Backdoors can be hidden in JS code using "invisible" variables. Code looks completely harmless.
https://ift.tt/30bjP0g
Submitted November 09, 2021 at 08:04PM by ma-ni
via reddit https://ift.tt/3oadSZz
https://ift.tt/30bjP0g
Submitted November 09, 2021 at 08:04PM by ma-ni
via reddit https://ift.tt/3oadSZz
reddit
Backdoors can be hidden in JS code using "invisible" variables....
Posted in r/netsec by u/ma-ni • 485 points and 25 comments
Secure software supply chain: why every link matters
https://ift.tt/305g9Nw
Submitted November 09, 2021 at 10:08PM by MiguelHzBz
via reddit https://ift.tt/3obQeMq
https://ift.tt/305g9Nw
Submitted November 09, 2021 at 10:08PM by MiguelHzBz
via reddit https://ift.tt/3obQeMq
Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog
https://ift.tt/3wtlomh
Submitted November 09, 2021 at 11:10PM by SRMish3
via reddit https://ift.tt/3BZLMoS
https://ift.tt/3wtlomh
Submitted November 09, 2021 at 11:10PM by SRMish3
via reddit https://ift.tt/3BZLMoS
JFrog
Unboxing BusyBox - 14 new vulnerabilities uncovered by Claroty and JFrog | JFrog
Background Embedded devices with limited memory and storage resources are likely to leverage a tool such as BusyBox, which is marketed as the Swiss Army Knife of embedded Linux. BusyBox is a software suite of many useful Unix utilities, known as applets,…
How to Avoid an Attack like Industroyer
https://ift.tt/3F1H1Nr
Submitted November 10, 2021 at 01:37AM by SCI_Rusher
via reddit https://ift.tt/3wxzymr
https://ift.tt/3F1H1Nr
Submitted November 10, 2021 at 01:37AM by SCI_Rusher
via reddit https://ift.tt/3wxzymr
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Technical Advisory – Arbitrary Signature Forgery in Stark Bank ECDSA Libraries
https://ift.tt/3bUJFYJ
Submitted November 10, 2021 at 02:19PM by digicat
via reddit https://ift.tt/3wEE4zp
https://ift.tt/3bUJFYJ
Submitted November 10, 2021 at 02:19PM by digicat
via reddit https://ift.tt/3wEE4zp
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
https://ift.tt/307J97a
Submitted November 10, 2021 at 09:46PM by albinowax
via reddit https://ift.tt/3qvouoV
https://ift.tt/307J97a
Submitted November 10, 2021 at 09:46PM by albinowax
via reddit https://ift.tt/3qvouoV
www.intruder.io
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
Modern web applications typically rely on chains of multiple servers, which forward HTTP requests to one another. The attack surface created by this forwarding is increasingly receiving more attention, including the recent popularisation of cache poisoning...
We love automation - FullHunt released a public API to identify all public assets of your organization for free
https://ift.tt/3CYTIIh
Submitted November 10, 2021 at 09:11PM by mazen160
via reddit https://ift.tt/3F4vbSQ
https://ift.tt/3CYTIIh
Submitted November 10, 2021 at 09:11PM by mazen160
via reddit https://ift.tt/3F4vbSQ
FullHunt Blog
New Release: FullHunt Public API! 🚀🚀
FullHunt is releasing a public API to find all attack surfaces, exposed services, DNS records, subdomains, and public assets for FREE!FullHunt API ReleaseAft...
CVE-2021-41765: Unauthenticated SQLi to RCE Chain in ResourceSpace
https://ift.tt/3n2DCaX
Submitted November 10, 2021 at 10:48PM by scopedsecurity
via reddit https://ift.tt/2YzYQDR
https://ift.tt/3n2DCaX
Submitted November 10, 2021 at 10:48PM by scopedsecurity
via reddit https://ift.tt/2YzYQDR
Horizon3.ai
Multiple Vulnerabilities in ResourceSpace
Advisory for CVE-2021-41765, a critical SQL injection vulnerability leading to remote code execution, by the Horizon3.ai red team.
PcapPlusPlus v21.11 released - a C++ library for capturing and analyzing network packets
https://ift.tt/304uHNf
Submitted November 10, 2021 at 10:36PM by seladb
via reddit https://ift.tt/3kp6kRU
https://ift.tt/304uHNf
Submitted November 10, 2021 at 10:36PM by seladb
via reddit https://ift.tt/3kp6kRU
GitHub
Release November 2021 Release · seladb/PcapPlusPlus
November 2021 release of PcapPlusPlus (v21.11)
This package contains
Binaries compiled for Ubuntu 20.04 LTS, 18.04 LTS,16.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bina...
This package contains
Binaries compiled for Ubuntu 20.04 LTS, 18.04 LTS,16.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bina...
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
https://ift.tt/3oeqY8h
Submitted November 10, 2021 at 11:50PM by sagitz_
via reddit https://ift.tt/3C7rUjA
https://ift.tt/3oeqY8h
Submitted November 10, 2021 at 11:50PM by sagitz_
via reddit https://ift.tt/3C7rUjA
Wiz Blog
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
This is the full story of the Azure ChaosDB Vulnerability that was discovered and disclosed by the Wiz Research Team, where we were able to gain complete unrestricted access to the databases of several thousand Microsoft Azure customers. In August 2021, we…
SMBSR: Automated SMB Enumeration and Secrets finder. python noscript which given a CIDR/IP/IP_file/HOSTNAME(s) enumerates all the SMB services listening (445) among the targets; if the authentication succeed then all the folders and subfolders are visited recursively in order to find secrets in files.
https://ift.tt/3H9SBrL
Submitted November 10, 2021 at 11:39PM by oldboy21
via reddit https://ift.tt/30cwtfQ
https://ift.tt/3H9SBrL
Submitted November 10, 2021 at 11:39PM by oldboy21
via reddit https://ift.tt/30cwtfQ
GitHub
GitHub - oldboy21/SMBSR: Lookup for interesting stuff in SMB shares
Lookup for interesting stuff in SMB shares. Contribute to oldboy21/SMBSR development by creating an account on GitHub.
