Doing a uni project on pen testing and appreciated this article for help writing up an information disclosure vulnerability. Though some of you might appreciate it too.
https://ift.tt/36aDpKY
Submitted January 23, 2022 at 03:39PM by PlatonicDogLover93
via reddit https://ift.tt/3fNd4X1
https://ift.tt/36aDpKY
Submitted January 23, 2022 at 03:39PM by PlatonicDogLover93
via reddit https://ift.tt/3fNd4X1
portswigger.net
Information disclosure vulnerabilities | Web Security Academy
In this section, we'll explain the basics of information disclosure vulnerabilities and describe how you can find and exploit them. We'll also offer some ...
Treat security as a risk
https://ift.tt/3fS7Ysg
Submitted January 23, 2022 at 10:33PM by nfrankel
via reddit https://ift.tt/355XZ0m
https://ift.tt/3fS7Ysg
Submitted January 23, 2022 at 10:33PM by nfrankel
via reddit https://ift.tt/355XZ0m
A Java geek
Treat security as a risk
Security is the poster child of a Non-Functional Requirement: most people don’t care until the proverbial fecal matter hits the rotary propeller. Consequences can range from losing reputation to legal liability to putting the business out. In my post on running…
Supply chain attacks are the new big thing
https://ift.tt/3nQOLMa
Submitted January 23, 2022 at 11:15PM by davidw_-
via reddit https://ift.tt/3H2kUbi
https://ift.tt/3nQOLMa
Submitted January 23, 2022 at 11:15PM by davidw_-
via reddit https://ift.tt/3H2kUbi
cryptologie.net
Supply chain attacks are the new big thing
Over 90 WordPress themes, plugins backdoored in supply chain attack
(source: bleepingcomputer.com)
A product can be seen as a production line. That's what The Phoenix Project novel argues. It makes sense to me. Things gets assembled and passed around, work…
(source: bleepingcomputer.com)
A product can be seen as a production line. That's what The Phoenix Project novel argues. It makes sense to me. Things gets assembled and passed around, work…
Binary-only fuzzong with python, Qemu and LibAFL
https://ift.tt/3fSAzho
Submitted January 24, 2022 at 01:15AM by domenukk
via reddit https://ift.tt/3KzsU5v
https://ift.tt/3fSAzho
Submitted January 24, 2022 at 01:15AM by domenukk
via reddit https://ift.tt/3KzsU5v
epi052.gitlab.io
Fuzzing101 with LibAFL - Part V: Fuzzing LibXML2 -
Part 5 of a series covering fuzzer development using LibAFL
Private Network Access: introducing preflights - Chrome Developers
https://ift.tt/3tiMzAI
Submitted January 24, 2022 at 02:17PM by rhaidiz
via reddit https://ift.tt/3rE6APA
https://ift.tt/3tiMzAI
Submitted January 24, 2022 at 02:17PM by rhaidiz
via reddit https://ift.tt/3rE6APA
Chrome for Developers
Private Network Access: introducing preflights | Blog | Chrome for Developers
Chrome is deprecating access to private network endpoints from non-secure public websites as part of the Private Network Access specification. Read on for recommended actions.
Qiling Sandbox Escape
https://ift.tt/3AyrC6f
Submitted January 24, 2022 at 02:15PM by ly4k_
via reddit https://ift.tt/3FUPgej
https://ift.tt/3AyrC6f
Submitted January 24, 2022 at 02:15PM by ly4k_
via reddit https://ift.tt/3FUPgej
www.kalmarunionen.dk
Qiling Sandbox Escape
Writeup by: Oliver Lyak (ly4k)
Solved by: Zopazz, Oliver Lyak (ly4k)
QLaaS QLaaS (Qiling as a Service) was a Clone-and-Pwn challenge with difficulty Schrödinger …
Solved by: Zopazz, Oliver Lyak (ly4k)
QLaaS QLaaS (Qiling as a Service) was a Clone-and-Pwn challenge with difficulty Schrödinger …
CVE-2022-0185 – What does the newest kernel exploit mean for Kubernetes
https://ift.tt/3FXn2Q5
Submitted January 24, 2022 at 01:59PM by gemyougym
via reddit https://ift.tt/35bFUhr
https://ift.tt/3FXn2Q5
Submitted January 24, 2022 at 01:59PM by gemyougym
via reddit https://ift.tt/35bFUhr
ARMO
What the newest kernel exploit - CVE-2022-0185 - mean for Kubernetes?
