Beginners Guide to 0day/CVE AppSec Research
https://ift.tt/3hAHrBd
Submitted September 22, 2021 at 02:59AM by 0xdea
via reddit https://ift.tt/2VXZSrM
https://ift.tt/3hAHrBd
Submitted September 22, 2021 at 02:59AM by 0xdea
via reddit https://ift.tt/2VXZSrM
Boku
Beginners Guide to 0day/CVE AppSec Research
Apache Dubbo: All roads lead to RCE
https://ift.tt/2XyQv2r
Submitted September 22, 2021 at 02:41AM by 0xdea
via reddit https://ift.tt/3nRFCDS
https://ift.tt/2XyQv2r
Submitted September 22, 2021 at 02:41AM by 0xdea
via reddit https://ift.tt/3nRFCDS
Software Supply Chain Security - Implementing Google's SLSA Framework and CNCF's Best Practices
https://ift.tt/3nWbJlW
Submitted September 22, 2021 at 08:14AM by garantir
via reddit https://ift.tt/2XH3E9K
https://ift.tt/3nWbJlW
Submitted September 22, 2021 at 08:14AM by garantir
via reddit https://ift.tt/2XH3E9K
When GoDaddy Fell to Social Engineering
https://ift.tt/2ZnonA7
Submitted September 22, 2021 at 05:44PM by endless
via reddit https://ift.tt/3lQK42T
https://ift.tt/2ZnonA7
Submitted September 22, 2021 at 05:44PM by endless
via reddit https://ift.tt/3lQK42T
Livejournal
When GoDaddy fell to Social Engineering
Back in 2007 my buddy [redacted] wanted to buy the domain name fucktube.com as we were adult webmasters at the time. He was out of luck. A quick WHOIS search revealed that "fucktube.com" had already been registered on GoDaddy. This was at a time when *tube…
High-Severity RCE Vulnerability Found in Several Netgear Routers
https://ift.tt/3CAzF27
Submitted September 22, 2021 at 06:29PM by george-alexander2k
via reddit https://ift.tt/3AwOtOB
https://ift.tt/3CAzF27
Submitted September 22, 2021 at 06:29PM by george-alexander2k
via reddit https://ift.tt/3AwOtOB
I’m not putting a WiFi router into a phone charger (Part 3)
https://ift.tt/2XGEJml
Submitted September 23, 2021 at 12:54AM by Machinehum
via reddit https://ift.tt/2XGEAiN
https://ift.tt/2XGEJml
Submitted September 23, 2021 at 12:54AM by Machinehum
via reddit https://ift.tt/2XGEAiN
Medium
I’m not putting a WiFi router into a phone charger (Part 3)
This is the fourth installment about designing a WiFi router into a phone charger for security, pentesting and red teaming; (part zero…
Catching the big fish: Analyzing a large-scale phishing-as-a-service operation
https://ift.tt/3lNpiRP
Submitted September 23, 2021 at 04:31AM by SCI_Rusher
via reddit https://ift.tt/3ub0siD
https://ift.tt/3lNpiRP
Submitted September 23, 2021 at 04:31AM by SCI_Rusher
via reddit https://ift.tt/3ub0siD
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Resetting Expired Passwords Remotely
https://ift.tt/2ZhSJ6V
Submitted September 23, 2021 at 04:28AM by scopedsecurity
via reddit https://ift.tt/3kxPYXB
https://ift.tt/2ZhSJ6V
Submitted September 23, 2021 at 04:28AM by scopedsecurity
via reddit https://ift.tt/3kxPYXB
www.n00py.io
Resetting an Expired Password Remotely
I've often found that while performing password guessing on a network, I'll find valid credentials, but the password will be expired. This presents a challenge, because the credentials are of limited use until they are reset. [crayon-62ffff147e8c4710256389/]…
Analysis of products made by Huawei, Xiaomi and OnePlus
https://ift.tt/3lOlQGF
Submitted September 23, 2021 at 12:43PM by AshamedRange
via reddit https://ift.tt/3EKpSIL
https://ift.tt/3lOlQGF
Submitted September 23, 2021 at 12:43PM by AshamedRange
via reddit https://ift.tt/3EKpSIL
The AOL Screen Name Exploit of 2000
https://ift.tt/3u5c7PR
Submitted September 23, 2021 at 03:14PM by endless
via reddit https://ift.tt/3AzVE93
https://ift.tt/3u5c7PR
Submitted September 23, 2021 at 03:14PM by endless
via reddit https://ift.tt/3AzVE93
Livejournal
The AOL Screen Name Exploit of 2000
I should start by saying that there were several AOL screen name exploits around that time, regime2k, etc. It was the golden age of AOL hacking, or "hacking" if you're an efnet elitist — but this exploit was different. It was skid treasure. I skipped school.…
Saved by the log: Building IR support into software design
https://ift.tt/3EUNtXx
Submitted September 23, 2021 at 04:34PM by TolgaDevSec
via reddit https://ift.tt/3kzhiVp
https://ift.tt/3EUNtXx
Submitted September 23, 2021 at 04:34PM by TolgaDevSec
via reddit https://ift.tt/3kzhiVp
F-Secure
Saved by the log: Building IR support into software design
Security Consultant Thomas Wearing and Incident Responder Jordan LaRose join forces to explore how developers might best build detective controls into their web apps.
