CryptoLyzer: A comprehensive cryptographic settings analyzer (introduction with a comparison of cryptographic settings analyzers)
https://ift.tt/3qHowcY
Submitted January 19, 2022 at 10:07PM by c0r0n3r
via reddit https://ift.tt/3rvEXIy
https://ift.tt/3qHowcY
Submitted January 19, 2022 at 10:07PM by c0r0n3r
via reddit https://ift.tt/3rvEXIy
Szilárd Pfeiffer
CryptoLyzer: A comprehensive cryptographic settings analyzer
CryptoLyzer is a multiprotocol cryptographic settings analyzer with SSL/TLS, SSH, and HTTP header analysis ability. The main purpose of the tool is to tell you what kind of cryptographic related settings are enabled on a client or server.
Privilege escalation in Acer Care Center by @last0x00 and @APTortellini
https://ift.tt/3rDQBkK
Submitted January 19, 2022 at 10:01PM by last0x00
via reddit https://ift.tt/3nHJWVr
https://ift.tt/3rDQBkK
Submitted January 19, 2022 at 10:01PM by last0x00
via reddit https://ift.tt/3nHJWVr
APT::WTF - APTortellini’s blog
🇬🇧 The ace(r) up your sleeve!
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
OctopusWAF is an open-source web application firewall made in C language and uses libevent resources.
https://ift.tt/3eOw2em
Submitted January 20, 2022 at 11:18AM by CoolerVoid
via reddit https://ift.tt/3qLDdvE
https://ift.tt/3eOw2em
Submitted January 20, 2022 at 11:18AM by CoolerVoid
via reddit https://ift.tt/3qLDdvE
GitHub
GitHub - CoolerVoid/OctopusWAF: OctopusWAF is a WAF( Web application firewall) with high performance, made in C language and use…
OctopusWAF is a WAF( Web application firewall) with high performance, made in C language and use libevent. - GitHub - CoolerVoid/OctopusWAF: OctopusWAF is a WAF( Web application firewall) with high...
SMBSR made it through another lockdown with some new interesting skills (and fixes). Go check out and judge it (respectfully)
https://ift.tt/3H9SBrL
Submitted January 20, 2022 at 03:09PM by oldboy21
via reddit https://ift.tt/3nGhH9s
https://ift.tt/3H9SBrL
Submitted January 20, 2022 at 03:09PM by oldboy21
via reddit https://ift.tt/3nGhH9s
GitHub
GitHub - oldboy21/SMBSR: Lookup for interesting stuff in SMB shares
Lookup for interesting stuff in SMB shares. Contribute to oldboy21/SMBSR development by creating an account on GitHub.
First Morello prototype architecture silicon (memory safety at a hardware level)
https://ift.tt/3qHRQQy
Submitted January 20, 2022 at 05:07PM by unaligned_access
via reddit https://ift.tt/359v2Rp
https://ift.tt/3qHRQQy
Submitted January 20, 2022 at 05:07PM by unaligned_access
via reddit https://ift.tt/359v2Rp
reddit
First Morello prototype architecture silicon (memory safety at a...
Posted in r/netsec by u/unaligned_access • 2 points and 0 comments
How mail server related DNS settings (SPF, DKIM, DMARC, MTA-STS, DANE, BIMI) work and their usage stats in the top 1M domain
https://ift.tt/3qIWRYW
Submitted January 20, 2022 at 07:24PM by c0r0n3r
via reddit https://ift.tt/3fJEMng
https://ift.tt/3qIWRYW
Submitted January 20, 2022 at 07:24PM by c0r0n3r
via reddit https://ift.tt/3fJEMng
www.balasys.hu
Modern Techniques to Prevent Malware instead of Detecting It
Google lists 4,840,000 results to the search of "malware detection tools." Is malware detection a silver bullet, or is there a smarter method to prevent malware attacks? We believe there is one.
Pentest Collaboration Framework: tool which will help you to store/modify/share information about pentest/web analysis projects. OpenSource, Portable, CrossPlatform & completely free! Supports integration with 15 tools & user-defined report generation. For several teams: seperated workspaces!
https://ift.tt/3qJmrwT
Submitted January 20, 2022 at 09:13PM by Any_Gas_6250
via reddit https://ift.tt/33yxYGJ
https://ift.tt/3qJmrwT
Submitted January 20, 2022 at 09:13PM by Any_Gas_6250
via reddit https://ift.tt/33yxYGJ
GitLab
Invuls / Pentest projects / Pentest-Collaboration-Framework · GitLab
Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!
