Reverse engineering and decrypting CyberArk vault credential files
https://ift.tt/3FtKWUj
Submitted October 09, 2021 at 12:13AM by digicat
via reddit https://ift.tt/3iKbFlM
https://ift.tt/3FtKWUj
Submitted October 09, 2021 at 12:13AM by digicat
via reddit https://ift.tt/3iKbFlM
NCC Group Research
Reverse engineering and decrypting CyberArk vault credential files
This blog will be a technical deep-dive into CyberArk credential files and how the credentials stored in these files are encrypted and decrypted. I discovered it was possible to reverse engineer the encryption and key generation algorithms and decrypt the…
HOW TO DEFEAT THE RUSSIAN DUKES: A STEP-BY-STEP ANALYSIS OF MINIDUKE USED BY APT29/COZY BEAR
https://ift.tt/3BtFm1S
Submitted October 09, 2021 at 11:16PM by CyberMasterV
via reddit https://ift.tt/3ADky6Z
https://ift.tt/3BtFm1S
Submitted October 09, 2021 at 11:16PM by CyberMasterV
via reddit https://ift.tt/3ADky6Z
Made a small suite of tools for generating personalized wordlists for password attacks
https://ift.tt/2YAcNkx
Submitted October 10, 2021 at 02:06PM by antfigunio
via reddit https://ift.tt/2YyrzZo
https://ift.tt/2YAcNkx
Submitted October 10, 2021 at 02:06PM by antfigunio
via reddit https://ift.tt/2YyrzZo
reddit
Made a small suite of tools for generating personalized wordlists...
Posted in r/netsec by u/antfigunio • 163 points and 6 comments
Understanding CVE-2019-9053
https://ift.tt/3Dn7PH4
Submitted October 10, 2021 at 10:06PM by pythonpsycho1337
via reddit https://ift.tt/302nblV
https://ift.tt/3Dn7PH4
Submitted October 10, 2021 at 10:06PM by pythonpsycho1337
via reddit https://ift.tt/302nblV
CVE Analyses
CVE-2019-9053
Background This weekend I was doing some HTB machines to prepare for the OSWE certification. One of the recommended machines was Writeup. This machine is vulnerable to CVE-2019-9053 which has a corresponding exploit on Exploit-DB.
Trying something new. Starting today, will try and write a primer on SAST for the next 4 weeks. Today's edition is an overview of what SAST is and why need it.
https://ift.tt/3ltedqk
Submitted October 10, 2021 at 11:33PM by jubbaonjeans
via reddit https://ift.tt/2YzfxiP
https://ift.tt/3ltedqk
Submitted October 10, 2021 at 11:33PM by jubbaonjeans
via reddit https://ift.tt/2YzfxiP
Substack
Edition 11: AppSec Primer - SAST - Part 1
First in a four part primer on Static Application Security Testing (SAST). This edition talks about what SAST is and why it's needed.
Pithus: A free and open-source mobile threat intelligence platform
https://ift.tt/3FB0jdB
Submitted October 11, 2021 at 02:52PM by Titokhan
via reddit https://ift.tt/3DqM5dx
https://ift.tt/3FB0jdB
Submitted October 11, 2021 at 02:52PM by Titokhan
via reddit https://ift.tt/3DqM5dx
Reddit
From the netsec community on Reddit: Pithus: A free and open-source mobile threat intelligence platform
Posted by Titokhan - 164 votes and 0 comments
EDRHunt: Detect EDRs installed on Windows endpoints.
https://ift.tt/3AqOTp2
Submitted October 11, 2021 at 04:55PM by FourCoreLabs
via reddit https://ift.tt/2X1jLyK
https://ift.tt/3AqOTp2
Submitted October 11, 2021 at 04:55PM by FourCoreLabs
via reddit https://ift.tt/2X1jLyK
GitHub
GitHub - FourCoreLabs/EDRHunt: Scan installed EDRs and AVs on Windows
Scan installed EDRs and AVs on Windows. Contribute to FourCoreLabs/EDRHunt development by creating an account on GitHub.
