Good attacks make good detections make good attacks (a MySQL booby-trap)
https://ift.tt/3jV3Qe5
Submitted September 09, 2021 at 10:23AM by thinkst
via reddit https://ift.tt/3tv4h1J
https://ift.tt/3jV3Qe5
Submitted September 09, 2021 at 10:23AM by thinkst
via reddit https://ift.tt/3tv4h1J
Thinkst Thoughts
Good attacks make good detections make good attacks make..
(The making of a MySQL Canarytoken) tl;dr Consider this scenario: An industrious attacker lands on one of your servers and finds a 5MB MySQL dump file (say, called prod_primary.dump). What do they …
ZDI-21-1053: Bypassing Windows Lock Screen
https://ift.tt/3tszsLd
Submitted September 09, 2021 at 11:12AM by 0xdea
via reddit https://ift.tt/3BUqGsu
https://ift.tt/3tszsLd
Submitted September 09, 2021 at 11:12AM by 0xdea
via reddit https://ift.tt/3BUqGsu
Blogspot
ZDI-21-1053: Bypassing Windows Lock Screen
In April 2021, I discovered a security flaw in Windows Recovery Environment Agent which allowed an unauthenticated attacker to gain elevat...
Introduction to OWASP Top 10 2021
https://ift.tt/3DYBY0q
Submitted September 09, 2021 at 01:07PM by Fugitif
via reddit https://ift.tt/2YH7boT
https://ift.tt/3DYBY0q
Submitted September 09, 2021 at 01:07PM by Fugitif
via reddit https://ift.tt/2YH7boT
owasp.org
OWASP Top 10
OWASP Top 10 2021 Draft
Mēris botnet, climbing to the record RPS DDoS attack
https://ift.tt/3nhOVwI
Submitted September 09, 2021 at 02:58PM by shapelez
via reddit https://ift.tt/3BVUvZK
https://ift.tt/3nhOVwI
Submitted September 09, 2021 at 02:58PM by shapelez
via reddit https://ift.tt/3BVUvZK
blog.qrator.net
Blog — Mēris botnet, climbing to the record
End of June 2021, Qrator Labs started to see signs of a new assaulting force on the Internet – a botnet of a new kind. That is a joint research we conducted together with Yandex to elaborate on the specifics of the DDoS attacks enabler emerging in almost…
IAM Vulnerable - An AWS IAM Privilege Escalation Playground
https://ift.tt/3zXHEpd
Submitted September 09, 2021 at 09:35PM by breach_house
via reddit https://ift.tt/3ldaGuT
https://ift.tt/3zXHEpd
Submitted September 09, 2021 at 09:35PM by breach_house
via reddit https://ift.tt/3ldaGuT
Bishop Fox
IAM Vulnerable Identify IAM misconfigurations
IAM Vulnerable is an open-source tool designed to help penetration testers better understand how to identify and exploit misconfigurations. Get the tool!
Microsoft CMMC Acceleration Program Update – September 2021
https://ift.tt/3BW6CWG
Submitted September 09, 2021 at 09:47PM by SM2548
via reddit https://ift.tt/3jZDTdr
https://ift.tt/3BW6CWG
Submitted September 09, 2021 at 09:47PM by SM2548
via reddit https://ift.tt/3jZDTdr
TECHCOMMUNITY.MICROSOFT.COM
Microsoft CMMC Acceleration Program Update – September 2021
We are actively building out our program by developing resources for both partners and Defense Industrial Base (DIB) companies to leverage in their Cybersecurity Maturity Model Certification (CMMC) journey. These tools cannot guarantee a positive CMMC adjudication…
Azurescape - cross-account container takeover in Azure Container Instances
https://ift.tt/2X8ONVt
Submitted September 10, 2021 at 12:17PM by YuvalAvra
via reddit https://ift.tt/3yUQQJv
https://ift.tt/2X8ONVt
Submitted September 10, 2021 at 12:17PM by YuvalAvra
via reddit https://ift.tt/3yUQQJv
Unit 42
Finding Azurescape – Cross-Account Container Takeover in Azure Container Instances
Affecting Azure Container Instances, Azurescape is the first known cross-account container takeover in the public cloud.