In the last few days, Linux maintainers disclosed a broadly available Linux kernel vulnerability - CVE-2022-0185- what does it mean for Kubernetes?
How BRATA is monitoring your bank account | Cleafy Labs
https://ift.tt/3IuiVN9
Submitted January 24, 2022 at 05:22PM by f3d_0x0
via reddit https://ift.tt/345JQja
https://ift.tt/3IuiVN9
Submitted January 24, 2022 at 05:22PM by f3d_0x0
via reddit https://ift.tt/345JQja
Cleafy
How BRATA is monitoring your bank account | Cleafy Labs
The mobile banking malware BRATA keeps evolving. Read here the new Technical Report, which explains in detail how it monitors banks account and how to prevent it.
Cobalt Strike, a Defender’s Guide – Part 2
https://ift.tt/3qTXEGz
Submitted January 24, 2022 at 07:49PM by TheDFIRReport
via reddit https://ift.tt/3nRKS9y
https://ift.tt/3qTXEGz
Submitted January 24, 2022 at 07:49PM by TheDFIRReport
via reddit https://ift.tt/3nRKS9y
The DFIR Report
Cobalt Strike, a Defender’s Guide – Part 2
Our previous report on Cobalt Strike focused on the most frequently used capabilities that we had observed. In this report, we will focus on the network traffic it produced, and provide some easy w…
Paranoids’ Vulnerability Research: PrinterLogic Issues Security Alert
https://ift.tt/3fRJakb
Submitted January 24, 2022 at 11:45PM by jrozner
via reddit https://ift.tt/3IxFb8H
https://ift.tt/3fRJakb
Submitted January 24, 2022 at 11:45PM by jrozner
via reddit https://ift.tt/3IxFb8H
Yahooinc
Paranoids’ Vulnerability Research: PrinterLogic Issues Security Alert | Paranoids Blog | Yahoo Inc.
Using Twitter to notify careless developers — the unorthodox way (Or, how you could use GitHub to compromise 9.5K Twitter accounts without “hacking”)
https://ift.tt/3ArlPze
Submitted January 25, 2022 at 02:52AM by sp00kyphiss
via reddit https://ift.tt/3qVCIPu
https://ift.tt/3ArlPze
Submitted January 25, 2022 at 02:52AM by sp00kyphiss
via reddit https://ift.tt/3qVCIPu
Medium
Using Twitter to notify careless developers — the unorthodox way
Or, how you could use GitHub to compromise 9.5K Twitter accounts without doing any “hacking”
TypeScript scenario-based web application Fuzzing Framework, supports genetic algorithm and running on CI
https://ift.tt/344p7wt
Submitted January 24, 2022 at 03:12PM by hi120ki
via reddit https://ift.tt/3fXagqm
https://ift.tt/344p7wt
Submitted January 24, 2022 at 03:12PM by hi120ki
via reddit https://ift.tt/3fXagqm
GitHub
GitHub - shfz/shfz: TypeScript Scenario-Based Web Application Fuzzing Framework
TypeScript Scenario-Based Web Application Fuzzing Framework - GitHub - shfz/shfz: TypeScript Scenario-Based Web Application Fuzzing Framework
WordPress 5.8.2 Stored XSS Vulnerability
https://ift.tt/3IuJ8em
Submitted January 24, 2022 at 09:03PM by monoimpact
via reddit https://ift.tt/3rUzc7w
https://ift.tt/3IuJ8em
Submitted January 24, 2022 at 09:03PM by monoimpact
via reddit https://ift.tt/3rUzc7w
A new shellcode injection methodology
https://ift.tt/3qYoSMr
Submitted January 24, 2022 at 02:00AM by Idov31
via reddit https://ift.tt/3IEAMB9
https://ift.tt/3qYoSMr
Submitted January 24, 2022 at 02:00AM by Idov31
via reddit https://ift.tt/3IEAMB9
GitHub
GitHub - Idov31/FunctionStomping: A new shellcode injection technique. Given as C++ header or standalone Rust program.