Hacking DigitalGangster.com
https://ift.tt/39yIRrk
Submitted September 23, 2021 at 07:22PM by endless
via reddit https://ift.tt/3lOTaNW
https://ift.tt/39yIRrk
Submitted September 23, 2021 at 07:22PM by endless
via reddit https://ift.tt/3lOTaNW
Livejournal
Hacking DigitalGangster.com
In 2009 Dropcode and I hacked DG, a now defunct forum operated by nerdcore artist Why Tea? Cracker © '-' This was when DG was huge. 100K members huge. The timing was perfect. digitalgangster.com when it was cool YTC coded a php noscript called ` touruploader.php…
IAM Vulnerable - Assessing the AWS Assessment Tools
https://ift.tt/3zvgAg0
Submitted September 23, 2021 at 10:29PM by sethsec
via reddit https://ift.tt/3EVZXOy
https://ift.tt/3zvgAg0
Submitted September 23, 2021 at 10:29PM by sethsec
via reddit https://ift.tt/3EVZXOy
Bishop Fox
IAM Vulnerable Identify IAM misconfigurations
IAM Vulnerable is an open-source tool designed to help penetration testers better understand how to identify and exploit misconfigurations. Get the tool!
Need Help Developing this DoS Code using DNS Amplification Attacks
https://ift.tt/3ACugXU
Submitted September 23, 2021 at 11:12PM by entropydaemon3
via reddit https://ift.tt/2XGX6b9
https://ift.tt/3ACugXU
Submitted September 23, 2021 at 11:12PM by entropydaemon3
via reddit https://ift.tt/2XGX6b9
GitHub
GitHub - RoseSecurity/DNS-Fender: A Proof-of-Concept tool utilizing open DNS resolvers to produce an amplification attack against…
A Proof-of-Concept tool utilizing open DNS resolvers to produce an amplification attack against web servers. Using Shodan APIs and native Linux commands, this tool is in development to cripple web ...
Financially motivated actor breaks certificate parsing to avoid detection
https://ift.tt/3i0u5yt
Submitted September 23, 2021 at 11:44PM by digicat
via reddit https://ift.tt/3u3aaDK
https://ift.tt/3i0u5yt
Submitted September 23, 2021 at 11:44PM by digicat
via reddit https://ift.tt/3u3aaDK
Google
Financially motivated actor breaks certificate parsing to avoid detection
Financially motivatedt threat actor breaks certificate parsing to avoid detection
Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program
https://ift.tt/39uOy9X
Submitted September 24, 2021 at 05:19AM by illusionofchaos
via reddit https://ift.tt/2XMO2Sv
https://ift.tt/39uOy9X
Submitted September 24, 2021 at 05:19AM by illusionofchaos
via reddit https://ift.tt/2XMO2Sv
Habr
Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program
I want to share my frustrating experience participating in Apple Security Bounty program. I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are...
Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program
https://ift.tt/3i4bcuh
Submitted September 24, 2021 at 03:47PM by pimterry
via reddit https://ift.tt/3o54s3k
https://ift.tt/3i4bcuh
Submitted September 24, 2021 at 03:47PM by pimterry
via reddit https://ift.tt/3o54s3k
Habr
Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program
I want to share my frustrating experience participating in Apple Security Bounty program. I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are...
CVE-2021-39246 – Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack excessive verbose logging – Windows, macOS, Linux
https://ift.tt/3CMCJIu
Submitted September 24, 2021 at 10:46PM by docker-osx
via reddit https://ift.tt/2XYPX6r
https://ift.tt/3CMCJIu
Submitted September 24, 2021 at 10:46PM by docker-osx
via reddit https://ift.tt/2XYPX6r
Sick.Codes
CVE-2021-39246 – Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack excessive verbose logging – Windows…
Title CVE-2021-39246 – Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack excessive verbose logging – Windows, macOS, Linux CVE ID CVE-2021-39246 CVSS Score 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Internal ID SICK-2021…
Massive DDoS attacks on VoIP Providers and simulated DDoS testing
https://ift.tt/2XPkG5e
Submitted September 25, 2021 at 12:54AM by lormayna
via reddit https://ift.tt/2XKrT6X
https://ift.tt/2XPkG5e
Submitted September 25, 2021 at 12:54AM by lormayna
via reddit https://ift.tt/2XKrT6X
Hacking LG WebOS Smart TVs Using A Phone
https://ift.tt/3EQSkcc
Submitted September 25, 2021 at 05:39PM by banginpadr
via reddit https://ift.tt/3ET1k0c
https://ift.tt/3EQSkcc
Submitted September 25, 2021 at 05:39PM by banginpadr
via reddit https://ift.tt/3ET1k0c
Medium
Hacking LG WebOS Smart TVs Using A Phone
Exploiting smart TVs.
Monitor: Autodiscover credential leak risk by TLD
https://ift.tt/3EQy8qO
Submitted September 26, 2021 at 12:44AM by tasinet
via reddit https://ift.tt/3AW8BKB
https://ift.tt/3EQy8qO
Submitted September 26, 2021 at 12:44AM by tasinet
via reddit https://ift.tt/3AW8BKB