Frida 15.1 is out with brand new Swift support
https://ift.tt/3E0lk0F
Submitted September 10, 2021 at 10:39PM by oleavr
via reddit https://ift.tt/3E8cRZm
https://ift.tt/3E0lk0F
Submitted September 10, 2021 at 10:39PM by oleavr
via reddit https://ift.tt/3E8cRZm
Frida • A world-class dynamic instrumentation framework
Frida 15.1 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
CVE-2021-40444 - 0day Affecting MSHTML Engine Leading to RCE via Crafted Microsoft Office or RTF File
https://ift.tt/3BWxjdD
Submitted September 10, 2021 at 11:09PM by quantum_noodle_soup
via reddit https://ift.tt/3yZqKFu
https://ift.tt/3BWxjdD
Submitted September 10, 2021 at 11:09PM by quantum_noodle_soup
via reddit https://ift.tt/3yZqKFu
Huntress
Threat Advisory: Hackers Are Exploiting CVE-2021-40444
Huntress is monitoring a new threat against Windows OS and Microsoft Office products (CVE-2021-40444). The MSHTML engine is vulnerable to arbitrary code execution.
Malicious docx generator to exploit CVE-2021-40444
https://ift.tt/3ho1lzg
Submitted September 11, 2021 at 02:51PM by 0xDangerous_bit
via reddit https://ift.tt/2X3r8p3
https://ift.tt/3ho1lzg
Submitted September 11, 2021 at 02:51PM by 0xDangerous_bit
via reddit https://ift.tt/2X3r8p3
GitHub
GitHub - lockedbyte/CVE-2021-40444: CVE-2021-40444 PoC
CVE-2021-40444 PoC. Contribute to lockedbyte/CVE-2021-40444 development by creating an account on GitHub.
Kerberos cheatsheet
https://ift.tt/32ejzcC
Submitted September 11, 2021 at 11:44PM by CuteCancel5438
via reddit https://ift.tt/2YHPchX
https://ift.tt/32ejzcC
Submitted September 11, 2021 at 11:44PM by CuteCancel5438
via reddit https://ift.tt/2YHPchX
Gist
A cheatsheet with commands that can be used to perform kerberos attacks
A cheatsheet with commands that can be used to perform kerberos attacks - kerberos_attacks_cheatsheet.md
Windows & Active Directory Exploitation Cheat Sheet and Command Reference - Cas van Cooten
https://ift.tt/38usbBi
Submitted September 12, 2021 at 11:23AM by CuteCancel5438
via reddit https://ift.tt/3nxqdbs
https://ift.tt/38usbBi
Submitted September 12, 2021 at 11:23AM by CuteCancel5438
via reddit https://ift.tt/3nxqdbs
Casvancooten
Windows & Active Directory Exploitation Cheat Sheet and Command Reference
Last update: November 3rd, 2021
Updated November 3rd, 2021: Included several fixes and actualized some techniques. Changes made to the Defender evasion, RBCD, Domain Enumeration, Rubeus, and Mimikatz sections. Fixed some whoopsies as well 🙃.
Updated June…
Updated November 3rd, 2021: Included several fixes and actualized some techniques. Changes made to the Defender evasion, RBCD, Domain Enumeration, Rubeus, and Mimikatz sections. Fixed some whoopsies as well 🙃.
Updated June…
Scaling AppSec programs is hard. Leveraging existing systems/initiatives from the rest of the org can help
https://ift.tt/2XlG9D3
Submitted September 12, 2021 at 03:18PM by jubbaonjeans
via reddit https://ift.tt/38ZjUoC
https://ift.tt/2XlG9D3
Submitted September 12, 2021 at 03:18PM by jubbaonjeans
via reddit https://ift.tt/38ZjUoC
Boring AppSec
Edition 7: Using force multipliers to scale AppSec programs
AppSec programs are hard to scale. What works for a portfolio of 10 applications don't work for 1000 apps. Piggybacking off existing organizational programs can super charge your AppSec journey.
