Behind BTHPORT.SYS
https://ift.tt/38OnCSg
Submitted September 08, 2021 at 03:29AM by lazybind
via reddit https://ift.tt/3zWWaxp
https://ift.tt/38OnCSg
Submitted September 08, 2021 at 03:29AM by lazybind
via reddit https://ift.tt/3zWWaxp
Blogspot
Behind BTHPORT.SYS
Paving the way for 0days Dedicated to: Zix , who spent precious-time guiding me within the last two-months . Mohammed , Jalil , Zakariae ...
SSTI vulnerability blog post
https://ift.tt/2X3rlIE
Submitted September 08, 2021 at 11:42AM by ndireddit
via reddit https://ift.tt/3tnWbI9
https://ift.tt/2X3rlIE
Submitted September 08, 2021 at 11:42AM by ndireddit
via reddit https://ift.tt/3tnWbI9
Atos
Server-Side Template Injection
Templates are pre-formatted documents, which already contain certain information. A template engine is a specific kind of template processing module that exhibits all major features of a modern programming language. The developers make use of Template engines…
Khepri: open source Cobalt Strike-like post-exploitation tool written in Golang and C++
https://ift.tt/3l0Fqzb
Submitted September 08, 2021 at 12:04PM by 0xdea
via reddit https://ift.tt/3BRHP5X
https://ift.tt/3l0Fqzb
Submitted September 08, 2021 at 12:04PM by 0xdea
via reddit https://ift.tt/3BRHP5X
GitHub
GitHub - geemion/Khepri: Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++.
Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang and C++. - GitHub - geemion/Khepri: Free,Open-Source,Cross-platform agent and Post-exploiton tool written in Golang a...
Critical Exchange Vulnerability: Quick Grab on Detection & Mitigation
https://ift.tt/2X3u45q
Submitted September 08, 2021 at 11:57AM by ndireddit
via reddit https://ift.tt/3DQIExP
https://ift.tt/2X3u45q
Submitted September 08, 2021 at 11:57AM by ndireddit
via reddit https://ift.tt/3DQIExP
Atos
Critical Exchange Vulnerability: Quick Grab on Detection & Mitigation
Microsoft has detected multiple zero-day exploits on the on-premises version of the Microsoft Exchange Server (2013,2016, and 2019). Microsoft attributes this campaign with high confidence to HAFNIUM, a group assessed to be state-sponsored and operating out…
CVE-2021-40346 - Integer Overflow leads to HTTP Smuggling in HAProxy
https://ift.tt/38P8yUd
Submitted September 08, 2021 at 05:06PM by SRMish3
via reddit https://ift.tt/3zWb0UP
https://ift.tt/38P8yUd
Submitted September 08, 2021 at 05:06PM by SRMish3
via reddit https://ift.tt/3zWb0UP
JFrog
Critical vulnerability in HAProxy | JFrog Security Research Team
JFrog security research team discovers new critical vulnerability (CVE-2021-40346) in HAProxy. The new vulnerability can be exploited for HTTP Request Smuggling attacks.
Arris Cable Modem Teardown
https://ift.tt/3BVIXFw
Submitted September 08, 2021 at 08:43PM by dinobyt3s
via reddit https://ift.tt/2X1WeNE
https://ift.tt/3BVIXFw
Submitted September 08, 2021 at 08:43PM by dinobyt3s
via reddit https://ift.tt/2X1WeNE
Medium
ARRIS CABLE MODEM TEARDOWN
Picked up one of these a little while back at the behest of a good friend…
CVE-2021-31698 - Code execution as root via AT commands on the Quectel EG25-G modem
https://ift.tt/3yUVCqr
Submitted September 08, 2021 at 09:16PM by crower
via reddit https://ift.tt/3naKMKV
https://ift.tt/3yUVCqr
Submitted September 08, 2021 at 09:16PM by crower
via reddit https://ift.tt/3naKMKV
nns.ee
Code execution as root via AT commands on the Quectel EG25-G modem
As I mentioned towards the end of my previous blog post, where I detailed running my blog on the PinePhone's GSM/WWAN/GPS modem, I suspected that the daemon ...
