A Beginner's Story on How a Cheapo Standard Issue Router was hacked.
https://ift.tt/3zkg1XG
Submitted January 03, 2022 at 11:58PM by secnigma
via reddit https://ift.tt/3pOa8yZ
https://ift.tt/3zkg1XG
Submitted January 03, 2022 at 11:58PM by secnigma
via reddit https://ift.tt/3pOa8yZ
SecNigma
The Story of How I Hacked my ISP’s Cheapo Standard Issue Router
Prelude OptiLink is a company based on India that specializes in manufacturing Networking Devices. Two of the largest Internet Service Providers in this country have provided / still providing Opti…
Domain Persistence - AdminSDHolder
https://ift.tt/3JDchpd
Submitted January 04, 2022 at 06:37PM by netbiosX
via reddit https://ift.tt/3mV28dw
https://ift.tt/3JDchpd
Submitted January 04, 2022 at 06:37PM by netbiosX
via reddit https://ift.tt/3mV28dw
Penetration Testing Lab
Domain Persistence – AdminSDHolder
Utilizing existing Microsoft features for offensive operations is very common during red team assessments as it provides the opportunity to blend in with the environment and stay undetected. Micros…
Cache Poisoning at Scale
https://ift.tt/3JeJp6e
Submitted January 04, 2022 at 06:33PM by albinowax
via reddit https://ift.tt/3JHQv3o
https://ift.tt/3JeJp6e
Submitted January 04, 2022 at 06:33PM by albinowax
via reddit https://ift.tt/3JHQv3o
Sears Garage Door Signal Reverse Engineering
https://ift.tt/3HBmKzs
Submitted January 04, 2022 at 09:30PM by mdulin2
via reddit https://ift.tt/3eMS3Lq
https://ift.tt/3HBmKzs
Submitted January 04, 2022 at 09:30PM by mdulin2
via reddit https://ift.tt/3eMS3Lq
reddit
Sears Garage Door Signal Reverse Engineering
Posted in r/netsec by u/mdulin2 • 2 points and 0 comments
Inoitsu email breach analysis gives a summary of data found in all breaches for an address. This makes it much easier to tell what info may be at risk. Shows breakdowns of the type of data found and an unique Relative Exposure Rating to help make sense of the overall data risk. Instant results.
https://ift.tt/3HsIm14
Submitted January 05, 2022 at 08:58AM by inoitsu
via reddit https://ift.tt/3JI7RNW
https://ift.tt/3HsIm14
Submitted January 05, 2022 at 08:58AM by inoitsu
via reddit https://ift.tt/3JI7RNW
Hotsheet
Email address breach detection and hacked data summary.
Rank your email address's breach exposure level from 1 - 10. Shows correlated personal info from all data breaches and hack events.
Microsoft releases Windows Server Update to fix Remote Desktop Issues
https://ift.tt/3EZE7Iy
Submitted January 05, 2022 at 12:19PM by 97-007
via reddit https://ift.tt/3mZxcZL
https://ift.tt/3EZE7Iy
Submitted January 05, 2022 at 12:19PM by 97-007
via reddit https://ift.tt/3mZxcZL
The Cybersecurity Times
Microsoft releases Windows Server Update to fix Remote Desktop Issues - The Cybersecurity Times
Microsoft released a crucial emergency out-of-band update for Windows Server addressing the Remote Desktop Issue.
The Kubernetes (K8s) Network Security Effect
https://ift.tt/3HArZPT
Submitted January 05, 2022 at 02:16PM by catgoddim
via reddit https://ift.tt/3sW9zFd
https://ift.tt/3HArZPT
Submitted January 05, 2022 at 02:16PM by catgoddim
via reddit https://ift.tt/3sW9zFd
ARMO
The Kubernetes (K8s) Network Security Effect | ARMO
Learn everything about the Kubernetes (K8s) network security effect from Amir Kaushansky, ARMO's VP Product. Read this insightful blog post here!
