V8 Heap pwn and /dev/memes - WebOS Root LPE
https://ift.tt/3qrAgPu
Submitted December 28, 2021 at 12:08PM by DavidBuchanan
via reddit https://ift.tt/3qsEd6f
https://ift.tt/3qrAgPu
Submitted December 28, 2021 at 12:08PM by DavidBuchanan
via reddit https://ift.tt/3qsEd6f
reddit
V8 Heap pwn and /dev/memes - WebOS Root LPE
Posted in r/netsec by u/DavidBuchanan • 17 points and 0 comments
PHP LFI with Nginx Assistance
https://ift.tt/3sA7oXT
Submitted December 28, 2021 at 02:29PM by dL2Hj4wR
via reddit https://ift.tt/3FBYtZx
https://ift.tt/3sA7oXT
Submitted December 28, 2021 at 02:29PM by dL2Hj4wR
via reddit https://ift.tt/3FBYtZx
bierbaumer.net
0xbb - PHP LFI with Nginx Assistance
New method to exploit PHP local file inclusion (LFI) vulnerabilities with Nginx assistance.
Pet surveillance with Falco
https://ift.tt/3pzvYGw
Submitted December 28, 2021 at 10:13PM by MiguelHzBz
via reddit https://ift.tt/3sN6tmO
https://ift.tt/3pzvYGw
Submitted December 28, 2021 at 10:13PM by MiguelHzBz
via reddit https://ift.tt/3sN6tmO
Sysdig
Pet surveillance with Falco - Home Security – Sysdig
Falco with plugin support is aiming to become the standard way to secure your infrastructure, the cloud one, and even the physical one.
Using laser speckle patterns to see keypresses etc.
https://ift.tt/3hoTVfd
Submitted December 28, 2021 at 10:06PM by anfractuosus
via reddit https://ift.tt/3mySRYH
https://ift.tt/3hoTVfd
Submitted December 28, 2021 at 10:06PM by anfractuosus
via reddit https://ift.tt/3mySRYH
Anfractuosity
Fun with speckle patterns
I recently came across a really fascinating video - https://www.youtube.com/watch?v=tYFLze9VwB0 where they make use of a micro laser projector to generate a speckle pattern on a surface and then photograph it with a DSLR. They then simply touch a surface…
Integrating Canary Tokens with Microsoft Sentinel SIEM
https://ift.tt/3mA2Mx2
Submitted December 28, 2021 at 09:51PM by m_rothe
via reddit https://ift.tt/3ExJy1d
https://ift.tt/3mA2Mx2
Submitted December 28, 2021 at 09:51PM by m_rothe
via reddit https://ift.tt/3ExJy1d
reddit
Integrating Canary Tokens with Microsoft Sentinel SIEM
Posted in r/netsec by u/m_rothe • 1 point and 0 comments
IRIS - A web collaborative platform for incident response analysts allowing to share investigations at a technical level
https://ift.tt/32IF8qV
Submitted December 29, 2021 at 12:47AM by Maijin
via reddit https://ift.tt/3qtmpId
https://ift.tt/32IF8qV
Submitted December 29, 2021 at 12:47AM by Maijin
via reddit https://ift.tt/3qtmpId
reddit
IRIS - A web collaborative platform for incident response analysts...
Posted in r/netsec by u/Maijin • 12 points and 1 comment
New Log4j CVE - CVE-2021-44832. Another JNDI RCE. Fixed in latest release.
