Verizon SIMs open their own TCP/IP sessions. And other stuff.
https://ift.tt/3BQMjtg
Submitted November 06, 2021 at 03:23AM by dburgess000
via reddit https://ift.tt/3wiVmSF
https://ift.tt/3BQMjtg
Submitted November 06, 2021 at 03:23AM by dburgess000
via reddit https://ift.tt/3wiVmSF
Medium
More Proactive SIMs
AT&T inspired me to explore a little more.
How to exploit CVE-2021-40539 on ManageEngine ADSelfService Plus
https://ift.tt/3CVumek
Submitted November 06, 2021 at 06:56AM by scopedsecurity
via reddit https://ift.tt/31v34O1
https://ift.tt/3CVumek
Submitted November 06, 2021 at 06:56AM by scopedsecurity
via reddit https://ift.tt/31v34O1
Synacktiv
How to exploit CVE-2021-40539 on ManageEngine ADSelfService Plus
A detailed analysis of the STOP/Djvu Ransomware
https://ift.tt/3BRtENO
Submitted November 07, 2021 at 02:06AM by CyberMasterV
via reddit https://ift.tt/3bOiNtw
https://ift.tt/3BRtENO
Submitted November 07, 2021 at 02:06AM by CyberMasterV
via reddit https://ift.tt/3bOiNtw
reddit
A detailed analysis of the STOP/Djvu Ransomware
Posted in r/netsec by u/CyberMasterV • 107 points and 3 comments
crashmon - a CrashWrangler replacement based on LLDB. Supports Apple Silicon - @ant4g0nist
https://ift.tt/3bMcRBe
Submitted November 07, 2021 at 10:40PM by ant4g0nist
via reddit https://ift.tt/302sdiw
https://ift.tt/3bMcRBe
Submitted November 07, 2021 at 10:40PM by ant4g0nist
via reddit https://ift.tt/302sdiw
GitHub
GitHub - ant4g0nist/crashmon: crashmon - A LLDB Based replacement for CrashWrangler
crashmon - A LLDB Based replacement for CrashWrangler - GitHub - ant4g0nist/crashmon: crashmon - A LLDB Based replacement for CrashWrangler
Homebrew Package Manager Harden Script
https://ift.tt/3kho7ua
Submitted November 08, 2021 at 04:11AM by AtropineTearz
via reddit https://ift.tt/3EOaLgw
https://ift.tt/3kho7ua
Submitted November 08, 2021 at 04:11AM by AtropineTearz
via reddit https://ift.tt/3EOaLgw
GitHub
TheMacHardeningScripts/brew-harden.sh at main · AtropineTears/TheMacHardeningScripts
Scripts to secure and harden Mac OS X. Contribute to AtropineTears/TheMacHardeningScripts development by creating an account on GitHub.
Trawling Weird Google Autocompletes
https://ift.tt/3bO6kGb
Submitted November 08, 2021 at 11:10AM by Vimda
via reddit https://ift.tt/301GH1Q
https://ift.tt/3bO6kGb
Submitted November 08, 2021 at 11:10AM by Vimda
via reddit https://ift.tt/301GH1Q
Sinkingpoint
Trawling Weird Google Autocompletes
A while back, I noticed that whenever I typed https:// into the search bar in Firefox on my phone, Google would helpfully try and autocomplete my search with a number of random domains. This immediatly nerd sniped me, so I thought it might be interesting…
How SSL certificates are leaking sensitive information - Detectify Labs
https://ift.tt/3BMjwpB
Submitted November 08, 2021 at 01:28PM by intheclairdelune
via reddit https://ift.tt/3kcDvaT
https://ift.tt/3BMjwpB
Submitted November 08, 2021 at 01:28PM by intheclairdelune
via reddit https://ift.tt/3kcDvaT
Beg Bounties
https://ift.tt/3CVU56q
Submitted November 08, 2021 at 05:23PM by RustEvangelist10xer
via reddit https://ift.tt/3CVrSNb
https://ift.tt/3CVU56q
Submitted November 08, 2021 at 05:23PM by RustEvangelist10xer
via reddit https://ift.tt/3CVrSNb
Troy Hunt
Beg Bounties
When someone passed me hundreds of thousands of records on kids taken from CloudPets a few years ago, I had a nightmare of a time getting in touch with the company. They'd left a MongoDB instance exposed to the public without a password and someone had snagged…
Driftwood: Immediately Know Which Private Keys are Sensitive
https://ift.tt/3khMnMq
Submitted November 08, 2021 at 09:49PM by wifihack
via reddit https://ift.tt/3EV4Kif
https://ift.tt/3khMnMq
Submitted November 08, 2021 at 09:49PM by wifihack
via reddit https://ift.tt/3EV4Kif
Truffle Security
Driftwood: Know if Private Keys are Sensitive — Truffle Security
Asymmetric private keys are among the most often leaked out. We’re open sourcing a tool that immediately tells you if one is sensitive https://github.com/trufflesecurity/driftwood With this tool we found the private keys for hundreds of TLS certificates…
Threat Hunting Certificate Account Persistence
https://ift.tt/3mVVww5
Submitted November 09, 2021 at 12:25AM by netbiosX
via reddit https://ift.tt/3ERb7mA
https://ift.tt/3mVVww5
Submitted November 09, 2021 at 12:25AM by netbiosX
via reddit https://ift.tt/3ERb7mA
Pentest Laboratories
Threat Hunting Certificate Account Persistence
The role of Certification Authority is to provide trust between different active directory entities or as an authentication mechanism in order to access specific resources such as web applications …
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
https://ift.tt/3bRCDE9
Submitted November 09, 2021 at 03:51AM by digicat
via reddit https://ift.tt/3C9diAx
https://ift.tt/3bRCDE9
Submitted November 09, 2021 at 03:51AM by digicat
via reddit https://ift.tt/3C9diAx
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Automatically Fix Security Issues at the Source
https://ift.tt/3mY7AwG
Submitted November 09, 2021 at 08:32PM by tmlxs
via reddit https://ift.tt/3knsiVb
https://ift.tt/3mY7AwG
Submitted November 09, 2021 at 08:32PM by tmlxs
via reddit https://ift.tt/3knsiVb
Backdoors can be hidden in JS code using "invisible" variables. Code looks completely harmless.
