OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
https://ift.tt/dyiaKfL
Submitted February 06, 2022 at 10:53PM by CyberMasterV
via reddit https://ift.tt/adXO3GP
Reddit
From the netsec community on Reddit: OSCP preparation - Buffer Overflow: VANILLA EIP OVERWRITE AND SEH
Posted by CyberMasterV - No votes and no comments
#Phishing like early 90's. Spoofing emails when DMARC isn't available or commonly known as "SPF-BYPASS".
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
https://ift.tt/7T1VJOE
Submitted February 07, 2022 at 07:57AM by intruderK
via reddit https://ift.tt/iE3U8XZ
www.redteam.cafe
Long Live DMARC - Email Spoof issues | Intruder
Spoof emails when SPF is present but DMARC is not allowing you to spoof the sender
Linux Persistence using Systemd Generators. They will run early at boot and can be used to create services and disable other services before they start.
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
https://ift.tt/V3X2ZyW
Submitted February 07, 2022 at 01:44PM by dashboard_monkey
via reddit https://ift.tt/1GLC4WX
pepe berba
Hunting for Persistence in Linux (Part 5): Systemd Generators
How attackers can insert backdoors early in the boot process using systemd generators
UEFI firmware vulnerabilities affect at least 25 computer vendors
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
https://ift.tt/wpJAnEa
Submitted February 07, 2022 at 02:58PM by TryptamineEntity
via reddit https://ift.tt/qiGCBnZ
Reddit
From the netsec community on Reddit: UEFI firmware vulnerabilities affect at least 25 computer vendors
Explore this post and more from the netsec community
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
https://ift.tt/Bzl6ZQF
Submitted February 07, 2022 at 06:49PM by digicat
via reddit https://ift.tt/gOiWZkY
NCC Group Research
A deeper dive into CVE-2021-39137 – a Golang security bug that Rust would have prevented
This blog post discusses two erroneous computation patterns in Golang. By erroneous computation we mean simply that given certain input, a computer program with certain state returns incorrect output or enters an incorrect state. While clearly there are no…
Shadow Credentials
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
Penetration Testing Lab
Shadow Credentials
Microsoft has introduced Windows Hello for Business (WHfB) to replace traditional password based authentication with a key based trust model. This implementation uses PIN or Bio-metrics which are l…
SHA-256 explained step-by-step visually
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
Sha256Algorithm
Sha256 Algorithm Explained
Sha256 algorithm explained online step by step visually
Qbot Likes to Move It, Move It
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
The DFIR Report
Qbot Likes to Move It, Move It
Qbot (aka QakBot, Quakbot, Pinkslipbot ) has been around for a long time having first been observed back in 2007. More info on Qbot can be found at the following links: Microsoft & Red Canary I…
How to Make Package Signing Useful
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
Chainguard, Inc.
How to Make Package Signing Useful
The Case for Farm-to-Table Package SigningThe benefits and limitations of signing an open source package–using a private key to create a unique digital signature–are a surprisingly contentious topic. One of the maintainers associated with the Python Package…
How open-source packages handle releasing security fixes
https://ift.tt/zj1MQ4W
Submitted February 08, 2022 at 07:27AM by Jazzlike-Vegetable69
via reddit https://ift.tt/NeATKmy
https://ift.tt/zj1MQ4W
Submitted February 08, 2022 at 07:27AM by Jazzlike-Vegetable69
via reddit https://ift.tt/NeATKmy
reddit
How open-source packages handle releasing security fixes
Posted in r/netsec by u/Jazzlike-Vegetable69 • 2 points and 0 comments
PPE - Poisoned Pipeline Execution. Running malicious code in your CI, without access to your CI
https://ift.tt/JtLAjOq
Submitted February 08, 2022 at 10:09PM by Hefty_Knowledge_7449
via reddit https://ift.tt/96UyMLg
https://ift.tt/JtLAjOq
Submitted February 08, 2022 at 10:09PM by Hefty_Knowledge_7449
via reddit https://ift.tt/96UyMLg
Medium
PPE — Poisoned Pipeline Execution
Running malicious code in your CI, without access to your CI
How Docker Made Me More Capable and the Host Less Secure
https://ift.tt/eOqJtov
Submitted February 08, 2022 at 11:48PM by jat0369
via reddit https://ift.tt/qPoz6ie
https://ift.tt/eOqJtov
Submitted February 08, 2022 at 11:48PM by jat0369
via reddit https://ift.tt/qPoz6ie
Cyberark
How Docker Made Me More Capable and the Host Less Secure
TL;DR After Docker released a fix [1] for CVE-2021-21284 [2], it unintentionally created a new vulnerability that allows a low-privileged user on the host to execute files from Docker images....
AWS Cloud Security Challenges
https://ift.tt/0U3xr2O
Submitted February 08, 2022 at 11:23PM by 0xdeadbeef0000
via reddit https://ift.tt/L63I8uJ
https://ift.tt/0U3xr2O
Submitted February 08, 2022 at 11:23PM by 0xdeadbeef0000
via reddit https://ift.tt/L63I8uJ
reddit
AWS Cloud Security Challenges
Posted in r/netsec by u/0xdeadbeef0000 • 16 points and 5 comments
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718)
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
Medium
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999)
In this blog post, we’ll look at a Windows Print Spooler local privilege escalation vulnerability that I found and…
SharpSQL: C# MS SQL enum and exploitation
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
GitHub
GitHub - mlcsec/SharpSQL: Simple C# implementation of PowerUpSQL
Simple C# implementation of PowerUpSQL. Contribute to mlcsec/SharpSQL development by creating an account on GitHub.
My SQLi adventure or: why you should make sure your WAF is configured properly
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
Astrocamel
Astrocamel - Blog/Portfolio of George Skouroupathis
astrocamel, Blog, Portfolio, George Skouroupathis
New release of 🔥Kubesploit v0.1.3🔥
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
GitHub
GitHub - cyberark/kubesploit: Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written…
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments. - GitHub - cyberark/kubesploit: Kubesplo...
Top 10 web hacking techniques of 2021
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
PortSwigger Research
Top 10 web hacking techniques of 2021
Welcome to the Top 10 (new) Web Hacking Techniques of 2021, the latest iteration of our annual community-powered effort to identify the most significant web security research released in the last year
npm weak links
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
reddit
npm weak links
Posted in r/netsec by u/Jazzlike-Vegetable69 • 5 points and 1 comment
4 Ways to Combat the DevOps and Security Workforce Shortage
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
Sysdig
4 Ways to Combat the DevOps and Security Workforce Shortage – Sysdig
Security breaches have increased in recent years. The world is dangerously ill-equipped to handle the magnitude of these threats.
Firejail oopsie
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
GitHub
private-cwd leaks access to the entire filesystem · Issue #4780 · netblue30/firejail
Denoscription Using firejail --private --private-cwd=. /usr/bin/sh leaks access to the entire filesystem. Steps to Reproduce cd into some subdirectory of $HOME. `firejail --private --private-cwd=. /u...