We desperately need a way to rapidly notify people of high-impact vulnerabilities, so I built one
https://ift.tt/3EVLlNT
Submitted January 05, 2022 at 08:09PM by sullivanmatt
via reddit https://ift.tt/3mTEgqX
https://ift.tt/3EVLlNT
Submitted January 05, 2022 at 08:09PM by sullivanmatt
via reddit https://ift.tt/3mTEgqX
Matt's Life Bytes
We desperately need a way to rapidly notify people of high-impact vulnerabilities, so I built one: BugAlert.org
Introducing bugalert.org, a free and open-source service for alerting security and IT professionals of high-impact and 0day vulnerabilities by email, SMS, and phone calls (and via Twitter).
Best Practices for Securing SSH in 2022
https://ift.tt/3G0Q3Lt
Submitted January 06, 2022 at 12:04AM by old-gregg
via reddit https://ift.tt/331SnTV
https://ift.tt/3G0Q3Lt
Submitted January 06, 2022 at 12:04AM by old-gregg
via reddit https://ift.tt/331SnTV
Goteleport
5 Best Practices for Securing SSH | Teleport
This article explores 5 SSH best practices you should observe to boost the security of your infrastructure.
PPTShots - Unintentionally shared data in PowerPoint presentations
https://ift.tt/3eWcTId
Submitted January 06, 2022 at 02:13AM by df_works
via reddit https://ift.tt/3JVqLB0
https://ift.tt/3eWcTId
Submitted January 06, 2022 at 02:13AM by df_works
via reddit https://ift.tt/3JVqLB0
GitHub
GitHub - dfaram7/pptshots: Finding sensitive information in the trimmed parts of cropped images
Finding sensitive information in the trimmed parts of cropped images - GitHub - dfaram7/pptshots: Finding sensitive information in the trimmed parts of cropped images
SANS Christmas Challenge 2021 - Write-up
https://ift.tt/337rEoS
Submitted January 06, 2022 at 04:39PM by the-useless-one
via reddit https://ift.tt/3JHT9qd
https://ift.tt/337rEoS
Submitted January 06, 2022 at 04:39PM by the-useless-one
via reddit https://ift.tt/3JHT9qd
Tek Fog: An App for Online Troops to Automate Hate, Manipulate Trends
https://ift.tt/3zw0Evp
Submitted January 06, 2022 at 04:10PM by goodwallboy
via reddit https://ift.tt/3qNlPoW
https://ift.tt/3zw0Evp
Submitted January 06, 2022 at 04:10PM by goodwallboy
via reddit https://ift.tt/3qNlPoW
The Wire
Tek Fog: An App With BJP Footprints for Cyber Troops to Automate Hate, Manipulate Trends
The Wire investigates claims behind the use of ‘Tek Fog’, a highly sophisticated app used by online operatives to hijack major social media and encrypted messaging platforms and amplify right-wing propaganda to a domestic audience.
Asimov Security | Enterprise Ready Security Solutions For Robotics
https://ift.tt/3zuZj8n
Submitted January 06, 2022 at 07:44PM by Da5h_Solo
via reddit https://ift.tt/3eZrgM5
https://ift.tt/3zuZj8n
Submitted January 06, 2022 at 07:44PM by Da5h_Solo
via reddit https://ift.tt/3eZrgM5
Asimovsec
Asimov Security | Enterprise Ready Cyber Security For Robotics
Enterprise Ready Cyber Security For Robotics & Robotic Components
Announcing the first open source security tool for Heroku!
https://ift.tt/32SvUc8
Submitted January 06, 2022 at 11:48PM by cloud-defender
via reddit https://ift.tt/3q0SIPH
https://ift.tt/32SvUc8
Submitted January 06, 2022 at 11:48PM by cloud-defender
via reddit https://ift.tt/3q0SIPH
GitHub
GitHub - heroku/heroku-guardian: Easy to use CLI security checks for the Heroku platform. Validate baseline security configurations…
Easy to use CLI security checks for the Heroku platform. Validate baseline security configurations for your own Heroku deployments. - GitHub - heroku/heroku-guardian: Easy to use CLI security check...
