WordPress 5.8.2 Stored XSS Vulnerability
https://ift.tt/3IuJ8em
Submitted January 24, 2022 at 09:03PM by monoimpact
via reddit https://ift.tt/3rUzc7w
https://ift.tt/3IuJ8em
Submitted January 24, 2022 at 09:03PM by monoimpact
via reddit https://ift.tt/3rUzc7w
A new shellcode injection methodology
https://ift.tt/3qYoSMr
Submitted January 24, 2022 at 02:00AM by Idov31
via reddit https://ift.tt/3IEAMB9
https://ift.tt/3qYoSMr
Submitted January 24, 2022 at 02:00AM by Idov31
via reddit https://ift.tt/3IEAMB9
GitHub
GitHub - Idov31/FunctionStomping: A new shellcode injection technique. Given as C++ header or standalone Rust program.
A new shellcode injection technique. Given as C++ header or standalone Rust program. - GitHub - Idov31/FunctionStomping: A new shellcode injection technique. Given as C++ header or standalone Rust ...
Solarwinds Web Help Desk: When the Helpdesk is too Helpful
https://ift.tt/3G0Opsm
Submitted January 25, 2022 at 03:03PM by Mempodipper
via reddit https://ift.tt/3FZMt3i
https://ift.tt/3G0Opsm
Submitted January 25, 2022 at 03:03PM by Mempodipper
via reddit https://ift.tt/3FZMt3i
Assetnote
Solarwinds Web Help Desk: When the Helpdesk is too Helpful
Application security issues found by Assetnote
Recovering redacted information from pixelated videos
https://ift.tt/3IAzneF
Submitted January 25, 2022 at 06:27PM by breakingsystems
via reddit https://ift.tt/33PHXaL
https://ift.tt/3IAzneF
Submitted January 25, 2022 at 06:27PM by breakingsystems
via reddit https://ift.tt/33PHXaL
positive.security
Recovering redacted information from pixelated videos | Positive Security
We explore the history of image unblurring and present a simple yet effective technique to get a high-resolution image from a pixelated video in order to recover redacted information (with no guessing involved).
Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1
https://ift.tt/3qVcEUF
Submitted January 25, 2022 at 08:48PM by 0xdea
via reddit https://ift.tt/3nWxRMf
https://ift.tt/3qVcEUF
Submitted January 25, 2022 at 08:48PM by 0xdea
via reddit https://ift.tt/3nWxRMf
Reversemode
Finding vulnerabilities in Swiss Post’s future e-voting system - Part 1
In September '21, I came across this story "Swiss Post Offers up to €230,000 for Critical Vulnerabilities in e-Voting System" while catchi...
RBCD attack & defense. From Domain User to DA on default domain controllers settings. Including webclient service activation
https://ift.tt/3IHkQhz
Submitted January 25, 2022 at 09:33PM by k3nfr4
via reddit https://ift.tt/3KFw5J5
https://ift.tt/3IHkQhz
Submitted January 25, 2022 at 09:33PM by k3nfr4
via reddit https://ift.tt/3KFw5J5
reddit
RBCD attack & defense. From Domain User to DA on default domain...
Posted in r/netsec by u/k3nfr4 • 0 points and 1 comment
Cracking Randomly Generated Passwords
https://ift.tt/3tWNh6K
Submitted January 25, 2022 at 11:00PM by hyperreality_monero
via reddit https://ift.tt/3H0m4UE
https://ift.tt/3tWNh6K
Submitted January 25, 2022 at 11:00PM by hyperreality_monero
via reddit https://ift.tt/3H0m4UE
TrustedSec
Recovering Randomly Generated Passwords - TrustedSec
TrustedSec's blog is an expert source of information on information security trends and best practices for strategic risk management.
Mind Your Dependencies: Defending against malicious npm packages
https://ift.tt/347p575
Submitted January 26, 2022 at 12:39AM by SRMish3
via reddit https://ift.tt/3KGRP7o
https://ift.tt/347p575
Submitted January 26, 2022 at 12:39AM by SRMish3
via reddit https://ift.tt/3KGRP7o
We purchased a machine from China and it came with malware preinstalled
https://ift.tt/3fS4Blk
Submitted January 26, 2022 at 12:35AM by lormayna
via reddit https://ift.tt/33LgCXo
https://ift.tt/3fS4Blk
Submitted January 26, 2022 at 12:35AM by lormayna
via reddit https://ift.tt/33LgCXo
reddit
We purchased a machine from China and it came with malware...
Posted in r/netsec by u/lormayna • 630 points and 166 comments
pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)
https://ift.tt/3fWIF8M
Submitted January 26, 2022 at 01:55AM by TheSwedishChef24
via reddit https://ift.tt/3IzIZGH
https://ift.tt/3fWIF8M
Submitted January 26, 2022 at 01:55AM by TheSwedishChef24
via reddit https://ift.tt/3IzIZGH
reddit
pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)
Posted in r/netsec by u/TheSwedishChef24 • 1 point and 0 comments
Exploit for CVE-2021-4034 that does not leave syslog entries
https://ift.tt/3H7ssJG
Submitted January 26, 2022 at 03:22PM by hermajordoctor
via reddit https://ift.tt/3tZw6l7
https://ift.tt/3H7ssJG
Submitted January 26, 2022 at 03:22PM by hermajordoctor
via reddit https://ift.tt/3tZw6l7
GitHub
GitHub - Ayrx/CVE-2021-4034: Exploit for CVE-2021-4034
Exploit for CVE-2021-4034. Contribute to Ayrx/CVE-2021-4034 development by creating an account on GitHub.