CVE-2021-3064: CVSS 9.8 RCE in Palo Alto Networks GlobalProtect VPN
https://ift.tt/3krGjBf
Submitted November 10, 2021 at 11:11PM by aaronportnoy
via reddit https://ift.tt/3F5Gh9Y
https://ift.tt/3krGjBf
Submitted November 10, 2021 at 11:11PM by aaronportnoy
via reddit https://ift.tt/3F5Gh9Y
Randori
Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064
On November 10, 2021 Palo Alto Networks (PAN) provided an update that patched CVE-2021-3064 which was discovered and disclosed by Randori.
MalwareBazaar - LinuxFilecoder.Polaris.sample. Linux ransomware 5 days old .
https://ift.tt/3wzCazU
Submitted November 11, 2021 at 02:19AM by spca2001
via reddit https://ift.tt/3C51kYg
https://ift.tt/3wzCazU
Submitted November 11, 2021 at 02:19AM by spca2001
via reddit https://ift.tt/3C51kYg
bazaar.abuse.ch
MalwareBazaar - LinuxFilecoder.Polaris.sample
Threat intel on LinuxFilecoder.Polaris.sample (MD5 c601a9e2b98b8e0146ca4b435bb42a0e)
Introducing TEQNIX: An online collection of free pentesting tools. Recently added: Frida Gadget Injector, APK static analyser, XSS exploitation helper.
http://teqnix.io/#
Submitted November 11, 2021 at 03:07AM by maudits
via reddit https://ift.tt/3DhcdaQ
http://teqnix.io/#
Submitted November 11, 2021 at 03:07AM by maudits
via reddit https://ift.tt/3DhcdaQ
A Detailed Analysis of Lazarus’ RAT Called FALLCHILL
https://ift.tt/3D811xs
Submitted November 11, 2021 at 05:01PM by CyberMasterV
via reddit https://ift.tt/3F7su2U
https://ift.tt/3D811xs
Submitted November 11, 2021 at 05:01PM by CyberMasterV
via reddit https://ift.tt/3F7su2U
New World's Botting Problem
https://ift.tt/3F7Xe3O
Submitted November 11, 2021 at 07:50PM by dinobyt3s
via reddit https://ift.tt/3Hdn8F6
https://ift.tt/3F7Xe3O
Submitted November 11, 2021 at 07:50PM by dinobyt3s
via reddit https://ift.tt/3Hdn8F6
Medium
New World’s Botting Problem
New World, Amazon’s latest entry into the gaming world, is a plagued by bots that are ruining player experiences.
SharkBot: a new generation of Android Trojans is targeting banks in Europe
https://ift.tt/3n4DQyk
Submitted November 11, 2021 at 09:33PM by f3d_0x0
via reddit https://ift.tt/3D7vprR
https://ift.tt/3n4DQyk
Submitted November 11, 2021 at 09:33PM by f3d_0x0
via reddit https://ift.tt/3D7vprR
Cleafy
SharkBot: a new generation of Android Trojans is targeting banks in Europe | Cleafy Labs
SharkBot: a new generation of Android Trojans is targeting European banks. It has been discovered by the threat intelligence team of Cleafy: here's the technical analysis.
Bypass EDR Hooks by Faking Reentrancy
https://ift.tt/3qosiYW
Submitted November 11, 2021 at 09:53PM by Safficon
via reddit https://ift.tt/3D8TCOq
https://ift.tt/3qosiYW
Submitted November 11, 2021 at 09:53PM by Safficon
via reddit https://ift.tt/3D8TCOq
Deep Instinct
Evading EDR Detection with Reentrancy Abuse | Deep Instinct
In this blog, we’ll explore a new way to exploit reentrancy that can be used to evade the behavioral analysis of EDR and legacy antivirus products.
The Kerberos Key List Attack: The return of the Read Only Domain Controllers
https://ift.tt/3c5iQkW
Submitted November 11, 2021 at 11:11PM by mgalloar
via reddit https://ift.tt/3oe36Bu
https://ift.tt/3c5iQkW
Submitted November 11, 2021 at 11:11PM by mgalloar
via reddit https://ift.tt/3oe36Bu
SecureAuth
The Kerberos Key List Attack: The return of the Read Only Domain Controllers
Some time ago Microsoft released a very cool feature that caught our attention. That was a passwordless authentication functionality that provides seamless single sign-on (SSO) to on-premises resources, using security keys such as the famous FIDO2 keys. …
Analyzing a watering hole campaign using macOS exploits
https://ift.tt/3ohoxBX
Submitted November 12, 2021 at 01:38AM by digicat
via reddit https://ift.tt/30kVFRe
https://ift.tt/3ohoxBX
Submitted November 12, 2021 at 01:38AM by digicat
via reddit https://ift.tt/30kVFRe
Google
Analyzing a watering hole campaign using macOS exploits
To protect our users, TAG routinely hunts for 0-day vulnerabilities exploited in-the-wild. In late August 2021, TAG discovered watering hole attacks targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political…
CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on everything
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
reddit
CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on...
A community for technical news and discussion of information security and closely related topics.