HOUDINI: A web app with huge number of Docker Images for Network Security with run commands and cheatsheet (Hundreds of Offensive and Useful Docker Images for Network Intrusion )
https://ift.tt/3GLtcny
Submitted January 20, 2022 at 09:11PM by deleee
via reddit https://ift.tt/358dZPE
https://ift.tt/3GLtcny
Submitted January 20, 2022 at 09:11PM by deleee
via reddit https://ift.tt/358dZPE
GitHub
GitHub - cybersecsi/HOUDINI: Hundreds of Offensive and Useful Docker Images for Network Intrusion. The name says it all.
Hundreds of Offensive and Useful Docker Images for Network Intrusion. The name says it all. - GitHub - cybersecsi/HOUDINI: Hundreds of Offensive and Useful Docker Images for Network Intrusion. The ...
A Detailed Analysis of WhisperGate Targeting Ukrainian Organizations
https://ift.tt/3Ah5Wvp
Submitted January 21, 2022 at 12:59AM by CyberMasterV
via reddit https://ift.tt/3nHXa4m
https://ift.tt/3Ah5Wvp
Submitted January 21, 2022 at 12:59AM by CyberMasterV
via reddit https://ift.tt/3nHXa4m
Captain Hook - How (not) to look for vulnerabilities in Java applications
https://ift.tt/3fP1KcA
Submitted January 21, 2022 at 11:15AM by Gallus
via reddit https://ift.tt/33UrNfU
https://ift.tt/3fP1KcA
Submitted January 21, 2022 at 11:15AM by Gallus
via reddit https://ift.tt/33UrNfU
Synacktiv
Captain Hook - How (not) to look for vulnerabilities in Java applications
During my 6-months intership, I developed a tool to ease vunerability research on Java applications.
The best free, open-source supply-chain security tool? The lockfile
https://ift.tt/3FOD9PV
Submitted January 21, 2022 at 09:58PM by pabloest
via reddit https://ift.tt/3rDULsD
https://ift.tt/3FOD9PV
Submitted January 21, 2022 at 09:58PM by pabloest
via reddit https://ift.tt/3rDULsD
CVE-2022-0185: Detecting and mitigating Linux Kernel vulnerability causing container escape
https://ift.tt/3AklVIW
Submitted January 22, 2022 at 04:01AM by MiguelHzBz
via reddit https://ift.tt/3GRhIPD
https://ift.tt/3AklVIW
Submitted January 22, 2022 at 04:01AM by MiguelHzBz
via reddit https://ift.tt/3GRhIPD
Sysdig
CVE-2022-0185: Detecting and mitigating Linux Kernel vulnerability causing container escape – Sysdig
Linux maintainers and vendors disclosed a heap overflow vulnerability in the Linux Kernel causing DoS, escape container or elevate privileges
CVE-2021-45467: CWP CentOS Web Panel – preauth RCE
https://ift.tt/3KC2f87
Submitted January 22, 2022 at 02:25PM by Gallus
via reddit https://ift.tt/3IsDtWd
https://ift.tt/3KC2f87
Submitted January 22, 2022 at 02:25PM by Gallus
via reddit https://ift.tt/3IsDtWd
reddit
CVE-2021-45467: CWP CentOS Web Panel – preauth RCE
Posted in r/netsec by u/Gallus • 88 points and 8 comments
GoWard - A robust Red Team proxy written in Go
https://ift.tt/3sCkTWU
Submitted January 23, 2022 at 12:20AM by UnwearableCactus
via reddit https://ift.tt/3FQ7GwH
https://ift.tt/3sCkTWU
Submitted January 23, 2022 at 12:20AM by UnwearableCactus
via reddit https://ift.tt/3FQ7GwH
GitHub
GitHub - chdav/GoWard: A robust Red Team proxy written in Go.
A robust Red Team proxy written in Go. Contribute to chdav/GoWard development by creating an account on GitHub.
