A simple walkthrough of x86_64 stack-based buffer overflow exploitation with gdb
https://ift.tt/3rRwfWS
Submitted December 09, 2021 at 09:30PM by oxagast
via reddit https://ift.tt/3pZPw5Z
https://ift.tt/3rRwfWS
Submitted December 09, 2021 at 09:30PM by oxagast
via reddit https://ift.tt/3pZPw5Z
oxasploits
A simple x86_64 stack based buffer overflow exploitation with gdb
Background
Checkpoint researchers say not only is Emotet volume already 50% it's old peak but now it directly drops Cobalt Strike
https://ift.tt/33iCQiP
Submitted December 10, 2021 at 08:20AM by AnIrregularRegular
via reddit https://ift.tt/3IzBwYR
https://ift.tt/33iCQiP
Submitted December 10, 2021 at 08:20AM by AnIrregularRegular
via reddit https://ift.tt/3IzBwYR
Check Point Research
When old friends meet again: why Emotet chose Trickbot for rebirth - Check Point Research
Research by: Raman Ladutska, Aliaksandr Trafimchuk, David Driker, Yali Magiel Overview Trickbot and Emotet are considered some of the largest botnets in history. They both share a similar story: they were taken down and made a comeback. Check Point Research…
RCE 0-day exploit found in log4j, a popular Java logging package
https://ift.tt/3pLLJbZ
Submitted December 10, 2021 at 07:11AM by freeqaz
via reddit https://ift.tt/3DIWyAy
https://ift.tt/3pLLJbZ
Submitted December 10, 2021 at 07:11AM by freeqaz
via reddit https://ift.tt/3DIWyAy
www.lunasec.io
Log4Shell: RCE 0-day exploit found in log4j, a popular Java logging package | LunaTrace
Given how ubiquitous log4j is, the impact of this vulnerability is quite severe. Learn how to fix Log4Shell, why it's bad, and what a working exploit requires in this post.
Denial of Service in the protection service provided by Avast Security Premium.
https://ift.tt/3DCxdIN
Submitted December 10, 2021 at 05:12PM by sp1d3rr
via reddit https://ift.tt/3rSlHql
https://ift.tt/3DCxdIN
Submitted December 10, 2021 at 05:12PM by sp1d3rr
via reddit https://ift.tt/3rSlHql
Hunting for Low-Hanging Fruit in applications at AWS environments
https://ift.tt/3pDe2JO
Submitted December 10, 2021 at 05:11PM by sp1d3rr
via reddit https://ift.tt/3yf2WhX
https://ift.tt/3pDe2JO
Submitted December 10, 2021 at 05:11PM by sp1d3rr
via reddit https://ift.tt/3yf2WhX
Medium
Hunting for Low-Hanging Fruit in applications at AWS environments
Hello everyone, it’s nothing new that Cloud environments have been dominating the market today, and among service providers, AWS is on the…
Critical vulnerability in log4j, a widely used logging library
https://ift.tt/31EuNfT
Submitted December 10, 2021 at 11:46PM by MiguelHzBz
via reddit https://ift.tt/3ELHhk2
https://ift.tt/31EuNfT
Submitted December 10, 2021 at 11:46PM by MiguelHzBz
via reddit https://ift.tt/3ELHhk2
Ghidra 10.1 Released
https://ift.tt/3oJjICH
Submitted December 11, 2021 at 04:58AM by mumbel
via reddit https://ift.tt/3yfQZbL
https://ift.tt/3oJjICH
Submitted December 11, 2021 at 04:58AM by mumbel
via reddit https://ift.tt/3yfQZbL
GitHub
Release Ghidra 10.1 · NationalSecurityAgency/ghidra
Includes log4j 2.15.0 which addresses CVE-2021-44228
What's New
Change History
Installation Guide
SHA-256: 99139c4a63a81135b3b63fe9997a012a6394a766c2c7f2ac5115ab53912d2a6c
What's New
Change History
Installation Guide
SHA-256: 99139c4a63a81135b3b63fe9997a012a6394a766c2c7f2ac5115ab53912d2a6c
Security researchers visit Nullcon Berlin
https://ift.tt/3s0ph1F
Submitted December 11, 2021 at 08:24AM by sparsh990
via reddit https://ift.tt/3EMS8u2
https://ift.tt/3s0ph1F
Submitted December 11, 2021 at 08:24AM by sparsh990
via reddit https://ift.tt/3EMS8u2
nullcon.net
Call for Papers | Nullcon Berlin 2022
Nullcon is an annual security conference which takes place in Goa, India. The focus of the conference is to showcase the next generation of offensive and defensive security research. Submit CFP for Nullcon 1st Berlin edition in 2022.
Hacking a Harley's Tuner - Part 3
https://ift.tt/3dJP1qF
Submitted December 11, 2021 at 08:44PM by _kawhl
via reddit https://ift.tt/3DLJL0t
https://ift.tt/3dJP1qF
Submitted December 11, 2021 at 08:44PM by _kawhl
via reddit https://ift.tt/3DLJL0t
therealunicornsecurity.github.io
Hacking a Harley's Tuner - Part 3
Completion of the primary objective
Log4shell - using the vulnerability to patch the vulnerability - very clever
https://ift.tt/3yhSbeS
Submitted December 11, 2021 at 10:44PM by lkn240
via reddit https://ift.tt/3lSW0lS
https://ift.tt/3yhSbeS
Submitted December 11, 2021 at 10:44PM by lkn240
via reddit https://ift.tt/3lSW0lS
log4shell.tools - Check if you're vulnerable to an egregious case of log4shell
https://ift.tt/3GABVsj
Submitted December 13, 2021 at 12:55AM by clearlyarbitrary
via reddit https://ift.tt/3DPx7xB
https://ift.tt/3GABVsj
Submitted December 13, 2021 at 12:55AM by clearlyarbitrary
via reddit https://ift.tt/3DPx7xB
reddit
log4shell.tools - Check if you're vulnerable to an egregious case...
