Domain Persistence – Machine Account
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
https://ift.tt/3Fz2ptq
Submitted January 17, 2022 at 07:41PM by netbiosX
via reddit https://ift.tt/34RQtWR
Penetration Testing Lab
Domain Persistence – Machine Account
Machine accounts play a role in red team operations as in a number of techniques are utilized for privilege escalation, lateral movement and domain escalation. However, there are also cases which a…
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
https://ift.tt/3Ib7yJM
Submitted January 18, 2022 at 12:25AM by obilodeau
via reddit https://ift.tt/3KiuNDy
GoSecure
Capturing RDP NetNTLMv2 Hashes: Attack details and a Technical How-To Guide - GoSecure
We will explore RDP security modes and learn how NetNTLMv2 hash capture via monster-in-the-middle works, putting it into practice using PyRDP.
Stealing administrative JWT's through post auth SSRF - VMWare Workspace One Access (CVE-2021-22056)
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
https://ift.tt/3fwtoer
Submitted January 18, 2022 at 08:42AM by Mempodipper
via reddit https://ift.tt/3fPqPVb
Assetnote
Stealing administrative JWT's through post auth SSRF (CVE-2021-22056)
Application security issues found by Assetnote
Public exploit POC for critical windows http RCE impacting multiple windows versions
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
https://ift.tt/3fvhKjV
Submitted January 18, 2022 at 10:17AM by markcartertm
via reddit https://ift.tt/33tdHlR
GitHub
GitHub - ZZ-SOCMAP/CVE-2022-21907: HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907
HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907 - ZZ-SOCMAP/CVE-2022-21907
An attempt to understand container runtime
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
https://ift.tt/3tzgKUj
Submitted January 18, 2022 at 01:11PM by alt-glitch
via reddit https://ift.tt/3A8JhRK
computer insecurities
An attempt to understand container runtime
Demystifying containers with `containerd`
How to securely implement TLS certificate checking in Android apps
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
https://ift.tt/3FCgZjB
Submitted January 18, 2022 at 07:01PM by Masrepus
via reddit https://ift.tt/3A7EfFj
Guardsquare
Implementing TLS Certificate Checking in Android Apps | Guardsquare
Learn how you can avoid potential TLS certificate issues and secure your android app in cases where you need to deviate from the default approach.
Telenot Complex: Insecure AES Key Generation
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
https://ift.tt/3fA8P0F
Submitted January 18, 2022 at 09:39PM by 0xdea
via reddit https://ift.tt/3tDmR9W
X41 D-SEC
Telenot Complex: Insecure AES Key Generation
CVE-2021-34600: How predictable random numbers (literally) open the door for attackers: Our discovery of a flaw in the generation of AES keys, used for both physical and remote access, in a popular alarm system’s parameterization software. Includes a proof…
Dahua DVRs and Webcams bruteforcer at port 37777
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
https://ift.tt/3tIra49
Submitted January 18, 2022 at 09:33PM by falx1fer
via reddit https://ift.tt/3nBwgvc
GitHub
GitHub - d34db33f-1007/asleep_scanner: Dahua DVRs bruteforcer at port 37777
Dahua DVRs bruteforcer at port 37777. Contribute to d34db33f-1007/asleep_scanner development by creating an account on GitHub.
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data.
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
https://ift.tt/3tL4Bvk
Submitted January 18, 2022 at 09:27PM by falx1fer
via reddit https://ift.tt/3rs8d2S
GitHub
GitHub - d34db33f-1007/fuzz300: Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling…
Robust and blazing fast open-redirect vulnerability scanner with ability of recursevely crawling all of web-forms, entry points, or links with data. - GitHub - d34db33f-1007/fuzz300: Robust and bl...
Vulnerable AWS Lambda function - Initial access in cloud attacks
https://ift.tt/3nD8JK3
Submitted January 18, 2022 at 09:53PM by MiguelHzBz
via reddit https://ift.tt/34Vi8Gl
https://ift.tt/3nD8JK3
Submitted January 18, 2022 at 09:53PM by MiguelHzBz
via reddit https://ift.tt/34Vi8Gl
Sysdig
Vulnerable AWS Lambda function - Initial access in cloud attacks – Sysdig
The security research team explains the attack scenario with a vulnerable AWS Lambda function could be used by attackers.
A Beginner’s guide into Router Hacking and Firmware Emulation
https://ift.tt/3tDqSLR
Submitted January 18, 2022 at 09:53PM by secnigma
via reddit https://ift.tt/3IhIqB2
https://ift.tt/3tDqSLR
Submitted January 18, 2022 at 09:53PM by secnigma
via reddit https://ift.tt/3IhIqB2
SecNigma
A Beginner’s guide into Router Hacking and Firmware Emulation
Prelude This post is about the personal experiences of me; A noobie hacker- who is super new into router reversing and the challenges I had to face, the research I did and the things I had learned …
Zooming in on Zero-click Exploits (Project Zero)
https://ift.tt/3KlkYEU
Submitted January 19, 2022 at 12:37AM by albinowax
via reddit https://ift.tt/33G0yWl
https://ift.tt/3KlkYEU
Submitted January 19, 2022 at 12:37AM by albinowax
via reddit https://ift.tt/33G0yWl
Blogspot
Zooming in on Zero-click Exploits
Posted by Natalie Silvanovich, Project Zero Zoom is a video conferencing platform that has gained popularity throughout the pandemic. U...