https://ift.tt/3Jrm954
Submitted December 29, 2021 at 03:12AM by emmainvincible
via reddit https://ift.tt/3ezbXJE
https://ift.tt/3Jrm954
Submitted December 29, 2021 at 03:12AM by emmainvincible
via reddit https://ift.tt/3ezbXJE
cve.mitre.org
CVE -
CVE-2021-44832
CVE-2021-44832
CVE® is a list of records — each containing an identification number, a denoscription, and at least one public reference — for publicly known cybersecurity vulnerabilities. The mission of the CVE Program is to identify, define, and catalog publicly disclosed…
Turning bad SSRF to good SSRF: Websphere Portal
https://ift.tt/3eyrjOw
Submitted December 29, 2021 at 02:58AM by Mempodipper
via reddit https://ift.tt/3Jss1eo
https://ift.tt/3eyrjOw
Submitted December 29, 2021 at 02:58AM by Mempodipper
via reddit https://ift.tt/3Jss1eo
How I built the PoC for the Log4j zero-day security vulnerability
https://ift.tt/3mFwSzc
Submitted December 29, 2021 at 08:24PM by melbadry9
via reddit https://ift.tt/3zawGxa
https://ift.tt/3mFwSzc
Submitted December 29, 2021 at 08:24PM by melbadry9
via reddit https://ift.tt/3zawGxa
blog.melbadry9.xyz
How I built the PoC for the Log4j zero-day security vulnerability
Insights on first few hours of Log4Shell zero-day, creating and sharing PoC with the community.
Flagpro malware is threatening enterprises and is backed by Chinese hackers
https://ift.tt/3Fy0KFb
Submitted December 29, 2021 at 09:11PM by Gengar-boy
via reddit https://ift.tt/3FCpbkY
https://ift.tt/3Fy0KFb
Submitted December 29, 2021 at 09:11PM by Gengar-boy
via reddit https://ift.tt/3FCpbkY
The Cybersecurity Times
Flagpro malware is threatening enterprises and is backed by Chinese hackers - The Cybersecurity Times
Japanese companies are being targeted by a novel malware called Flagpro developed by BlackTech cyber-espionage APT group.
PrintNightmare and SSH Tunnels
https://ift.tt/3pDiLwo
Submitted December 30, 2021 at 02:11AM by m_edmondson
via reddit https://ift.tt/3FIUWZy
https://ift.tt/3pDiLwo
Submitted December 30, 2021 at 02:11AM by m_edmondson
via reddit https://ift.tt/3FIUWZy
Marcus Edmondson | Threat Hunting | Information Security
PrintNightmare and SSH Tunnels for Fun
Today I wanted to cover a subject that has been covered many times before, but writing about the techniques and tools I am learning helps me solidify my knowledge so here we go. Today’s post …
Bootkit samples
https://ift.tt/3qxOazv
Submitted December 30, 2021 at 02:53PM by hardenedvault
via reddit https://ift.tt/3z8LXhU
https://ift.tt/3qxOazv
Submitted December 30, 2021 at 02:53PM by hardenedvault
via reddit https://ift.tt/3z8LXhU
GitHub
GitHub - hardenedvault/bootkit-samples: Bootkit sample for firmware attack
Bootkit sample for firmware attack. Contribute to hardenedvault/bootkit-samples development by creating an account on GitHub.
I wrote a replacement for Pyrasite to inject code into Python processes on Kubernetes
https://ift.tt/33Zd8jy
Submitted December 30, 2021 at 08:26PM by nyellin
via reddit https://ift.tt/3FILYvd
https://ift.tt/33Zd8jy
Submitted December 30, 2021 at 08:26PM by nyellin
via reddit https://ift.tt/3FILYvd
GitHub
GitHub - robusta-dev/debug-toolkit: A modern code-injection framework for Python. Like Pyrasite but Kubernetes-aware.
A modern code-injection framework for Python. Like Pyrasite but Kubernetes-aware. - GitHub - robusta-dev/debug-toolkit: A modern code-injection framework for Python. Like Pyrasite but Kubernetes-aw...
441K RedLine Malware affected accounts are included by Have I Been Pwned
https://ift.tt/32S6I5r
Submitted December 31, 2021 at 02:20PM by IT_band
via reddit https://ift.tt/32KGtxE
https://ift.tt/32S6I5r
Submitted December 31, 2021 at 02:20PM by IT_band
via reddit https://ift.tt/32KGtxE
The Cybersecurity Times
441K RedLine Malware affected accounts are included by Have I Been Pwned - The Cybersecurity Times
If you're wondering whether your email account is compromised by RedLine malware, you can check the same with 'Have I Been Pwned' website as RedLine malware has now 441,000 accounts that are compromised.