GHSL-2021-1012: Poor random number generation in keypair - CVE-2021-41117
https://ift.tt/3BwMcnn
Submitted October 11, 2021 at 11:21PM by Photogurt
via reddit https://ift.tt/3oMiaIG
https://ift.tt/3BwMcnn
Submitted October 11, 2021 at 11:21PM by Photogurt
via reddit https://ift.tt/3oMiaIG
GitHub Security Lab
GHSL-2021-1012: Poor random number generation in keypair - CVE-2021-41117
keypair implements a lot of cryptographic primitives on its own or by borrowing from other libraries where possible, including node-forge. An issue was discovered where this library was generating identical RSA keys used in SSH. This would mean that the library…
How cyberattacks are changing according to new Microsoft Digital Defense Report
https://ift.tt/3mIKclD
Submitted October 12, 2021 at 02:01AM by SCI_Rusher
via reddit https://ift.tt/3AAGfnU
https://ift.tt/3mIKclD
Submitted October 12, 2021 at 02:01AM by SCI_Rusher
via reddit https://ift.tt/3AAGfnU
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Hacking YouTube with a MP4
https://ift.tt/3oSA2l2
Submitted October 12, 2021 at 09:08AM by Gallus
via reddit https://ift.tt/3oT39oz
https://ift.tt/3oSA2l2
Submitted October 12, 2021 at 09:08AM by Gallus
via reddit https://ift.tt/3oT39oz
realkeyboardwarrior.github.io
Keyboard Warrior - Breaking software is just finding unintended features, right?
Keyboard Warrior, Breaking software is just finding unintended features, right?
Relational databases aren’t dinosaurs, they’re sharks
https://ift.tt/3s3Is92
Submitted October 12, 2021 at 01:50PM by thetughum
via reddit https://ift.tt/3v1vCtk
https://ift.tt/3s3Is92
Submitted October 12, 2021 at 01:50PM by thetughum
via reddit https://ift.tt/3v1vCtk
Simple Thread
Relational Databases Aren’t Dinosaurs, They’re Sharks
Oh relational databases, that tired old relic of another age. Codd and friends were great in their time, but serious software engineers need to move on. People building Web Scale™ software You’ve probably heard a similar sentiment at some point. That relational…
Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors - Microsoft Security Blog
https://ift.tt/3DvlOL7
Submitted October 12, 2021 at 08:21PM by ksr_malware
via reddit https://ift.tt/3AB96sr
https://ift.tt/3DvlOL7
Submitted October 12, 2021 at 08:21PM by ksr_malware
via reddit https://ift.tt/3AB96sr
reddit
Iran-linked DEV-0343 targeting defense, GIS, and maritime sectors...
Posted in r/netsec by u/ksr_malware • 33 points and 0 comments
MITMf headless install in Kali Linux 2021.x [noscript & manual installation]
https://ift.tt/3BABADX
Submitted October 12, 2021 at 08:14PM by nexenta81
via reddit https://ift.tt/3axH1HI
https://ift.tt/3BABADX
Submitted October 12, 2021 at 08:14PM by nexenta81
via reddit https://ift.tt/3axH1HI
Nude Systems
How To Install MITMf In Kali Linux 2021 » Nude Systems
In this tutorial, I will show you how to install MITMf in Kali Linux 2021 using a simple noscript I made to automate the whole installation process as well as
New GitHub vulnerability: Bypassing required reviews using GitHub Actions
https://ift.tt/3DxJrm5
Submitted October 12, 2021 at 10:11PM by Hefty_Knowledge_7449
via reddit https://ift.tt/3Axgi8N
https://ift.tt/3DxJrm5
Submitted October 12, 2021 at 10:11PM by Hefty_Knowledge_7449
via reddit https://ift.tt/3Axgi8N
Medium
Bypassing required reviews using GitHub Actions
Not using GitHub Actions? You’re also vulnerable.