Posted in r/netsec by u/clearlyarbitrary • 33 points and 9 comments
Our new tool for enumerating hidden Log4Shell-affected hosts
https://ift.tt/3IFhHzs
Submitted December 13, 2021 at 01:53AM by dn3t
via reddit https://ift.tt/3oPHUTS
https://ift.tt/3IFhHzs
Submitted December 13, 2021 at 01:53AM by dn3t
via reddit https://ift.tt/3oPHUTS
reddit
Our new tool for enumerating hidden Log4Shell-affected hosts
Posted in r/netsec by u/dn3t • 193 points and 23 comments
Cisco Security Advisory: Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
https://ift.tt/3IMUrzt
Submitted December 13, 2021 at 08:27AM by girl_from_japan
via reddit https://ift.tt/31W0MaO
https://ift.tt/3IMUrzt
Submitted December 13, 2021 at 08:27AM by girl_from_japan
via reddit https://ift.tt/31W0MaO
Cisco
Cisco Security Advisory: Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions prior to 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other…
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other…
GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
https://ift.tt/31ZbcGE
Submitted December 13, 2021 at 10:23AM by mazen160
via reddit https://ift.tt/3s0ck81
https://ift.tt/31ZbcGE
Submitted December 13, 2021 at 10:23AM by mazen160
via reddit https://ift.tt/3s0ck81
GitHub
GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 - GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE...
Log4Shell: Reconnaissance and post exploitation network detection
https://ift.tt/3rZjSbl
Submitted December 13, 2021 at 01:10PM by digicat
via reddit https://ift.tt/3lXrZkA
https://ift.tt/3rZjSbl
Submitted December 13, 2021 at 01:10PM by digicat
via reddit https://ift.tt/3lXrZkA
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
log4hshell - Quick Guide
https://ift.tt/31SJD27
Submitted December 13, 2021 at 03:06PM by 0xmusana
via reddit https://ift.tt/3ynytyw
https://ift.tt/31SJD27
Submitted December 13, 2021 at 03:06PM by 0xmusana
via reddit https://ift.tt/3ynytyw
musana.net
log4shell - Quick Guide
CVE-2021-44228 (a.k.a. log4shell) is a Remote Code Execution vulnerability in the Apache Log4j library, a Java-based logging tool widely used in applications around the world.
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228)
https://ift.tt/3s2FweG
Submitted December 13, 2021 at 03:59PM by freeqaz
via reddit https://ift.tt/3GAXl8L
https://ift.tt/3s2FweG
Submitted December 13, 2021 at 03:59PM by freeqaz
via reddit https://ift.tt/3GAXl8L
www.lunasec.io
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228 & CVE-2021-45046) | LunaSec
If you're using log4j 2 in your infrastructure, this guide will help you understand how to check if you're impacted and show you how to quickly and securely mitigate the issue.
pimps/JNDI-Exploit-Kit: added support to LDAP Serialized Payloads and attack path works in *ANY* java version
https://ift.tt/3pOF15j
Submitted December 13, 2021 at 06:24PM by Gallus
via reddit https://ift.tt/31YEvJr
https://ift.tt/3pOF15j
Submitted December 13, 2021 at 06:24PM by Gallus
via reddit https://ift.tt/31YEvJr
GitHub
GitHub - pimps/JNDI-Exploit-Kit: JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n.…
JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v...
Diavol Ransomware
https://ift.tt/3dIla1W
Submitted December 13, 2021 at 06:14PM by TheDFIRReport
via reddit https://ift.tt/3lZyuDN
https://ift.tt/3dIla1W
Submitted December 13, 2021 at 06:14PM by TheDFIRReport
via reddit https://ift.tt/3lZyuDN
The DFIR Report
Diavol Ransomware
In the past, threat actors have used BazarLoader to deploy Ryuk and Conti ransomware, as reported on many occasions. In this intrusion, however, a BazarLoader infection resulted in deployment of Di…
Analysis of Initial In The Wild Attacks Exploiting Log4Shell/Log4J/CVE-2021-44228
https://ift.tt/31KRXRP
Submitted December 13, 2021 at 05:51PM by 0x636f6f6c
via reddit https://ift.tt/3oP1dwR
https://ift.tt/31KRXRP
Submitted December 13, 2021 at 05:51PM by 0x636f6f6c
via reddit https://ift.tt/3oP1dwR
Cado Security | Cloud Forensics & Incident Response
Analysis of Initial In The Wild Attacks Exploiting Log4Shell/Log4J/CVE-2021-44228 - Cado Security | Cloud Forensics & Incident…
Log4J is an open-source logging platform running on Java and built-in to many web platforms. Reports of exploitation started on December 9th.
(Log4Shell / Log4J) CVE-2021-44228 dummy Spring Boot target docker image
https://ift.tt/30peHWK
Submitted December 13, 2021 at 07:13PM by zshalo
via reddit https://ift.tt/3oOYOCf
https://ift.tt/30peHWK
Submitted December 13, 2021 at 07:13PM by zshalo
via reddit https://ift.tt/3oOYOCf
GitHub
GitHub - zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
Contribute to zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service development by creating an account on GitHub.