SeeYouCM-Thief: Exploiting common misconfigurations in Cisco phone systems
https://ift.tt/3Afnsjt
Submitted January 19, 2022 at 06:09AM by HackingLZ
via reddit https://ift.tt/3fzGp70
https://ift.tt/3Afnsjt
Submitted January 19, 2022 at 06:09AM by HackingLZ
via reddit https://ift.tt/3fzGp70
TrustedSec
SeeYouCM-Thief: Exploiting common misconfigurations in Cisco phone systems - TrustedSec
Learn about using SeeYouCM-Thief, a new tool that exploits common misconfigurations seen in environments that deployed Cisco phones.
Mixed Messages: Busting Box’s MFA Methods | Varonis
https://ift.tt/3AcJWBz
Submitted January 18, 2022 at 08:54PM by VaronisThreatLabs
via reddit https://ift.tt/3Acv3zf
https://ift.tt/3AcJWBz
Submitted January 18, 2022 at 08:54PM by VaronisThreatLabs
via reddit https://ift.tt/3Acv3zf
Varonis
Mixed Messages: Busting Box’s MFA Methods | Varonis
Varonis Threat Labs discovered a way to bypass multi-factor authentication (MFA) for Box accounts that use an SMS code for login verification.
Demonstrating how phishermen abuse free hosting
https://ift.tt/3IgbVDp
Submitted January 19, 2022 at 03:10PM by df_works
via reddit https://ift.tt/3Ad3iXs
https://ift.tt/3IgbVDp
Submitted January 19, 2022 at 03:10PM by df_works
via reddit https://ift.tt/3Ad3iXs
GitHub
GitHub - dfaram7/phishers_abuse_free_hosting: Phishers abusing free javanoscript hosting
Phishers abusing free javanoscript hosting. Contribute to dfaram7/phishers_abuse_free_hosting development by creating an account on GitHub.
Introducing TREVORproxy and TREVORspray 2.0
https://ift.tt/3Ip8ACd
Submitted January 19, 2022 at 08:39PM by aconite33
via reddit https://ift.tt/32dRcAR
https://ift.tt/3Ip8ACd
Submitted January 19, 2022 at 08:39PM by aconite33
via reddit https://ift.tt/32dRcAR
Blacklanternsecurity
Introducing TREVORproxy and TREVORspray 2.0
Increasing the Speed and Effectiveness of Password Sprays
Gorillas: Special offer - unicorn slices, 150g 🦍❤️
https://ift.tt/3jMOQiL
Submitted January 19, 2022 at 04:31PM by moviuro
via reddit https://ift.tt/3fFyPI8
https://ift.tt/3jMOQiL
Submitted January 19, 2022 at 04:31PM by moviuro
via reddit https://ift.tt/3fFyPI8
zerforschung.org
Gorillas: Special offer - unicorn slices, 150g 🦍❤️
We felt more like “Oh fuck, Databreach”
Dieser Artikel ist auch auf deutsch erschienen.
During the pandemic, grocery delivery services gained popularity.
New players on the market offer delivery in under an hour.
One of them is Gorillas, which…
Dieser Artikel ist auch auf deutsch erschienen.
During the pandemic, grocery delivery services gained popularity.
New players on the market offer delivery in under an hour.
One of them is Gorillas, which…
CryptoLyzer: A comprehensive cryptographic settings analyzer (introduction with a comparison of cryptographic settings analyzers)
https://ift.tt/3qHowcY
Submitted January 19, 2022 at 10:07PM by c0r0n3r
via reddit https://ift.tt/3rvEXIy
https://ift.tt/3qHowcY
Submitted January 19, 2022 at 10:07PM by c0r0n3r
via reddit https://ift.tt/3rvEXIy
Szilárd Pfeiffer
CryptoLyzer: A comprehensive cryptographic settings analyzer
CryptoLyzer is a multiprotocol cryptographic settings analyzer with SSL/TLS, SSH, and HTTP header analysis ability. The main purpose of the tool is to tell you what kind of cryptographic related settings are enabled on a client or server.
Privilege escalation in Acer Care Center by @last0x00 and @APTortellini
https://ift.tt/3rDQBkK
Submitted January 19, 2022 at 10:01PM by last0x00
via reddit https://ift.tt/3nHJWVr
https://ift.tt/3rDQBkK
Submitted January 19, 2022 at 10:01PM by last0x00
via reddit https://ift.tt/3nHJWVr
APT::WTF - APTortellini’s blog
🇬🇧 The ace(r) up your sleeve!
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
OctopusWAF is an open-source web application firewall made in C language and uses libevent resources.
https://ift.tt/3eOw2em
Submitted January 20, 2022 at 11:18AM by CoolerVoid
via reddit https://ift.tt/3qLDdvE
https://ift.tt/3eOw2em
Submitted January 20, 2022 at 11:18AM by CoolerVoid
via reddit https://ift.tt/3qLDdvE
GitHub
GitHub - CoolerVoid/OctopusWAF: OctopusWAF is a WAF( Web application firewall) with high performance, made in C language and use…
OctopusWAF is a WAF( Web application firewall) with high performance, made in C language and use libevent. - GitHub - CoolerVoid/OctopusWAF: OctopusWAF is a WAF( Web application firewall) with high...
SMBSR made it through another lockdown with some new interesting skills (and fixes). Go check out and judge it (respectfully)
https://ift.tt/3H9SBrL
Submitted January 20, 2022 at 03:09PM by oldboy21
via reddit https://ift.tt/3nGhH9s
https://ift.tt/3H9SBrL
Submitted January 20, 2022 at 03:09PM by oldboy21
via reddit https://ift.tt/3nGhH9s
GitHub
GitHub - oldboy21/SMBSR: Lookup for interesting stuff in SMB shares
Lookup for interesting stuff in SMB shares. Contribute to oldboy21/SMBSR development by creating an account on GitHub.