DNS records of 1% .fi domains exposed through Zone Transfers
https://ift.tt/3FrccBI
Submitted January 13, 2022 at 09:20PM by ValtteriLe
via reddit https://ift.tt/3Gpkifi
https://ift.tt/3FrccBI
Submitted January 13, 2022 at 09:20PM by ValtteriLe
via reddit https://ift.tt/3Gpkifi
Shufflingbytes
DNS records of 1% .fi domains exposed through Zone Transfers
Post describing my experiment of finding out how commonly nameservers are misconfigured to allow zone transfers
SSH Bastion Host Best Practices
https://ift.tt/3zYb9rz
Submitted January 13, 2022 at 11:22PM by old-gregg
via reddit https://ift.tt/3GqTHP7
https://ift.tt/3zYb9rz
Submitted January 13, 2022 at 11:22PM by old-gregg
via reddit https://ift.tt/3GqTHP7
Goteleport
SSH Bastion host best practices: How to Build and Deploy a Security-Hardened SSH Bastion Host
Learn best practices to build and deploy a security-hardened SSH bastion host based on OpenSSH server.
BreakingFormation: Orca Security Research Team Discovers AWS CloudFormation Vulnerability
https://ift.tt/33gXHTV
Submitted January 14, 2022 at 12:04AM by eberkut
via reddit https://ift.tt/33uhdfp
https://ift.tt/33gXHTV
Submitted January 14, 2022 at 12:04AM by eberkut
via reddit https://ift.tt/33uhdfp
Complete Cloud Security in Minutes | Orca Security
Orca Discovers AWS CloudFormation Vulnerability - Orca Security
Orca Security’s vulnerability researcher, Tzah Pahima, discovered a zero day AWS CloudFormation vulnerability, which AWS quickly mitigated within 6 days.
Forensics Analysis of the NSO Group’s Pegasus Spyware
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
https://ift.tt/3I66RSa
Submitted January 14, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/3rf8lme
LIFARS, Your Cyber Resiliency Partner
Forensics Analysis of the NSO Group’s Pegasus Spyware
NSO’s Group Pegasus spyware was mentioned multiple times during 2021 in the media. It has been heavily analyzed by organizations such as Amnesty Forensics Analysis of the NSO Group’s Pegasus Spyware
Propagating phishing via Slack webhooks
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
https://ift.tt/3rfqL6m
Submitted January 14, 2022 at 03:43AM by amirshk
via reddit https://ift.tt/3npQ0BI
Medium
Propagating phishing via Slack webhooks
“Are slack webhooks a secret or not?”
A Deep Dive into The Grief Ransomware’s Capabilities
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
https://ift.tt/3rdlTyk
Submitted January 15, 2022 at 01:39AM by CyberMasterV
via reddit https://ift.tt/33wW30e
10 real-world stories of how we’ve compromised CI/CD pipelines
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
https://ift.tt/3Grpmjt
Submitted January 15, 2022 at 11:03AM by digicat
via reddit https://ift.tt/3qtcu6I
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
PinataHub: Exposing what developers push is OS projects
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
https://ift.tt/3Idz4qd
Submitted January 15, 2022 at 03:24PM by sp00kyphiss
via reddit https://ift.tt/3GzViSA
pinatahub.incognita.tech
PinataHub - Explore the world of leaked secrets in GitHub.
PinataHub is the most wide and comprehensive database of publicly leaked secrets from careless developers.
A Detailed Guide to cracking the OSWE Certification
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
https://ift.tt/3quPeVZ
Submitted January 15, 2022 at 07:56PM by YashitM
via reddit https://ift.tt/3tvIA3x
reddit
A Detailed Guide to cracking the OSWE Certification
Posted in r/netsec by u/YashitM • 7 points and 2 comments
IndexedDB in Safari 15 leaks your browsing activity in real time
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
https://ift.tt/3A3ZMyk
Submitted January 15, 2022 at 09:57PM by Synchisis
via reddit https://ift.tt/3GCfGTd
Fingerprintjs
Exploiting IndexedDB API information leaks in Safari 15
In this article we discuss a software bug introduced in Safari 15’s implementation of the IndexedDB API that lets any website track your internet activity and even reveal your identity.
Free copy of The ssh Plumber's Handbook
https://ift.tt/3n9gw2V
Submitted January 16, 2022 at 11:44AM by markcartertm
via reddit https://ift.tt/3K9IIMh
https://ift.tt/3n9gw2V
Submitted January 16, 2022 at 11:44AM by markcartertm
via reddit https://ift.tt/3K9IIMh
GitHub
GitHub - opsdisk/the_cyber_plumbers_handbook: Free copy of The Cyber Plumber's Handbook
Free copy of The Cyber Plumber's Handbook. Contribute to opsdisk/the_cyber_plumbers_handbook development by creating an account on GitHub.
You're running untrusted code!
https://ift.tt/3FAwcBI
Submitted January 17, 2022 at 12:27AM by nfrankel
via reddit https://ift.tt/3qyWErt
https://ift.tt/3FAwcBI
Submitted January 17, 2022 at 12:27AM by nfrankel
via reddit https://ift.tt/3qyWErt
A Java geek
You're running untrusted code!
Last December, Log4Shell shortened the nights of many people in the JVM world. Worse, using the earthquake analogy caused many aftershocks after the initial quake. I immediately made the connection between Log4Shell and the Security Manager. At first, I didn’t…
Domain Persistence – Machine Account
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
Penetration Testing Lab
Domain Persistence – Machine Account
Machine accounts play a role in red team operations as in a number of techniques are utilized for privilege escalation, lateral movement and domain escalation. However, there are also cases which a…
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
GoSecure
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
We will explore RDP security modes and learn how NetNTLMv2 hash capture via monster-in-the-middle works, putting it into practice using PyRDP.
Stealing administrative JWT's through post auth SSRF - VMWare Workspace One Access (CVE-2021-22056)
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
Assetnote
Stealing administrative JWT's through post auth SSRF (CVE-2021-22056)
Application security issues found by Assetnote
Public exploit POC for critical windows http RCE impacting multiple windows versions
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
GitHub
GitHub - ZZ-SOCMAP/CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907 - ZZ-SOCMAP/CVE-2022-21907
An attempt to understand container runtime
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
computer insecurities
An attempt to understand container runtime
Demystifying containers with `containerd`
How to securely implement TLS certificate checking in Android apps
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
Guardsquare
Implementing TLS Certificate Checking in Android Apps | Guardsquare
Learn how you can avoid potential TLS certificate issues and secure your android app in cases where you need to deviate from the default approach.
Telenot Complex: Insecure AES Key Generation
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
X41 D-SEC
Telenot Complex: Insecure AES Key Generation
CVE-2021-34600: How predictable random numbers (literally) open the door for attackers: Our discovery of a flaw in the generation of AES keys, used for both physical and remote access, in a popular alarm system’s parameterization software. Includes a proof…
Dahua DVRs and Webcams bruteforcer at port 37777
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
GitHub
GitHub - d34db33f-1007/asleep_scanner: Dahua DVRs bruteforcer at port 37777
Dahua DVRs bruteforcer at port 37777. Contribute to d34db33f-1007/asleep_scanner development by creating an account on GitHub.
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data.
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
GitHub
GitHub - d34db33f-1007/fuzz300: Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling…
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data. - GitHub - d34db33f-1007/fuzz300: Robust and bl...