Ghidra 10.1 Released
https://ift.tt/3oJjICH
Submitted December 11, 2021 at 04:58AM by mumbel
via reddit https://ift.tt/3yfQZbL
https://ift.tt/3oJjICH
Submitted December 11, 2021 at 04:58AM by mumbel
via reddit https://ift.tt/3yfQZbL
GitHub
Release Ghidra 10.1 · NationalSecurityAgency/ghidra
Includes log4j 2.15.0 which addresses CVE-2021-44228
What's New
Change History
Installation Guide
SHA-256: 99139c4a63a81135b3b63fe9997a012a6394a766c2c7f2ac5115ab53912d2a6c
What's New
Change History
Installation Guide
SHA-256: 99139c4a63a81135b3b63fe9997a012a6394a766c2c7f2ac5115ab53912d2a6c
Security researchers visit Nullcon Berlin
https://ift.tt/3s0ph1F
Submitted December 11, 2021 at 08:24AM by sparsh990
via reddit https://ift.tt/3EMS8u2
https://ift.tt/3s0ph1F
Submitted December 11, 2021 at 08:24AM by sparsh990
via reddit https://ift.tt/3EMS8u2
nullcon.net
Call for Papers | Nullcon Berlin 2022
Nullcon is an annual security conference which takes place in Goa, India. The focus of the conference is to showcase the next generation of offensive and defensive security research. Submit CFP for Nullcon 1st Berlin edition in 2022.
Hacking a Harley's Tuner - Part 3
https://ift.tt/3dJP1qF
Submitted December 11, 2021 at 08:44PM by _kawhl
via reddit https://ift.tt/3DLJL0t
https://ift.tt/3dJP1qF
Submitted December 11, 2021 at 08:44PM by _kawhl
via reddit https://ift.tt/3DLJL0t
therealunicornsecurity.github.io
Hacking a Harley's Tuner - Part 3
Completion of the primary objective
Log4shell - using the vulnerability to patch the vulnerability - very clever
https://ift.tt/3yhSbeS
Submitted December 11, 2021 at 10:44PM by lkn240
via reddit https://ift.tt/3lSW0lS
https://ift.tt/3yhSbeS
Submitted December 11, 2021 at 10:44PM by lkn240
via reddit https://ift.tt/3lSW0lS
log4shell.tools - Check if you're vulnerable to an egregious case of log4shell
https://ift.tt/3GABVsj
Submitted December 13, 2021 at 12:55AM by clearlyarbitrary
via reddit https://ift.tt/3DPx7xB
https://ift.tt/3GABVsj
Submitted December 13, 2021 at 12:55AM by clearlyarbitrary
via reddit https://ift.tt/3DPx7xB
reddit
log4shell.tools - Check if you're vulnerable to an egregious case...
Posted in r/netsec by u/clearlyarbitrary • 33 points and 9 comments
Our new tool for enumerating hidden Log4Shell-affected hosts
https://ift.tt/3IFhHzs
Submitted December 13, 2021 at 01:53AM by dn3t
via reddit https://ift.tt/3oPHUTS
https://ift.tt/3IFhHzs
Submitted December 13, 2021 at 01:53AM by dn3t
via reddit https://ift.tt/3oPHUTS
reddit
Our new tool for enumerating hidden Log4Shell-affected hosts
Posted in r/netsec by u/dn3t • 193 points and 23 comments
Cisco Security Advisory: Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
https://ift.tt/3IMUrzt
Submitted December 13, 2021 at 08:27AM by girl_from_japan
via reddit https://ift.tt/31W0MaO
https://ift.tt/3IMUrzt
Submitted December 13, 2021 at 08:27AM by girl_from_japan
via reddit https://ift.tt/31W0MaO
Cisco
Cisco Security Advisory: Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
On December 9, 2021, the following vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions prior to 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other…
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other…
GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
https://ift.tt/31ZbcGE
Submitted December 13, 2021 at 10:23AM by mazen160
via reddit https://ift.tt/3s0ck81
https://ift.tt/31ZbcGE
Submitted December 13, 2021 at 10:23AM by mazen160
via reddit https://ift.tt/3s0ck81
GitHub
GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 - GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE...
Log4Shell: Reconnaissance and post exploitation network detection
https://ift.tt/3rZjSbl
Submitted December 13, 2021 at 01:10PM by digicat
via reddit https://ift.tt/3lXrZkA
https://ift.tt/3rZjSbl
Submitted December 13, 2021 at 01:10PM by digicat
via reddit https://ift.tt/3lXrZkA
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
log4hshell - Quick Guide
https://ift.tt/31SJD27
Submitted December 13, 2021 at 03:06PM by 0xmusana
via reddit https://ift.tt/3ynytyw
https://ift.tt/31SJD27
Submitted December 13, 2021 at 03:06PM by 0xmusana
via reddit https://ift.tt/3ynytyw
musana.net
log4shell - Quick Guide
CVE-2021-44228 (a.k.a. log4shell) is a Remote Code Execution vulnerability in the Apache Log4j library, a Java-based logging tool widely used in applications around the world.
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228)
https://ift.tt/3s2FweG
Submitted December 13, 2021 at 03:59PM by freeqaz
via reddit https://ift.tt/3GAXl8L
https://ift.tt/3s2FweG
Submitted December 13, 2021 at 03:59PM by freeqaz
via reddit https://ift.tt/3GAXl8L
www.lunasec.io
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228 & CVE-2021-45046) | LunaSec
If you're using log4j 2 in your infrastructure, this guide will help you understand how to check if you're impacted and show you how to quickly and securely mitigate the issue.
pimps/JNDI-Exploit-Kit: added support to LDAP Serialized Payloads and attack path works in *ANY* java version
https://ift.tt/3pOF15j
Submitted December 13, 2021 at 06:24PM by Gallus
via reddit https://ift.tt/31YEvJr
https://ift.tt/3pOF15j
Submitted December 13, 2021 at 06:24PM by Gallus
via reddit https://ift.tt/31YEvJr
GitHub
GitHub - pimps/JNDI-Exploit-Kit: JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n.…
JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps v...