AWSXenos will detect and classify all the cross account trust relationships in all the IAM roles and S3 buckets, in you AWS Account.
https://ift.tt/38RW1iO
Submitted September 08, 2021 at 09:09PM by _skynet
via reddit https://ift.tt/2VqnhSB
https://ift.tt/38RW1iO
Submitted September 08, 2021 at 09:09PM by _skynet
via reddit https://ift.tt/2VqnhSB
GitHub
GitHub - AirWalk-Digital/AWSXenos: AWSXenos will list all the trust relationships in all the IAM roles, S3 buckets, and more
AWSXenos will list all the trust relationships in all the IAM roles, S3 buckets, and more - AirWalk-Digital/AWSXenos
Operational Mental Models - Jackson T
https://ift.tt/3hbXcy4
Submitted September 08, 2021 at 10:25PM by WM-M-GM
via reddit https://ift.tt/3jTLx91
https://ift.tt/3hbXcy4
Submitted September 08, 2021 at 10:25PM by WM-M-GM
via reddit https://ift.tt/3jTLx91
Why Rust for offensive security
https://ift.tt/2X5KYAq
Submitted September 08, 2021 at 10:42PM by z0mbie42_
via reddit https://ift.tt/3BTH6Bq
https://ift.tt/2X5KYAq
Submitted September 08, 2021 at 10:42PM by z0mbie42_
via reddit https://ift.tt/3BTH6Bq
Kerkour
Why Rust for offensive security
Imagine: all the tanks of your army are made of cardboard. Now imagine that not only your tanks but also all your airforce is composed of paper planes and your navy of paper vessels. It would be a pretty bad situation, don’t you think?
While it sounds absurd…
While it sounds absurd…
Muhstik Takes Aim at Confluence CVE 2021-26084
https://ift.tt/3l5shEU
Submitted September 09, 2021 at 01:47AM by DLLCoolJ
via reddit https://ift.tt/3tp14Rn
https://ift.tt/3l5shEU
Submitted September 09, 2021 at 01:47AM by DLLCoolJ
via reddit https://ift.tt/3tp14Rn
Lacework
Muhstik Takes Aim at Confluence CVE 2021-26084 - Lacework
Lacework Labs Team has observed a number of CVE 2021-26084 exploit attempts using the publicly available exploit code.
Vulnerability in check-spelling GitHub Actions community workflow could have allowed malicious code to be introduced to repos from Microsoft, Jekyll, NASA and PowerDNS
https://ift.tt/3nd2sW3
Submitted September 09, 2021 at 06:30AM by Gallus
via reddit https://ift.tt/2X1Th0e
https://ift.tt/3nd2sW3
Submitted September 09, 2021 at 06:30AM by Gallus
via reddit https://ift.tt/2X1Th0e
GitHub
advisories/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md at master · justinsteven/advisories
Contribute to justinsteven/advisories development by creating an account on GitHub.
Good attacks make good detections make good attacks (a MySQL booby-trap)
https://ift.tt/3jV3Qe5
Submitted September 09, 2021 at 10:23AM by thinkst
via reddit https://ift.tt/3tv4h1J
https://ift.tt/3jV3Qe5
Submitted September 09, 2021 at 10:23AM by thinkst
via reddit https://ift.tt/3tv4h1J
Thinkst Thoughts
Good attacks make good detections make good attacks make..
(The making of a MySQL Canarytoken) tl;dr Consider this scenario: An industrious attacker lands on one of your servers and finds a 5MB MySQL dump file (say, called prod_primary.dump). What do they …
ZDI-21-1053: Bypassing Windows Lock Screen
https://ift.tt/3tszsLd
Submitted September 09, 2021 at 11:12AM by 0xdea
via reddit https://ift.tt/3BUqGsu
https://ift.tt/3tszsLd
Submitted September 09, 2021 at 11:12AM by 0xdea
via reddit https://ift.tt/3BUqGsu
Blogspot
ZDI-21-1053: Bypassing Windows Lock Screen
In April 2021, I discovered a security flaw in Windows Recovery Environment Agent which allowed an unauthenticated attacker to gain elevat...