Self-contained exploit for CVE-2021-4034 (Pkexec 1-day LPE)
https://ift.tt/3G7mVS2
Submitted January 26, 2022 at 07:59PM by ly4k_
via reddit https://ift.tt/3o2AZGq
https://ift.tt/3G7mVS2
Submitted January 26, 2022 at 07:59PM by ly4k_
via reddit https://ift.tt/3o2AZGq
GitHub
GitHub - ly4k/PwnKit: Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation - GitHub - ly4k/PwnKit: Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
wholeaked: a file-sharing tool that allows you to find the responsible person in case of a leakage
https://ift.tt/3AAPnL9
Submitted January 26, 2022 at 09:21PM by utku1337
via reddit https://ift.tt/3o1mLFI
https://ift.tt/3AAPnL9
Submitted January 26, 2022 at 09:21PM by utku1337
via reddit https://ift.tt/3o1mLFI
GitHub
GitHub - utkusen/wholeaked: a file-sharing tool that allows you to find the responsible person in case of a leakage
a file-sharing tool that allows you to find the responsible person in case of a leakage - GitHub - utkusen/wholeaked: a file-sharing tool that allows you to find the responsible person in case of a...
AD CS: weaponizing the ESC7 attack - BlackArrow
https://ift.tt/3Axjnr0
Submitted January 26, 2022 at 08:52PM by apanonimo
via reddit https://ift.tt/3G6TyPI
https://ift.tt/3Axjnr0
Submitted January 26, 2022 at 08:52PM by apanonimo
via reddit https://ift.tt/3G6TyPI
Tarlogic Security
AD CS: weaponizing the ESC7 attack
Research and tooling development around the ESC7 attack at Active Directory Certificate Services (AD CS) for Red Team operations
Perfect wordlist to discover directories and files on target size with tools like ffuf.
https://ift.tt/3AyR9w4
Submitted January 26, 2022 at 10:03PM by mexhanical
via reddit https://ift.tt/35gkVtW
https://ift.tt/3AyR9w4
Submitted January 26, 2022 at 10:03PM by mexhanical
via reddit https://ift.tt/35gkVtW
GitHub
GitHub - aels/subdirectories-discover: Perfect wordlist for discovering directories and files on target site
Perfect wordlist for discovering directories and files on target site - GitHub - aels/subdirectories-discover: Perfect wordlist for discovering directories and files on target site
Bypassing Little Snitch Firewall with Empty TCP Packets
https://ift.tt/32xWRBN
Submitted January 26, 2022 at 11:05PM by hackers_and_builders
via reddit https://ift.tt/348fRr2
https://ift.tt/32xWRBN
Submitted January 26, 2022 at 11:05PM by hackers_and_builders
via reddit https://ift.tt/348fRr2
Rhino Security Labs
Bypassing Little Snitch Firewall with Empty TCP Packets - Rhino Security Labs
Little Snitch is a host-based firewall for macOS, used for monitoring and restricting egress network traffic.
Reversing ALPHV (aka BlackCat): Rust-Based Ransomware
https://ift.tt/3rVE8Zy
Submitted January 27, 2022 at 03:05AM by rsobers
via reddit https://ift.tt/3fYf2Uf
https://ift.tt/3rVE8Zy
Submitted January 27, 2022 at 03:05AM by rsobers
via reddit https://ift.tt/3fYf2Uf
Varonis
BlackCat Ransomware (ALPHV) | Varonis
Varonis has observed the ALPHV (BlackCat) ransomware, actively recruiting new affiliates and targeting organizations across multiple sectors worldwide.
Pwnkit: How to exploit and check
https://ift.tt/3IAnBRw
Submitted January 27, 2022 at 04:15AM by DevSec23
via reddit https://ift.tt/3G5peVV
https://ift.tt/3IAnBRw
Submitted January 27, 2022 at 04:15AM by DevSec23
via reddit https://ift.tt/3G5peVV
beny23.github.io
Pwnkit: How to exploit and check
Pwnkit is a vulnerability that uses a bug in polkit to elevate permissions to root. This write-up shows how to reproduce it using Ubuntu and what to do to check whether a system is vulnerable.
What went wrong? Quoting from the original researchers:
This…
What went wrong? Quoting from the original researchers:
This…
How to use FaPro to simulate multiple devices in network
https://ift.tt/3r1yLcb
Submitted January 27, 2022 at 06:57AM by ntestoc3
via reddit https://ift.tt/3H9dPWq
https://ift.tt/3r1yLcb
Submitted January 27, 2022 at 06:57AM by ntestoc3
via reddit https://ift.tt/3H9dPWq
Medium
How to use FaPro to simulate multiple devices in network
With FaPro, you can create a virtual network and simulate several different devices in it with a single command.
Webcam Hacking (again) - Safari UXSS
https://ift.tt/3nYa922
Submitted January 26, 2022 at 05:32AM by Straight_Finding_756
via reddit https://ift.tt/3HddZfu
https://ift.tt/3nYa922
Submitted January 26, 2022 at 05:32AM by Straight_Finding_756
via reddit https://ift.tt/3HddZfu
ryan-pickren
Webcam Hacking (again) - Safari UXSS | Ryan Pickren
$100,500 Apple Bug Bounty for hacking the webcam via a Safari Universal Cross-Site Scripting (UXSS) bug. CVE-2021-30861, CVE-2021-30975
Blockchain-based xx messenger protects message content and metadata with unprecedented quantum resistance
https://ift.tt/3KPFCgu
Submitted January 27, 2022 at 11:53AM by eliapinto
via reddit https://ift.tt/33Q0QdQ
https://ift.tt/3KPFCgu
Submitted January 27, 2022 at 11:53AM by eliapinto
via reddit https://ift.tt/33Q0QdQ