Diavol Ransomware
https://ift.tt/3dIla1W
Submitted December 13, 2021 at 06:14PM by TheDFIRReport
via reddit https://ift.tt/3lZyuDN
https://ift.tt/3dIla1W
Submitted December 13, 2021 at 06:14PM by TheDFIRReport
via reddit https://ift.tt/3lZyuDN
The DFIR Report
Diavol Ransomware
In the past, threat actors have used BazarLoader to deploy Ryuk and Conti ransomware, as reported on many occasions. In this intrusion, however, a BazarLoader infection resulted in deployment of Di…
Analysis of Initial In The Wild Attacks Exploiting Log4Shell/Log4J/CVE-2021-44228
https://ift.tt/31KRXRP
Submitted December 13, 2021 at 05:51PM by 0x636f6f6c
via reddit https://ift.tt/3oP1dwR
https://ift.tt/31KRXRP
Submitted December 13, 2021 at 05:51PM by 0x636f6f6c
via reddit https://ift.tt/3oP1dwR
Cado Security | Cloud Forensics & Incident Response
Analysis of Initial In The Wild Attacks Exploiting Log4Shell/Log4J/CVE-2021-44228 - Cado Security | Cloud Forensics & Incident…
Log4J is an open-source logging platform running on Java and built-in to many web platforms. Reports of exploitation started on December 9th.
(Log4Shell / Log4J) CVE-2021-44228 dummy Spring Boot target docker image
https://ift.tt/30peHWK
Submitted December 13, 2021 at 07:13PM by zshalo
via reddit https://ift.tt/3oOYOCf
https://ift.tt/30peHWK
Submitted December 13, 2021 at 07:13PM by zshalo
via reddit https://ift.tt/3oOYOCf
GitHub
GitHub - zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service
Contribute to zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service development by creating an account on GitHub.
Driver-Based Attacks: Past and Present
https://ift.tt/3IJNrDE
Submitted December 13, 2021 at 08:00PM by chicksdigthelongrun
via reddit https://ift.tt/30kgk7U
https://ift.tt/3IJNrDE
Submitted December 13, 2021 at 08:00PM by chicksdigthelongrun
via reddit https://ift.tt/30kgk7U
Rapid7
Driver-Based Attacks: Past and Present | Rapid7 Blog
Test driving the Log4Shell log4j vulnerability with various versions of Java and observing the network egress connections (tl;dr Java 8u191 onwards is less bad)
https://ift.tt/3dKAgUP
Submitted December 13, 2021 at 10:56PM by lowlevelprog
via reddit https://ift.tt/33rb4kd
https://ift.tt/3dKAgUP
Submitted December 13, 2021 at 10:56PM by lowlevelprog
via reddit https://ift.tt/33rb4kd
Chaser Systems
Log4Shell and its traces in a network egress filter | Chaser Systems
Test driving the Log4Shell vulnerability with various versions of Java and observing the network egress connections
Invoke-noPac - CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter
https://ift.tt/3e3K24B
Submitted December 14, 2021 at 02:06AM by v1brio
via reddit https://ift.tt/3ypBdeM
https://ift.tt/3e3K24B
Submitted December 14, 2021 at 02:06AM by v1brio
via reddit https://ift.tt/3ypBdeM
GitHub
GitHub - ricardojba/Invoke-noPac: .Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Scanner & Exploit noPac
.Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Scanner & Exploit noPac - GitHub - ricardojba/Invoke-noPac: .Net Assembly loader for the [CVE-2021-42287 - CVE-2021-42278] Sca...
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
https://ift.tt/3ygpX4h
Submitted December 14, 2021 at 12:23PM by 0xdea
via reddit https://ift.tt/3m2o9XC
https://ift.tt/3ygpX4h
Submitted December 14, 2021 at 12:23PM by 0xdea
via reddit https://ift.tt/3m2o9XC
fully independent exploit does not require any 3rd party binaries. The exploit spraying the payload to all possible logged HTTP Headers such as
https://ift.tt/3ESy3m8
Submitted December 14, 2021 at 12:54PM by EmirgianDark
via reddit https://ift.tt/3dOeG1t
https://ift.tt/3ESy3m8
Submitted December 14, 2021 at 12:54PM by EmirgianDark
via reddit https://ift.tt/3dOeG1t
GitHub
GitHub - cyberstruggle/L4sh: Log4Shell RCE Exploit - fully independent exploit does not require any 3rd party binaries.
Log4Shell RCE Exploit - fully independent exploit does not require any 3rd party binaries. - GitHub - cyberstruggle/L4sh: Log4Shell RCE Exploit - fully independent exploit does not require any 3rd ...
Log4J – A Look into Threat Actors Exploitation Attempts
https://ift.tt/3s0LVag
Submitted December 14, 2021 at 03:33PM by spyduecap
via reddit https://ift.tt/3s4YP6X
https://ift.tt/3s0LVag
Submitted December 14, 2021 at 03:33PM by spyduecap
via reddit https://ift.tt/3s4YP6X
Catonetworks
Log4J – A Look into Threat Actors Exploitation Attempts - Cato Networks
Recently, a critical zero-day vulnerability was discovered in Apache Log4j, a Java logging tool. Here's why this vulnerability is particularly dangerous.