An Intro to Fuzzing (AKA Fuzz Testing)
https://ift.tt/3FfmWUT
Submitted October 05, 2021 at 01:42AM by breach_house
via reddit https://ift.tt/3l9GVMM
https://ift.tt/3FfmWUT
Submitted October 05, 2021 at 01:42AM by breach_house
via reddit https://ift.tt/3l9GVMM
Bishop Fox
Fuzz Testing for blackbox security analysis
Learn about fuzzing testing, including who should fuzz, what types of fuzzers exist, how to write a good harness to perform blackbox analysis on a given program.
Creating an IoT botnet of IPTVs to rickroll 10,000+ students
https://ift.tt/3l7XjNC
Submitted October 05, 2021 at 02:41AM by WhiteHoodHacker
via reddit https://ift.tt/3l9wn07
https://ift.tt/3l7XjNC
Submitted October 05, 2021 at 02:41AM by WhiteHoodHacker
via reddit https://ift.tt/3l9wn07
Protect Your GitHub Actions with Semgrep
https://ift.tt/2WLEXsA
Submitted October 05, 2021 at 06:26AM by iterablewords
via reddit https://ift.tt/3ivZuc6
https://ift.tt/2WLEXsA
Submitted October 05, 2021 at 06:26AM by iterablewords
via reddit https://ift.tt/3ivZuc6
r2c.dev
r2c blog — Protect Your GitHub Actions with Semgrep
Semgrep rules for GitHub Actions
Update: Facebook, Instagram And WhatsApp Go Down Hard In Possible Whistleblower DDoS Backlash
https://ift.tt/3acowbz
Submitted October 05, 2021 at 10:20AM by kayeT16
via reddit https://ift.tt/2WFqVbJ
https://ift.tt/3acowbz
Submitted October 05, 2021 at 10:20AM by kayeT16
via reddit https://ift.tt/2WFqVbJ
HotHardware
Update: Facebook, Instagram And WhatsApp Go Down Hard In Possible Whistleblower DDoS Backlash
It’s widely reported worldwide that Facebook, WhatsApp, and Instagram are down at the moment.
Practical strategies for pentesting and exploiting file read vulnerabilities.
https://ift.tt/3a71Aup
Submitted October 05, 2021 at 12:00PM by portmapper
via reddit https://ift.tt/3abZhWQ
https://ift.tt/3a71Aup
Submitted October 05, 2021 at 12:00PM by portmapper
via reddit https://ift.tt/3abZhWQ
Medium
Practical strategies for exploiting FILE READ vulnerabilities
Techniques for pentesting and exploiting file read conditions in web applications, also with a pinch of recommendations for…
TEQNIX - I made an online platform of pentesting tools and automation. Check it out and let me know
https://teqnix.io
Submitted October 05, 2021 at 12:10PM by maudits
via reddit https://ift.tt/3adRc3X
https://teqnix.io
Submitted October 05, 2021 at 12:10PM by maudits
via reddit https://ift.tt/3adRc3X
Swimming Upstream: Uncovering Broadcom SDK Vulnerabilities from Bug Reports.
https://ift.tt/3BbsehO
Submitted October 05, 2021 at 02:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/3iAT0sv
https://ift.tt/3BbsehO
Submitted October 05, 2021 at 02:08PM by g_e_r_h_a_r_d
via reddit https://ift.tt/3iAT0sv
IoT Inspector
Swimming Upstream: Uncovering Broadcom SDK vulnerabilities from bug reports - IoT Inspector
IoT Inspector identified security vulnerabilities affecting the UPnP implementation of Broadcom’s SDK that affect vendors such as Cisco or Linksys.
Abusing vCenter SAML Certificates: Logging in as Admin from Backups
https://ift.tt/3msyr2y
Submitted October 05, 2021 at 04:26PM by scopedsecurity
via reddit https://ift.tt/2ZZuE5m
https://ift.tt/3msyr2y
Submitted October 05, 2021 at 04:26PM by scopedsecurity
via reddit https://ift.tt/2ZZuE5m
GitHub
GitHub - horizon3ai/vcenter_saml_login: A tool to extract the IdP cert from vCenter backups and log in as Administrator
A tool to extract the IdP cert from vCenter backups and log in as Administrator - horizon3ai/vcenter_saml_login
23andMe’s Yamale Python code injection, and properly sanitizing eval()
https://ift.tt/3A7k7S5
Submitted October 05, 2021 at 07:28PM by SRMish3
via reddit https://ift.tt/3uLSFbh
https://ift.tt/3A7k7S5
Submitted October 05, 2021 at 07:28PM by SRMish3
via reddit https://ift.tt/3uLSFbh
JFrog
Newly discovered code injection vulnerability in Yamale
Yamale, schema validator for YAML files. Attackers can bypass security and run arbitrary code. See the details, fix and recommendations from the JFrog security team.
