NTLM Relaying - A comprehensive guide
https://ift.tt/d3W1MiJpS
Submitted February 03, 2022 at 08:28PM by jeanc0re
via reddit https://ift.tt/ZhtCXFHpk
https://ift.tt/d3W1MiJpS
Submitted February 03, 2022 at 08:28PM by jeanc0re
via reddit https://ift.tt/ZhtCXFHpk
TrustedSec
I’m bringing relaying back: A comprehensive guide on relaying anno 2022 - TrustedSec
The first comprehensive resource about relaying that will walk you through the attack primitives that continue to work today including some lesser known attacks.
A detailed analysis of Lazarus malware disguised as Notepad++ Shell Extension
https://ift.tt/w2sXl7mLZ
Submitted February 04, 2022 at 12:58AM by CyberMasterV
via reddit https://ift.tt/oxRr8hmJv
https://ift.tt/w2sXl7mLZ
Submitted February 04, 2022 at 12:58AM by CyberMasterV
via reddit https://ift.tt/oxRr8hmJv
reddit
A detailed analysis of Lazarus malware disguised as Notepad++...
Posted in r/netsec by u/CyberMasterV • 37 points and 10 comments
Compromising out-of-bound secrets on Argo CD platform utilizing a malicious Kubernetes Helm Chart (CVE-2022-24348)
https://ift.tt/K4nfPD6
Submitted February 04, 2022 at 12:37PM by dalmoz
via reddit https://ift.tt/BZlgh3F
https://ift.tt/K4nfPD6
Submitted February 04, 2022 at 12:37PM by dalmoz
via reddit https://ift.tt/BZlgh3F
Apiiro | Deep Application Security Posture Management (ASPM)
Malicious Kubernetes Helm charts can be used to steal sensitive information from Argo CD deployments
Apiiro's Security Research team has discovered a major vulnerability in Argo CD platform (CVE-2022-24348).
Silly proof of concept: Anti-phishing using perceptual hashing algorithms
https://ift.tt/fvHuZcj
Submitted February 04, 2022 at 07:24PM by anvilventures
via reddit https://ift.tt/YK6laZP
https://ift.tt/fvHuZcj
Submitted February 04, 2022 at 07:24PM by anvilventures
via reddit https://ift.tt/YK6laZP
Anvil Secure
Silly proof of concept: Anti-phishing using perceptual hashing algorithms - Anvil Secure
by Diego Freijo Welcome to the first dispatch coming out of the Ministry of Silly Ideas! It’s a space we’ve got inside Anvil where we encourage ourselves to come up with interesting-even-if-sounding-silly-at-first-glance ideas around security or IT in general.…
Multiple vulnerabilities in Nooie baby monitor
https://ift.tt/BtvHdAX
Submitted February 04, 2022 at 09:43PM by jaymzu
via reddit https://ift.tt/BU4EkaX
https://ift.tt/BtvHdAX
Submitted February 04, 2022 at 09:43PM by jaymzu
via reddit https://ift.tt/BU4EkaX
Bitdefender Labs
Vulnerabilities Identified in Nooie Baby Monitor
At Bitdefender, we care deeply about security, so we’ve been working with media
partners and IoT devices manufacturers to identify vulnerabilities in the
world’s best-selling connected devices.
partners and IoT devices manufacturers to identify vulnerabilities in the
world’s best-selling connected devices.
Rooting Gryphon Routers via Shared VPN : 🎵 This LAN is your LAN, this LAN is my LAN 🎵
https://ift.tt/R6z2qp7
Submitted February 05, 2022 at 12:16AM by stargravy
via reddit https://ift.tt/UvYn7Lc
https://ift.tt/R6z2qp7
Submitted February 05, 2022 at 12:16AM by stargravy
via reddit https://ift.tt/UvYn7Lc
Medium
Rooting Gryphon Routers via Shared VPN
🎵 This LAN is your LAN, this LAN is my LAN 🎵
Linux | Madaidan's Insecurities
https://ift.tt/v1lcm04
Submitted February 05, 2022 at 01:35AM by Nhamatanda
via reddit https://ift.tt/Qec120y
https://ift.tt/v1lcm04
Submitted February 05, 2022 at 01:35AM by Nhamatanda
via reddit https://ift.tt/Qec120y
Reddit
From the netsec community on Reddit: Linux | Madaidan's Insecurities
Posted by Nhamatanda - 2 votes and 11 comments
CISSP Domain 1 - Episode 4 - Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification by Get Set CISSP
https://ift.tt/BzfoK4g
Submitted February 05, 2022 at 12:56PM by Tradition_Wonderful
via reddit https://ift.tt/COa8Rb1
https://ift.tt/BzfoK4g
Submitted February 05, 2022 at 12:56PM by Tradition_Wonderful
via reddit https://ift.tt/COa8Rb1
Anchor
CISSP Domain 1 - Episode 4 - Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification…
In this episode I talk about the concept of Business Case, Types of Project Plans, Organizational Process, Change Management and Data Classification which are essentials from an exam and real life security practice perspective.