New year, new password habit
https://ift.tt/3JzWJme
Submitted December 31, 2021 at 08:07PM by Novel_Author
via reddit https://ift.tt/3mOa4xr
https://ift.tt/3JzWJme
Submitted December 31, 2021 at 08:07PM by Novel_Author
via reddit https://ift.tt/3mOa4xr
reddit
New year, new password habit
Posted in r/netsec by u/Novel_Author • 0 points and 3 comments
New year, new password habit
https://ift.tt/3JuSM1W
Submitted December 31, 2021 at 08:05PM by Novel_Author
via reddit https://ift.tt/3mO9PCx
https://ift.tt/3JuSM1W
Submitted December 31, 2021 at 08:05PM by Novel_Author
via reddit https://ift.tt/3mO9PCx
GitHub
GitHub - eddiechu/passbox: Compose your complex password
Compose your complex password. Contribute to eddiechu/passbox development by creating an account on GitHub.
serpentine - C++/Win32/Boost Windows RAT (Remote Administration Tool) with a multiplatform Java/Spring RESTful C2 server and Go, C++/Qt5 frontends
https://ift.tt/3cMxbjX
Submitted December 31, 2021 at 11:50PM by jafarlihi
via reddit https://ift.tt/3zgYLm9
https://ift.tt/3cMxbjX
Submitted December 31, 2021 at 11:50PM by jafarlihi
via reddit https://ift.tt/3zgYLm9
GitHub
GitHub - jafarlihi/serpentine: C++/Win32/Boost Windows RAT (Remote Administration Tool) with a multiplatform Java/Spring RESTful…
C++/Win32/Boost Windows RAT (Remote Administration Tool) with a multiplatform Java/Spring RESTful C2 server and Go, C++/Qt5 frontends - GitHub - jafarlihi/serpentine: C++/Win32/Boost Windows RAT (R...
Build your own reconnaissance system with Osmedeus Next Generation
https://ift.tt/3JzF7a0
Submitted January 01, 2022 at 02:30PM by j3ssiejjj
via reddit https://ift.tt/3Jqptxs
https://ift.tt/3JzF7a0
Submitted January 01, 2022 at 02:30PM by j3ssiejjj
via reddit https://ift.tt/3Jqptxs
reddit
Build your own reconnaissance system with Osmedeus Next Generation
Posted in r/netsec by u/j3ssiejjj • 54 points and 5 comments
Fixing the Unfixable: Story of a Google Cloud SSRF
https://ift.tt/3EIw0zW
Submitted January 01, 2022 at 07:52PM by xdavidhu
via reddit https://ift.tt/3pHMq7B
https://ift.tt/3EIw0zW
Submitted January 01, 2022 at 07:52PM by xdavidhu
via reddit https://ift.tt/3pHMq7B
bugs.xdavidhu.me
Fixing the Unfixable: Story of a Google Cloud SSRF
David Schütz's bug bounty writeups
I found and fixed a vulnerability in Python's source code
https://ift.tt/3EtHasa
Submitted January 01, 2022 at 11:07PM by sn1pr0s
via reddit https://ift.tt/3mNvE5g
https://ift.tt/3EtHasa
Submitted January 01, 2022 at 11:07PM by sn1pr0s
via reddit https://ift.tt/3mNvE5g
ExpiredDomains.com
tldr.engineering is for sale! Check it out on ExpiredDomains.com
tldr.engineering is available for sale! Check it out on ExpiredDomains.com. tldr.engineering is in high demand, secure it today!
How to Detect DNS Tunneling in the Network
https://ift.tt/3xTwrpA
Submitted January 02, 2022 at 02:59PM by whyisvan
via reddit https://ift.tt/3pLu19P
https://ift.tt/3xTwrpA
Submitted January 02, 2022 at 02:59PM by whyisvan
via reddit https://ift.tt/3pLu19P
Cato Networks
How to Detect DNS Tunneling in the Network?
In the past several years, we have seen multiple malware samples using DNS tunneling to exfiltrate data. In June, Microsoft Security Intelligence warned about BazarCall (or BazaLoader), a scam infecting victims with malware to get them to call a phony call…