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 (CVE-2021-41773)
https://ift.tt/3yRVc5s
Submitted October 05, 2021 at 08:01PM by Gallus
via reddit https://ift.tt/3BcGtCQ
https://ift.tt/3yRVc5s
Submitted October 05, 2021 at 08:01PM by Gallus
via reddit https://ift.tt/3BcGtCQ
httpd.apache.org
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Phrack 70
https://ift.tt/3A6Cx5m
Submitted October 05, 2021 at 09:29PM by mateusnr
via reddit https://ift.tt/3laFQE9
https://ift.tt/3A6Cx5m
Submitted October 05, 2021 at 09:29PM by mateusnr
via reddit https://ift.tt/3laFQE9
reddit
Phrack 70
Posted in r/netsec by u/mateusnr • 237 points and 14 comments
r2flutch: Yet another tool to decrypt iOS apps using r2frida
https://ift.tt/3itQRyT
Submitted October 05, 2021 at 09:58PM by Titokhan
via reddit https://ift.tt/3Bj80Te
https://ift.tt/3itQRyT
Submitted October 05, 2021 at 09:58PM by Titokhan
via reddit https://ift.tt/3Bj80Te
GitHub
GitHub - as0ler/r2flutch: Tool to decrypt iOS apps using r2frida
Tool to decrypt iOS apps using r2frida. Contribute to as0ler/r2flutch development by creating an account on GitHub.
Even Censors Have a Backup: Examining China’s Double HTTPS Censorship Middleboxes
https://ift.tt/3lai0Zg
Submitted October 05, 2021 at 02:17AM by dontbenebby
via reddit https://ift.tt/3uHR0DC
https://ift.tt/3lai0Zg
Submitted October 05, 2021 at 02:17AM by dontbenebby
via reddit https://ift.tt/3uHR0DC
Decoding AT&T's Proactive SIM
https://ift.tt/3FjZKoh
Submitted October 05, 2021 at 06:37PM by dburgess000
via reddit https://ift.tt/3uI9GmM
https://ift.tt/3FjZKoh
Submitted October 05, 2021 at 06:37PM by dburgess000
via reddit https://ift.tt/3uI9GmM
Medium
What is AT&T doing at 1111340002?
Welcome to the magical world of proactive SIMs.
Assessing the security and privacy of Vaccine Passports
https://ift.tt/3iuSUTl
Submitted October 05, 2021 at 10:54AM by digicat
via reddit https://ift.tt/3oxJ1YT
https://ift.tt/3iuSUTl
Submitted October 05, 2021 at 10:54AM by digicat
via reddit https://ift.tt/3oxJ1YT
NCC Group Research
Assessing the security and privacy of Vaccine Passports
This post attempts to explore the security and privacy concerns related with vaccine credential systems, by way of threat modelling and exploring the various risks and attacks conceivable against such systems.... Furthermore, we'll look at these concerns…
S0cm0nkey's Reference Guide - OSINT and Passive Recon
https://ift.tt/3leYcEm
Submitted October 05, 2021 at 11:37PM by s0cm0nkey
via reddit https://ift.tt/2Yr5pII
https://ift.tt/3leYcEm
Submitted October 05, 2021 at 11:37PM by s0cm0nkey
via reddit https://ift.tt/2Yr5pII
s0cm0nkey.gitbook.io
OSINT | s0cm0nkey's Security Reference Guide
Open Source Intelligence
Correlate network connections with community ID in osquery.
https://ift.tt/3a9zoHh
Submitted October 06, 2021 at 04:22AM by Silly-Pop-7437
via reddit https://ift.tt/3BkgF7W
https://ift.tt/3a9zoHh
Submitted October 06, 2021 at 04:22AM by Silly-Pop-7437
via reddit https://ift.tt/3BkgF7W
Medium
Correlate network connections with community ID in osquery.
Interested in correlating events from network monitoring tools to host activity? Support for Community ID hashing in osquery allows osquery’s endpoint instrumentation to be easily correlated with…
Yet another PHP 7.0-8.0 disable_functions bypass 0day PoC
https://ift.tt/3DaieFS
Submitted October 06, 2021 at 09:42AM by dradzenglor
via reddit https://ift.tt/3uKvUV7
https://ift.tt/3DaieFS
Submitted October 06, 2021 at 09:42AM by dradzenglor
via reddit https://ift.tt/3uKvUV7
GitHub
exploits/php-filter-bypass at master · mm0r1/exploits
Pwn stuff. Contribute to mm0r1/exploits development by creating an account on GitHub.
Breakdown of a New Novel Exploit Using REBOL for Malicious Purposes
https://ift.tt/3Ac6mkR
Submitted October 06, 2021 at 07:44PM by FRSecure
via reddit https://ift.tt/3lepCKk
https://ift.tt/3Ac6mkR
Submitted October 06, 2021 at 07:44PM by FRSecure
via reddit https://ift.tt/3lepCKk
FRSecure
The REBOL Yell: A New Novel REBOL Exploit | FRSecure
We recently discovered a novel REBOL exploit technique used for command-and-control. We've coined this the REBOL Yell. Read about the exploit and preventing it.
GitOops! Attacking and defending CI/CD pipelines.
https://ift.tt/3CNIvJW
Submitted October 06, 2021 at 09:20PM by alexksak
via reddit https://ift.tt/3Bjc3z0
https://ift.tt/3CNIvJW
Submitted October 06, 2021 at 09:20PM by alexksak
via reddit https://ift.tt/3Bjc3z0
Running the Tpot honeypot on Google Cloud Platform - Part 1
https://ift.tt/3afOJGi
Submitted October 06, 2021 at 10:47PM by gamingalife
via reddit https://ift.tt/3Bizk45
https://ift.tt/3afOJGi
Submitted October 06, 2021 at 10:47PM by gamingalife
via reddit https://ift.tt/3Bizk45
blog.chy.la
Running the Tpot honeypot on Google Cloud Platform - Part 1
Deploying the Tpot honeypot on Google Cloud using Terraform