If you like this episode do…
If you like this episode do…
Testing Infrastructure-as-Code Using Dynamic Tooling
https://ift.tt/NFE39Lr
Submitted February 05, 2022 at 05:40PM by digicat
via reddit https://ift.tt/xYO7kMP
https://ift.tt/NFE39Lr
Submitted February 05, 2022 at 05:40PM by digicat
via reddit https://ift.tt/xYO7kMP
NCC Group Research Blog
Testing Infrastructure-as-Code Using Dynamic Tooling
Erik Steringer, NCC Group Overview TL;DR: Go check out As public cloud service consumption has grown, engineering and security professionals have responded with different tools and techniques to ac…
CVE-2022-24348 Argo CD Vulnerability and its impact on Kubernetes
https://ift.tt/GnZfwuN
Submitted February 06, 2022 at 02:44PM by rippatpop
via reddit https://ift.tt/nYzqyFC
https://ift.tt/GnZfwuN
Submitted February 06, 2022 at 02:44PM by rippatpop
via reddit https://ift.tt/nYzqyFC
ARMO
CVE-2022-24348 Argo CD Vulnerability and its impact on Kubernetes
A major software supply chain critical vulnerability CVE-2022-24348 was discovered in the popular open-source CD platform Argo CD. See its impact on Kubernetes here
Software Defined Radio, Part 6: Building a Cellphone IMSI Catcher (Stingray)
https://ift.tt/p6Bsej8
Submitted February 06, 2022 at 03:18PM by digicat
via reddit https://ift.tt/B8j9x2Z
https://ift.tt/p6Bsej8
Submitted February 06, 2022 at 03:18PM by digicat
via reddit https://ift.tt/B8j9x2Z
Reddit
From the netsec community on Reddit: Software Defined Radio, Part 6: Building a Cellphone IMSI Catcher (Stingray)
Posted by digicat - 210 votes and 14 comments
GUARDARA, a software quality assurance platform to identify bugs and zero-day vulnerabilities at scale, is now free for individual security researchers and non-commercial open-source projects.
https://guardara.com
Submitted February 06, 2022 at 10:34PM by JohnKeymanUK
via reddit https://ift.tt/Gan2Iqb
https://guardara.com
Submitted February 06, 2022 at 10:34PM by JohnKeymanUK
via reddit https://ift.tt/Gan2Iqb
Guardara
Build secure, rock-solid software | Build secure, rock-solid software
The most comprehensive negative testing / fuzz testing platform to hunt down bugs and zero-day vulnerabilities.
OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
Reddit
From the netsec community on Reddit: OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
Posted by CyberMasterV - No votes and no comments
#Phishing like early 90's. Spoofing emails when DMARC isn't available or commonly known as "SPF-BYPASS".
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
www.redteam.cafe
Long Live DMARC - Email Spoof issues | Intruder
Spoof emails when SPF is present but DMARC is not allowing you to spoof the sender
Linux Persistence using Systemd Generators. They will run early at boot and can be used to create services and disable other services before they start.
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
pepe berba
Hunting for Persistence in Linux (Part 5): Systemd Generators
How attackers can insert backdoors early in the boot process using systemd generators
UEFI firmware vulnerabilities affect at least 25 computer vendors
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
Reddit
From the netsec community on Reddit: UEFI firmware vulnerabilities affect at least 25 computer vendors
Explore this post and more from the netsec community
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
NCC Group Research
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
This blog post discusses two erroneous computation patterns in Golang. By erroneous computation we mean simply that given certain input, a computer program with certain state returns incorrect output or enters an incorrect state. While clearly there are no…
Shadow Credentials
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
Penetration Testing Lab
Shadow Credentials
Microsoft has introduced Windows Hello for Business (WHfB) to replace traditional password based authentication with a key based trust model. This implementation uses PIN or Bio-metrics which are l…
SHA-256 explained step-by-step visually
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
Sha256Algorithm
Sha256 Algorithm Explained
Sha256 algorithm explained online step by step visually
Qbot Likes to Move It, Move It
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
The DFIR Report
Qbot Likes to Move It, Move It
Qbot (aka QakBot, Quakbot, Pinkslipbot ) has been around for a long time having first been observed back in 2007. More info on Qbot can be found at the following links: Microsoft & Red Canary I…
How to Make Package Signing Useful
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
Chainguard, Inc.
How to Make Package Signing Useful
The Case for Farm-to-Table Package SigningThe benefits and limitations of signing an open source package–using a private key to create a unique digital signature–are a surprisingly contentious topic. One of the maintainers associated with the Python Package…