726564646974
via reddit https://ift.tt/3n7RzVF
OllieJC
Open Redirect Vulnerability
This post is about open redirect vulnerabilities; the story of three vulnerable websites, why it’s bad, and how to prevent and detect abuse. First, a primer…
Behind BTHPORT.SYS
https://ift.tt/38OnCSg
Submitted September 08, 2021 at 03:29AM by lazybind
via reddit https://ift.tt/3zWWaxp
https://ift.tt/38OnCSg
Submitted September 08, 2021 at 03:29AM by lazybind
via reddit https://ift.tt/3zWWaxp
Blogspot
Behind BTHPORT.SYS
Paving the way for 0days Dedicated to: Zix , who spent precious-time guiding me within the last two-months . Mohammed , Jalil , Zakariae ...
SSTI vulnerability blog post
https://ift.tt/2X3rlIE
Submitted September 08, 2021 at 11:42AM by ndireddit
via reddit https://ift.tt/3tnWbI9
https://ift.tt/2X3rlIE
Submitted September 08, 2021 at 11:42AM by ndireddit
via reddit https://ift.tt/3tnWbI9
Atos
Server-Side Template Injection
Templates are pre-formatted documents, which already contain certain information. A template engine is a specific kind of template processing module that exhibits all major features of a modern programming language. The developers make use of Template engines…
Khepri: open source Cobalt Strike-like post-exploitation tool written in Golang and C++
https://ift.tt/3l0Fqzb
Submitted September 08, 2021 at 12:04PM by 0xdea
via reddit https://ift.tt/3BRHP5X
https://ift.tt/3l0Fqzb
Submitted September 08, 2021 at 12:04PM by 0xdea
via reddit https://ift.tt/3BRHP5X
GitHub
GitHub - geemion/Khepri: Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++. - GitHub - geemion/Khepri: Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang a...
Critical Exchange Vulnerability: Quick Grab on Detection & Mitigation
https://ift.tt/2X3u45q
Submitted September 08, 2021 at 11:57AM by ndireddit
via reddit https://ift.tt/3DQIExP
https://ift.tt/2X3u45q
Submitted September 08, 2021 at 11:57AM by ndireddit
via reddit https://ift.tt/3DQIExP
Atos
Critical Exchange Vulnerability: Quick Grab on Detection & Mitigation
Microsoft has detected multiple zero-day exploits on the on-premises version of the Microsoft Exchange Server (2013,2016, and 2019). Microsoft attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out…
CVE-2021-40346 - Integer Overflow leads to HTTP Smuggling in HAProxy
https://ift.tt/38P8yUd
Submitted September 08, 2021 at 05:06PM by SRMish3
via reddit https://ift.tt/3zWb0UP
https://ift.tt/38P8yUd
Submitted September 08, 2021 at 05:06PM by SRMish3
via reddit https://ift.tt/3zWb0UP
JFrog
Critical vulnerability in HAProxy | JFrog Security Research Team
JFrog security research team discovers new critical vulnerability (CVE-2021-40346) in HAProxy. The new vulnerability can be exploited for HTTP Request Smuggling attacks.
Arris Cable Modem Teardown
https://ift.tt/3BVIXFw
Submitted September 08, 2021 at 08:43PM by dinobyt3s
via reddit https://ift.tt/2X1WeNE
https://ift.tt/3BVIXFw
Submitted September 08, 2021 at 08:43PM by dinobyt3s
via reddit https://ift.tt/2X1WeNE
Medium
ARRIS CABLE MODEM TEARDOWN
Picked up one of these a little while back at the behest of a good friend…