BazarLoader to Conti Ransomware in 32 Hours - In July we witnessed a BazarLoader campaign that deployed Cobalt Strike and ended with domain wide encryption using Conti ransomware.
https://ift.tt/38Z6PMa
Submitted September 13, 2021 at 06:00AM by TheDFIRReport
via reddit https://ift.tt/390v6Bo
https://ift.tt/38Z6PMa
Submitted September 13, 2021 at 06:00AM by TheDFIRReport
via reddit https://ift.tt/390v6Bo
The DFIR Report
BazarLoader to Conti Ransomware in 32 Hours
Intro Conti is a top player in the ransomware ecosystem, being listed as 2nd overall in the Q2 2021 Coveware ransomware report. The groups deploying this RaaS have only grown more prevalent. Despit…
Release dirsearch v0.4.2 - Web Path Scanner
https://ift.tt/3EdJTY7
Submitted September 13, 2021 at 09:55AM by maurosoria
via reddit https://ift.tt/392Skag
https://ift.tt/3EdJTY7
Submitted September 13, 2021 at 09:55AM by maurosoria
via reddit https://ift.tt/392Skag
North Korean Hacker Recently Employed Social Media to Launch a Cyberattack
https://ift.tt/3lhI2sy
Submitted September 13, 2021 at 12:34PM by george-alexander2k
via reddit https://ift.tt/3npyFtx
https://ift.tt/3lhI2sy
Submitted September 13, 2021 at 12:34PM by george-alexander2k
via reddit https://ift.tt/3npyFtx
VaultFuzzer: A state-based approach for Linux kernel
https://ift.tt/3E6XUGZ
Submitted September 13, 2021 at 05:57PM by hardenedvault
via reddit https://ift.tt/3AaMYWh
https://ift.tt/3E6XUGZ
Submitted September 13, 2021 at 05:57PM by hardenedvault
via reddit https://ift.tt/3AaMYWh
Frans Rosen does it again: "Hacking CloudKit - How I accidentally deleted your Apple Shortcuts"
https://ift.tt/3k4IiLV
Submitted September 13, 2021 at 07:47PM by intheclairdelune
via reddit https://ift.tt/38ZPzXj
https://ift.tt/3k4IiLV
Submitted September 13, 2021 at 07:47PM by intheclairdelune
via reddit https://ift.tt/38ZPzXj
Vermilion Strike: Linux and Windows Re-implementation of Cobalt Strike
https://ift.tt/3hoOJYA
Submitted September 13, 2021 at 10:47PM by notemaker
via reddit https://ift.tt/3A7L6xG
https://ift.tt/3hoOJYA
Submitted September 13, 2021 at 10:47PM by notemaker
via reddit https://ift.tt/3A7L6xG
Easily Exploitable Critical Vulnerability in ProfilePress Plugin of WordPress CVE-2021-34621
https://ift.tt/3lnFV6j
Submitted September 13, 2021 at 10:44PM by SL7reach
via reddit https://ift.tt/2XduaHx
https://ift.tt/3lnFV6j
Submitted September 13, 2021 at 10:44PM by SL7reach
via reddit https://ift.tt/2XduaHx
Penetration Testing and CyberSecurity Solution - SecureLayer7
Easily Exploitable Critical Vulnerability in ProfilePress Plugin of WordPress CVE-2021-34621
Understanding the Vulnerability ProfilePress, formerly WP User Avatar, a WordPress plugin installed on over 400,000 sites made it possible for an attacker to upload arbitrary files to a vulnerable site and register as an administrator on sites even if user…
Account Persistence – Certificates
https://ift.tt/3C98XO8
Submitted September 14, 2021 at 12:33AM by netbiosX
via reddit https://ift.tt/3919Dsc
https://ift.tt/3C98XO8
Submitted September 14, 2021 at 12:33AM by netbiosX
via reddit https://ift.tt/3919Dsc
Penetration Testing Lab
Account Persistence – Certificates
It is not uncommon organizations to implement an internal certification authority in order to establish trust between entities (users, computers etc.) or utilize it for user authentication. Impleme…