https://ift.tt/30bjP0g
Submitted November 09, 2021 at 08:04PM by ma-ni
via reddit https://ift.tt/3oadSZz
https://ift.tt/30bjP0g
Submitted November 09, 2021 at 08:04PM by ma-ni
via reddit https://ift.tt/3oadSZz
reddit
Backdoors can be hidden in JS code using "invisible" variables....
Posted in r/netsec by u/ma-ni • 485 points and 25 comments
Secure software supply chain: why every link matters
https://ift.tt/305g9Nw
Submitted November 09, 2021 at 10:08PM by MiguelHzBz
via reddit https://ift.tt/3obQeMq
https://ift.tt/305g9Nw
Submitted November 09, 2021 at 10:08PM by MiguelHzBz
via reddit https://ift.tt/3obQeMq
Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog
https://ift.tt/3wtlomh
Submitted November 09, 2021 at 11:10PM by SRMish3
via reddit https://ift.tt/3BZLMoS
https://ift.tt/3wtlomh
Submitted November 09, 2021 at 11:10PM by SRMish3
via reddit https://ift.tt/3BZLMoS
JFrog
Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog | JFrog
Background Embedded devices with limited memory and storage resources are likely to leverage a tool such as BusyBox, which is marketed as the Swiss Army Knife of embedded Linux. BusyBox is a software suite of many useful Unix utilities, known as applets,…
How to Avoid an Attack like Industroyer
https://ift.tt/3F1H1Nr
Submitted November 10, 2021 at 01:37AM by SCI_Rusher
via reddit https://ift.tt/3wxzymr
https://ift.tt/3F1H1Nr
Submitted November 10, 2021 at 01:37AM by SCI_Rusher
via reddit https://ift.tt/3wxzymr
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Technical Advisory – Arbitrary Signature Forgery in Stark Bank ECDSA Libraries
https://ift.tt/3bUJFYJ
Submitted November 10, 2021 at 02:19PM by digicat
via reddit https://ift.tt/3wEE4zp
https://ift.tt/3bUJFYJ
Submitted November 10, 2021 at 02:19PM by digicat
via reddit https://ift.tt/3wEE4zp
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
https://ift.tt/307J97a
Submitted November 10, 2021 at 09:46PM by albinowax
via reddit https://ift.tt/3qvouoV
https://ift.tt/307J97a
Submitted November 10, 2021 at 09:46PM by albinowax
via reddit https://ift.tt/3qvouoV
www.intruder.io
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
Modern web applications typically rely on chains of multiple servers, which forward HTTP requests to one another. The attack surface created by this forwarding is increasingly receiving more attention, including the recent popularisation of cache poisoning...
We love automation - FullHunt released a public API to identify all public assets of your organization for free
https://ift.tt/3CYTIIh
Submitted November 10, 2021 at 09:11PM by mazen160
via reddit https://ift.tt/3F4vbSQ
https://ift.tt/3CYTIIh
Submitted November 10, 2021 at 09:11PM by mazen160
via reddit https://ift.tt/3F4vbSQ
FullHunt Blog
New Release: FullHunt Public API! 🚀🚀
FullHunt is releasing a public API to find all attack surfaces, exposed services, DNS records, subdomains, and public assets for FREE!FullHunt API ReleaseAft...
CVE-2021-41765: Unauthenticated SQLi to RCE Chain in ResourceSpace
https://ift.tt/3n2DCaX
Submitted November 10, 2021 at 10:48PM by scopedsecurity
via reddit https://ift.tt/2YzYQDR
https://ift.tt/3n2DCaX
Submitted November 10, 2021 at 10:48PM by scopedsecurity
via reddit https://ift.tt/2YzYQDR
Horizon3.ai
Multiple Vulnerabilities in ResourceSpace
Advisory for CVE-2021-41765, a critical SQL injection vulnerability leading to remote code execution, by the Horizon3.ai red team.
PcapPlusPlus v21.11 released - a C++ library for capturing and analyzing network packets
https://ift.tt/304uHNf
Submitted November 10, 2021 at 10:36PM by seladb
via reddit https://ift.tt/3kp6kRU
https://ift.tt/304uHNf
Submitted November 10, 2021 at 10:36PM by seladb
via reddit https://ift.tt/3kp6kRU
GitHub
Release November 2021 Release · seladb/PcapPlusPlus
November 2021 release of PcapPlusPlus (v21.11)
This package contains
Binaries compiled for Ubuntu 20.04 LTS, 18.04 LTS,16.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bina...
This package contains
Binaries compiled for Ubuntu 20.04 LTS, 18.04 LTS,16.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bina...