Doing a uni project on pen testing and appreciated this article for help writing up an information disclosure vulnerability. Though some of you might appreciate it too.
https://ift.tt/36aDpKY
Submitted January 23, 2022 at 03:39PM by PlatonicDogLover93
via reddit https://ift.tt/3fNd4X1
https://ift.tt/36aDpKY
Submitted January 23, 2022 at 03:39PM by PlatonicDogLover93
via reddit https://ift.tt/3fNd4X1
portswigger.net
Information disclosure vulnerabilities | Web Security Academy
In this section, we'll explain the basics of information disclosure vulnerabilities and describe how you can find and exploit them. We'll also offer some ...
Treat security as a risk
https://ift.tt/3fS7Ysg
Submitted January 23, 2022 at 10:33PM by nfrankel
via reddit https://ift.tt/355XZ0m
https://ift.tt/3fS7Ysg
Submitted January 23, 2022 at 10:33PM by nfrankel
via reddit https://ift.tt/355XZ0m
A Java geek
Treat security as a risk
Security is the poster child of a Non-Functional Requirement: most people don’t care until the proverbial fecal matter hits the rotary propeller. Consequences can range from losing reputation to legal liability to putting the business out. In my post on running…
Supply chain attacks are the new big thing
https://ift.tt/3nQOLMa
Submitted January 23, 2022 at 11:15PM by davidw_-
via reddit https://ift.tt/3H2kUbi
https://ift.tt/3nQOLMa
Submitted January 23, 2022 at 11:15PM by davidw_-
via reddit https://ift.tt/3H2kUbi
cryptologie.net
Supply chain attacks are the new big thing
Over 90 WordPress themes, plugins backdoored in supply chain attack
(source: bleepingcomputer.com)
A product can be seen as a production line. That's what The Phoenix Project novel argues. It makes sense to me. Things gets assembled and passed around, work…
(source: bleepingcomputer.com)
A product can be seen as a production line. That's what The Phoenix Project novel argues. It makes sense to me. Things gets assembled and passed around, work…
Binary-only fuzzong with python, Qemu and LibAFL
https://ift.tt/3fSAzho
Submitted January 24, 2022 at 01:15AM by domenukk
via reddit https://ift.tt/3KzsU5v
https://ift.tt/3fSAzho
Submitted January 24, 2022 at 01:15AM by domenukk
via reddit https://ift.tt/3KzsU5v
epi052.gitlab.io
Fuzzing101 with LibAFL - Part V: Fuzzing LibXML2 -
Part 5 of a series covering fuzzer development using LibAFL
Private Network Access: introducing preflights - Chrome Developers
https://ift.tt/3tiMzAI
Submitted January 24, 2022 at 02:17PM by rhaidiz
via reddit https://ift.tt/3rE6APA
https://ift.tt/3tiMzAI
Submitted January 24, 2022 at 02:17PM by rhaidiz
via reddit https://ift.tt/3rE6APA
Chrome for Developers
Private Network Access: introducing preflights | Blog | Chrome for Developers
Chrome is deprecating access to private network endpoints from non-secure public websites as part of the Private Network Access specification. Read on for recommended actions.
Qiling Sandbox Escape
https://ift.tt/3AyrC6f
Submitted January 24, 2022 at 02:15PM by ly4k_
via reddit https://ift.tt/3FUPgej
https://ift.tt/3AyrC6f
Submitted January 24, 2022 at 02:15PM by ly4k_
via reddit https://ift.tt/3FUPgej
www.kalmarunionen.dk
Qiling Sandbox Escape
Writeup by: Oliver Lyak (ly4k)
Solved by: Zopazz, Oliver Lyak (ly4k)
QLaaS QLaaS (Qiling as a Service) was a Clone-and-Pwn challenge with difficulty Schrödinger …
Solved by: Zopazz, Oliver Lyak (ly4k)
QLaaS QLaaS (Qiling as a Service) was a Clone-and-Pwn challenge with difficulty Schrödinger …
CVE-2022-0185 – What does the newest kernel exploit mean for Kubernetes
https://ift.tt/3FXn2Q5
Submitted January 24, 2022 at 01:59PM by gemyougym
via reddit https://ift.tt/35bFUhr
https://ift.tt/3FXn2Q5
Submitted January 24, 2022 at 01:59PM by gemyougym
via reddit https://ift.tt/35bFUhr
ARMO
What the newest kernel exploit - CVE-2022-0185 - mean for Kubernetes?
In the last few days, Linux maintainers disclosed a broadly available Linux kernel vulnerability - CVE-2022-0185- what does it mean for Kubernetes?