Hacking the Furbo Dog Camera: Part II
https://ift.tt/2YJAgzR
Submitted October 12, 2021 at 10:33PM by somersetrecon
via reddit https://ift.tt/2YFKFgf
https://ift.tt/2YJAgzR
Submitted October 12, 2021 at 10:33PM by somersetrecon
via reddit https://ift.tt/2YFKFgf
Somerset Recon
Hacking the Furbo Dog Camera: Part II — Somerset Recon
As mentioned in our previous post , Part II is a continuation of our research sparked by changes found in the revised Furbo 2.5T devices. This post specifically covers a command injection vulnerability (CVE-2021-32452) discovered in the HTTP server running…
Protecting Prometheus: Insecure configuration exposes secrets
https://ift.tt/2YKQ0CE
Submitted October 13, 2021 at 12:09AM by SRMish3
via reddit https://ift.tt/3avEJsD
https://ift.tt/2YKQ0CE
Submitted October 13, 2021 at 12:09AM by SRMish3
via reddit https://ift.tt/3avEJsD
JFrog
Protecting Prometheus: Insecure configuration exposes secrets
How to deploy & configure Prometheus securely, including authentication and encryption capabilities. Real-world exposures discovered by the JFrog Security Research team
Bindiff and POC for the IOMFB vulnerability, iOS 15.0.2
https://ift.tt/3DxWrbo
Submitted October 13, 2021 at 02:26AM by 0xdea
via reddit https://ift.tt/3lzP3X3
https://ift.tt/3DxWrbo
Submitted October 13, 2021 at 02:26AM by 0xdea
via reddit https://ift.tt/3lzP3X3
reddit
Bindiff and POC for the IOMFB vulnerability, iOS 15.0.2
Posted in r/netsec by u/0xdea • 31 points and 2 comments
Build an osquery Performance Dashboard Using Elasticsearch and Kibana
https://ift.tt/3iY2a2B
Submitted October 13, 2021 at 04:25AM by Silly-Pop-7437
via reddit https://ift.tt/3v5I776
https://ift.tt/3iY2a2B
Submitted October 13, 2021 at 04:25AM by Silly-Pop-7437
via reddit https://ift.tt/3v5I776
Medium
Build an osquery performance dashboard
This article serves as a guide to building an osquery performance dashboard with Elasticsearch and Kibana. In an existing osquery deployment, you may already have some mechanism for shipping logs to…
Threat Modeling cheat sheet (free) just released:
https://ift.tt/3iSwfQP
Submitted October 13, 2021 at 05:25AM by blokdijkg
via reddit https://ift.tt/3AC8h2y
https://ift.tt/3iSwfQP
Submitted October 13, 2021 at 05:25AM by blokdijkg
via reddit https://ift.tt/3AC8h2y
Theartofservice
Threat Modeling Kanban- The Art of Service, Standard Requirements Self Assessments
Ready to use prioritized Threat Modeling requirements, to: Lead architecture design reviews with development and product management to incorporate
White House looks to step up endpoint monitoring
https://ift.tt/3Dqtxdc
Submitted October 13, 2021 at 01:10PM by bidrawrob
via reddit https://ift.tt/3iXQzk2
https://ift.tt/3Dqtxdc
Submitted October 13, 2021 at 01:10PM by bidrawrob
via reddit https://ift.tt/3iXQzk2
FCW
White House looks to step up endpoint monitoring
The Biden administration is requiring agencies to provide visibility into their endpoint detection and response efforts as part of the cybersecurity executive order.
Google Announces Action Team to Support the Security Transformations of Public and Private Sector Organizations
https://ift.tt/3FDiY8L
Submitted October 13, 2021 at 12:58PM by tab228
via reddit https://ift.tt/3azCzrX
https://ift.tt/3FDiY8L
Submitted October 13, 2021 at 12:58PM by tab228
via reddit https://ift.tt/3azCzrX
Google Cloud Press Corner
Google Announces Cybersecurity Action Team to Support the Security Transformations of Public and Private Sector Organizations
Today, Google announced the Google Cybersecurity Action Team. Made up of experts from across the company, the Google Cybersecurity Action Team will be the world's premier security advisory team...