Introduction to OWASP Top 10 2021
https://ift.tt/3DYBY0q
Submitted September 09, 2021 at 01:07PM by Fugitif
via reddit https://ift.tt/2YH7boT
https://ift.tt/3DYBY0q
Submitted September 09, 2021 at 01:07PM by Fugitif
via reddit https://ift.tt/2YH7boT
owasp.org
OWASP Top 10
OWASP Top 10 2021 Draft
Mēris botnet, climbing to the record RPS DDoS attack
https://ift.tt/3nhOVwI
Submitted September 09, 2021 at 02:58PM by shapelez
via reddit https://ift.tt/3BVUvZK
https://ift.tt/3nhOVwI
Submitted September 09, 2021 at 02:58PM by shapelez
via reddit https://ift.tt/3BVUvZK
blog.qrator.net
Blog — Mēris botnet, climbing to the record
End of June 2021, Qrator Labs started to see signs of a new assaulting force on the Internet – a botnet of a new kind. That is a joint research we conducted together with Yandex to elaborate on the specifics of the DDoS attacks enabler emerging in almost…
IAM Vulnerable - An AWS IAM Privilege Escalation Playground
https://ift.tt/3zXHEpd
Submitted September 09, 2021 at 09:35PM by breach_house
via reddit https://ift.tt/3ldaGuT
https://ift.tt/3zXHEpd
Submitted September 09, 2021 at 09:35PM by breach_house
via reddit https://ift.tt/3ldaGuT
Bishop Fox
IAM Vulnerable Identify IAM misconfigurations
IAM Vulnerable is an open-source tool designed to help penetration testers better understand how to identify and exploit misconfigurations. Get the tool!
Microsoft CMMC Acceleration Program Update – September 2021
https://ift.tt/3BW6CWG
Submitted September 09, 2021 at 09:47PM by SM2548
via reddit https://ift.tt/3jZDTdr
https://ift.tt/3BW6CWG
Submitted September 09, 2021 at 09:47PM by SM2548
via reddit https://ift.tt/3jZDTdr
TECHCOMMUNITY.MICROSOFT.COM
Microsoft CMMC Acceleration Program Update – September 2021
We are actively building out our program by developing resources for both partners and Defense Industrial Base (DIB) companies to leverage in their Cybersecurity Maturity Model Certification (CMMC) journey. These tools cannot guarantee a positive CMMC adjudication…
Azurescape - cross-account container takeover in Azure Container Instances
https://ift.tt/2X8ONVt
Submitted September 10, 2021 at 12:17PM by YuvalAvra
via reddit https://ift.tt/3yUQQJv
https://ift.tt/2X8ONVt
Submitted September 10, 2021 at 12:17PM by YuvalAvra
via reddit https://ift.tt/3yUQQJv
Unit 42
Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances
Affecting Azure Container Instances, Azurescape is the first known cross-account container takeover in the public cloud.
Frida 15.1 is out with brand new Swift support
https://ift.tt/3E0lk0F
Submitted September 10, 2021 at 10:39PM by oleavr
via reddit https://ift.tt/3E8cRZm
https://ift.tt/3E0lk0F
Submitted September 10, 2021 at 10:39PM by oleavr
via reddit https://ift.tt/3E8cRZm
Frida • A world-class dynamic instrumentation framework
Frida 15.1 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
CVE-2021-40444 - 0day Affecting MSHTML Engine Leading to RCE via Crafted Microsoft Office or RTF File
https://ift.tt/3BWxjdD
Submitted September 10, 2021 at 11:09PM by quantum_noodle_soup
via reddit https://ift.tt/3yZqKFu
https://ift.tt/3BWxjdD
Submitted September 10, 2021 at 11:09PM by quantum_noodle_soup
via reddit https://ift.tt/3yZqKFu
Huntress
Threat Advisory: Hackers Are Exploiting CVE-2021-40444
Huntress is monitoring a new threat against Windows OS and Microsoft Office products (CVE-2021-40444). The MSHTML engine is vulnerable to arbitrary code execution.