Garlicshare - Private and secure file sharing over the Tor network
https://ift.tt/3qW6yC9
Submitted January 07, 2022 at 12:06AM by ILDVUCE
via reddit https://ift.tt/31vpVJE
https://ift.tt/3qW6yC9
Submitted January 07, 2022 at 12:06AM by ILDVUCE
via reddit https://ift.tt/31vpVJE
GitHub
GitHub - R4yGM/garlicshare: Private and self-hosted file sharing over the Tor network written in golang
Private and self-hosted file sharing over the Tor network written in golang - GitHub - R4yGM/garlicshare: Private and self-hosted file sharing over the Tor network written in golang
The JNDI Strikes Back – Unauthenticated RCE in H2 Database Console
https://ift.tt/3pZHISD
Submitted January 07, 2022 at 02:52AM by SRMish3
via reddit https://ift.tt/3F7bXeF
https://ift.tt/3pZHISD
Submitted January 07, 2022 at 02:52AM by SRMish3
via reddit https://ift.tt/3F7bXeF
JFrog
JNDI-Related Vulnerability Discovered in H2 Database Console
Critical JNDI-based vulnerability exploiting the same root cause of Log4Shell. Read more from the JFrog Security Research Team describing the attack vector >
PHP 7.3-8.1 disable_functions bypass using string concatenation (PoC)
https://ift.tt/33a2oyi
Submitted January 07, 2022 at 07:42AM by dradzenglor
via reddit https://ift.tt/3t9lrnt
https://ift.tt/33a2oyi
Submitted January 07, 2022 at 07:42AM by dradzenglor
via reddit https://ift.tt/3t9lrnt
GitHub
exploits/php-concat-bypass at master · mm0r1/exploits
Pwn stuff. Contribute to mm0r1/exploits development by creating an account on GitHub.
Lopsided routing, a stealthy hole punch into FortiGate
https://ift.tt/33fwv7P
Submitted January 07, 2022 at 11:18PM by oherrala
via reddit https://ift.tt/34piFQB
https://ift.tt/33fwv7P
Submitted January 07, 2022 at 11:18PM by oherrala
via reddit https://ift.tt/34piFQB
Medium
Lopsided routing, a stealthy hole punch into FortiGate
A critical infrastructure player found a way for traffic to leak out from their isolated network and asked us for help. They had updated…
Mutual Authentication: A Component of Zero Trust
https://ift.tt/32SZZIS
Submitted January 08, 2022 at 01:26AM by alexfornuto
via reddit https://ift.tt/3G5plS8
https://ift.tt/32SZZIS
Submitted January 08, 2022 at 01:26AM by alexfornuto
via reddit https://ift.tt/3G5plS8
Pomerium
Mutual Authentication | Pomerium
This page describes the concept of mutual authentication and why it's important.
NPM might be executing malicious code in your CI without your knowledge
https://ift.tt/3G2sHoO
Submitted January 08, 2022 at 03:39AM by words_are_sacred
via reddit https://ift.tt/3q7u2Fa
https://ift.tt/3G2sHoO
Submitted January 08, 2022 at 03:39AM by words_are_sacred
via reddit https://ift.tt/3q7u2Fa
Medium
NPM might be executing malicious code in your CI without your knowledge
How to tell if you are using NPM safely within your CI
Project to Regularly and Automatically Update Docker Images that contains a lot of NetSec related tools
https://ift.tt/33dL77I
Submitted January 08, 2022 at 07:53PM by deleee
via reddit https://ift.tt/31DZj9r
https://ift.tt/33dL77I
Submitted January 08, 2022 at 07:53PM by deleee
via reddit https://ift.tt/31DZj9r
GitHub
GitHub - cybersecsi/RAUDI: A repo to automatically generate and keep updated a series of Docker images through GitHub Actions.
A repo to automatically generate and keep updated a series of Docker images through GitHub Actions. - GitHub - cybersecsi/RAUDI: A repo to automatically generate and keep updated a series of Docker...