I put a WiFi router into a phone charger (Final Post)
https://ift.tt/3mfhxFM
Submitted October 26, 2021 at 06:12AM by Machinehum
via reddit https://ift.tt/3EfleRZ
https://ift.tt/3mfhxFM
Submitted October 26, 2021 at 06:12AM by Machinehum
via reddit https://ift.tt/3EfleRZ
Medium
I put a WiFi router into a phone charger (Final Post)
This is the fifth and final installment about designing a WiFi router into a phone charger for security, pentesting and red teaming; (part…
Double spending bug in Polygon’s Plasma bridge
https://ift.tt/3b9e1qf
Submitted October 26, 2021 at 11:02AM by Gallus
via reddit https://ift.tt/3bd8y1r
https://ift.tt/3b9e1qf
Submitted October 26, 2021 at 11:02AM by Gallus
via reddit https://ift.tt/3bd8y1r
Medium
Double spending bug in Polygon’s Plasma bridge
I thought I was out of the security game for a while now and that my interests have moved on to other fields. Last week I came back from an…
Chrome Ad-Heavy detection mechanism: How it can be bypassed and allow ads that are breaching the restrictions imposed by Chrome to still run
https://ift.tt/3GmznyH
Submitted October 26, 2021 at 01:37PM by SSDisclosure
via reddit https://ift.tt/3Ba4Sbz
https://ift.tt/3GmznyH
Submitted October 26, 2021 at 01:37PM by SSDisclosure
via reddit https://ift.tt/3Ba4Sbz
SSD Secure Disclosure
SSD Advisory – Chrome Ad Heavy Bypass (via SharedWorker) - SSD Secure Disclosure
Find out how a vulnerability in macOS Finder system allows remote attackers to trick users into running arbitrary commands.
Advanced HTTP(/2) Request Smuggling
https://ift.tt/3Eje7Ic
Submitted October 26, 2021 at 07:25PM by albinowax
via reddit https://ift.tt/3jDhthu
https://ift.tt/3Eje7Ic
Submitted October 26, 2021 at 07:25PM by albinowax
via reddit https://ift.tt/3jDhthu
portswigger.net
Advanced request smuggling | Web Security Academy
In this section, we'll build on the concepts you've learned so far and teach you some more advanced HTTP request smuggling techniques. We'll also cover a ...
How I Cracked 70% of Tel Aviv’s Wifi Networks (from a Sample of 5,000 Gathered WiFi).
https://ift.tt/3nzQBAd
Submitted October 27, 2021 at 12:03AM by jat0369
via reddit https://ift.tt/3bemrwo
https://ift.tt/3nzQBAd
Submitted October 27, 2021 at 12:03AM by jat0369
via reddit https://ift.tt/3bemrwo
Cyberark
Cracking WiFi at Scale with One Simple Trick
How I Cracked 70% of Tel Aviv’s Wifi Networks (from a Sample of 5,000 Gathered WiFi). In the past seven years that I’ve lived in Tel Aviv, I’ve changed apartments four times. Every time I...
The Top 13 Ethical Hacking Courses on Udemy (2021)
https://ift.tt/3fFqPY7
Submitted October 27, 2021 at 01:09AM by Jan_Prince
via reddit https://ift.tt/3jGT5vr
https://ift.tt/3fFqPY7
Submitted October 27, 2021 at 01:09AM by Jan_Prince
via reddit https://ift.tt/3jGT5vr
Pythonstacks
The Top 13 Ethical Hacking Courses on Udemy (2022)
Gain robust hacking skills with these courses.
A reverse engineering challenge I created, who can solve it? I'll list you in the hall of fame
https://ift.tt/3md7wJg
Submitted October 27, 2021 at 01:01AM by vowie92
via reddit https://ift.tt/3BfOMgA
https://ift.tt/3md7wJg
Submitted October 27, 2021 at 01:01AM by vowie92
via reddit https://ift.tt/3BfOMgA
Reverse Engineering Challenge MMXI | CYTRES
This reverse engineering challenge is about obtaining the password of the targetapplication.Download the the bundle (Windows / Linux / MacOS): https://cytres.com/re_mmxi.zipIf you solved the challenge, apply your solution to info@cytres.comHall of fame:1.…
On code isolation in Python!
https://ift.tt/3kyZzec
Submitted October 27, 2021 at 04:58AM by montanababy62
via reddit https://ift.tt/3Ciq4NH
https://ift.tt/3kyZzec
Submitted October 27, 2021 at 04:58AM by montanababy62
via reddit https://ift.tt/3Ciq4NH
Artem Golubin
On code isolation in Python
On why It's not possible to isolate Python code when running it in the same interpreter
Cisco Cert Giveaway
https://ift.tt/3BhJwsL
Submitted October 27, 2021 at 05:31AM by rockintrix
via reddit https://ift.tt/3nu8ekU
https://ift.tt/3BhJwsL
Submitted October 27, 2021 at 05:31AM by rockintrix
via reddit https://ift.tt/3nu8ekU
Cisco
Cybersecurity Giveaway
Calling all Cyber Defenders. Enter our Cybersecurity Giveaway now for your chance to win a training and exam bundle to get you ready for either Cisco Certified CyberOps Associate, CyberOps Professional or CCNP Security certifications.
How to exploit a double free vulnerability in 2021
https://ift.tt/3GoU9hh
Submitted October 27, 2021 at 03:03PM by vonadz
via reddit https://ift.tt/3Bgqpzb
https://ift.tt/3GoU9hh
Submitted October 27, 2021 at 03:03PM by vonadz
via reddit https://ift.tt/3Bgqpzb
GitHub
GitHub - stong/how-to-exploit-a-double-free: How to exploit a double free vulnerability in 2021. 'Use After Free for Dummies'
How to exploit a double free vulnerability in 2021. 'Use After Free for Dummies' - GitHub - stong/how-to-exploit-a-double-free: How to exploit a double free vulnerability in 2021. &...