A new shellcode injection technique. Given as C++ header or standalone Rust program. - GitHub - Idov31/FunctionStomping: A new shellcode injection technique. Given as C++ header or standalone Rust ...
Solarwinds Web Help Desk: When the Helpdesk is too Helpful
https://ift.tt/3G0Opsm
Submitted January 25, 2022 at 03:03PM by Mempodipper
via reddit https://ift.tt/3FZMt3i
https://ift.tt/3G0Opsm
Submitted January 25, 2022 at 03:03PM by Mempodipper
via reddit https://ift.tt/3FZMt3i
Assetnote
Solarwinds Web Help Desk: When the Helpdesk is too Helpful
Application security issues found by Assetnote
Recovering redacted information from pixelated videos
https://ift.tt/3IAzneF
Submitted January 25, 2022 at 06:27PM by breakingsystems
via reddit https://ift.tt/33PHXaL
https://ift.tt/3IAzneF
Submitted January 25, 2022 at 06:27PM by breakingsystems
via reddit https://ift.tt/33PHXaL
positive.security
Recovering redacted information from pixelated videos | Positive Security
We explore the history of image unblurring and present a simple yet effective technique to get a high-resolution image from a pixelated video in order to recover redacted information (with no guessing involved).
Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1
https://ift.tt/3qVcEUF
Submitted January 25, 2022 at 08:48PM by 0xdea
via reddit https://ift.tt/3nWxRMf
https://ift.tt/3qVcEUF
Submitted January 25, 2022 at 08:48PM by 0xdea
via reddit https://ift.tt/3nWxRMf
Reversemode
Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1
In September '21, I came across this story "Swiss Post Offers up to €230,000 for Critical Vulnerabilities in e-Voting System" while catchi...
RBCD attack & defense. From Domain User to DA on default domain controllers settings. Including webclient service activation
https://ift.tt/3IHkQhz
Submitted January 25, 2022 at 09:33PM by k3nfr4
via reddit https://ift.tt/3KFw5J5
https://ift.tt/3IHkQhz
Submitted January 25, 2022 at 09:33PM by k3nfr4
via reddit https://ift.tt/3KFw5J5
reddit
RBCD attack & defense. From Domain User to DA on default domain...
Posted in r/netsec by u/k3nfr4 • 0 points and 1 comment
Cracking Randomly Generated Passwords
https://ift.tt/3tWNh6K
Submitted January 25, 2022 at 11:00PM by hyperreality_monero
via reddit https://ift.tt/3H0m4UE
https://ift.tt/3tWNh6K
Submitted January 25, 2022 at 11:00PM by hyperreality_monero
via reddit https://ift.tt/3H0m4UE
TrustedSec
Recovering Randomly Generated Passwords - TrustedSec
TrustedSec's blog is an expert source of information on information security trends and best practices for strategic risk management.
Mind Your Dependencies: Defending against malicious npm packages
https://ift.tt/347p575
Submitted January 26, 2022 at 12:39AM by SRMish3
via reddit https://ift.tt/3KGRP7o
https://ift.tt/347p575
Submitted January 26, 2022 at 12:39AM by SRMish3
via reddit https://ift.tt/3KGRP7o
We purchased a machine from China and it came with malware preinstalled
https://ift.tt/3fS4Blk
Submitted January 26, 2022 at 12:35AM by lormayna
via reddit https://ift.tt/33LgCXo
https://ift.tt/3fS4Blk
Submitted January 26, 2022 at 12:35AM by lormayna
via reddit https://ift.tt/33LgCXo
reddit
We purchased a machine from China and it came with malware...
Posted in r/netsec by u/lormayna • 630 points and 166 comments