Container security best practices: Comprehensive guide
https://ift.tt/3mQV5Sq
Submitted October 27, 2021 at 07:57PM by MiguelHzBz
via reddit https://ift.tt/3BmOGDP
https://ift.tt/3mQV5Sq
Submitted October 27, 2021 at 07:57PM by MiguelHzBz
via reddit https://ift.tt/3BmOGDP
Sysdig
Container security best practices: Comprehensive guide – Sysdig
Container security best practices include the full component stack used for building, distributing, and specifically executing the container.
GoCD pre-auth secret leakage
https://ift.tt/3be6tCn
Submitted October 27, 2021 at 10:11PM by websecdev
via reddit https://ift.tt/3BfGuFf
https://ift.tt/3be6tCn
Submitted October 27, 2021 at 10:11PM by websecdev
via reddit https://ift.tt/3BfGuFf
Sonarsource
Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD
We recently discovered critical security issues in the popular CI/CD solution GoCD that can be exploited by unauthenticated attackers
Writing a SQLMap tamper for Google Protobuf - @APTortellini
https://ift.tt/3bhfwCJ
Submitted October 28, 2021 at 01:38AM by last0x00
via reddit https://ift.tt/3GDsA3U
https://ift.tt/3bhfwCJ
Submitted October 28, 2021 at 01:38AM by last0x00
via reddit https://ift.tt/3GDsA3U
APT::WTF - APTortellini’s blog
Tortellini in Brodobuf
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
Using Kerberos for Authentication Relay Attacks
https://ift.tt/3B3ELCT
Submitted October 28, 2021 at 11:08AM by 0xdea
via reddit https://ift.tt/3EnLPfH
https://ift.tt/3B3ELCT
Submitted October 28, 2021 at 11:08AM by 0xdea
via reddit https://ift.tt/3EnLPfH
Blogspot
Using Kerberos for Authentication Relay Attacks
Posted by James Forshaw, Project Zero This blog post is a summary of some research I've been doing into relaying Kerberos authentica...
Unauthenticated RCE vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)
https://ift.tt/3u393nv
Submitted October 28, 2021 at 12:40PM by Gallus
via reddit https://ift.tt/3nA4oGS
https://ift.tt/3u393nv
Submitted October 28, 2021 at 12:40PM by Gallus
via reddit https://ift.tt/3nA4oGS
Watchful_IP
Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP camera/NVR firmware (CVE-2021-36260)
This article has been written for a technical audience.
Finding gadgets like it's 2015: part 1
https://ift.tt/3pLXGA3
Submitted October 28, 2021 at 03:00PM by Gallus
via reddit https://ift.tt/2XVBTdW
https://ift.tt/3pLXGA3
Submitted October 28, 2021 at 03:00PM by Gallus
via reddit https://ift.tt/2XVBTdW
Synacktiv
Finding gadgets like it's 2015: part 1
We found a new Java gadget chain in the Mojarra library, one of the most used implementation of the JSF specification.
Impacket v0.9.24 Released 🎉
https://ift.tt/3jMIvCZ
Submitted October 28, 2021 at 07:23PM by mgalloar
via reddit https://ift.tt/3EmsGec
https://ift.tt/3jMIvCZ
Submitted October 28, 2021 at 07:23PM by mgalloar
via reddit https://ift.tt/3EmsGec
SecureAuth
Impacket v0.9.24 Released
Here at SecureAuth, we’re excited to announce the release of the latest version of Impacket, our collection of Python classes for working with network protocols, and much more. Impacket release 0.9.24 is available today and includes a lot of new features…
Solarmarker In-Depth Analysis
https://ift.tt/3pM7OsL
Submitted October 28, 2021 at 08:43PM by Egesploit
via reddit https://ift.tt/2Zy9Lyq
https://ift.tt/3pM7OsL
Submitted October 28, 2021 at 08:43PM by Egesploit
via reddit https://ift.tt/2Zy9Lyq
NGINX Custom Snippets CVE-2021-25742 Deep Dive
https://ift.tt/3w1nVE0
Submitted October 28, 2021 at 04:30PM by gafnita
via reddit https://ift.tt/3jGwuyY
https://ift.tt/3w1nVE0
Submitted October 28, 2021 at 04:30PM by gafnita
via reddit https://ift.tt/3jGwuyY
blog.lightspin.io
NGINX Custom Snippets CVE-2021-25742
Here's a deep dive into what high severity alert known as CVE-2021-25742 really is and what it means for today’s organizations.
DriverBuddyReloaded - IDA Python noscript to assist with the reverse engineering of Windows kernel drivers
https://ift.tt/3jCZYxN
Submitted October 28, 2021 at 08:56PM by Void_Sec
via reddit https://ift.tt/3jNLX0b
https://ift.tt/3jCZYxN
Submitted October 28, 2021 at 08:56PM by Void_Sec
via reddit https://ift.tt/3jNLX0b
VoidSec
Driver Buddy Reloaded - VoidSec
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks.
Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection
https://ift.tt/30ZoTVF
Submitted October 28, 2021 at 11:13PM by moviuro
via reddit https://ift.tt/3pJMdRN
https://ift.tt/30ZoTVF
Submitted October 28, 2021 at 11:13PM by moviuro
via reddit https://ift.tt/3pJMdRN
Microsoft Security Blog
Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection | Microsoft Security Blog
Microsoft found a vulnerability (CVE-2021-30892) that could allow an attacker to bypass System Integrity Protection (SIP) in macOS. We shared our findings with Apple via coordinated vulnerability disclosure, and a fix was released October 26.