Shadow Credentials
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
https://ift.tt/faywcPq
Submitted February 07, 2022 at 06:04PM by netbiosX
via reddit https://ift.tt/buIGmDA
Penetration Testing Lab
Shadow Credentials
Microsoft has introduced Windows Hello for Business (WHfB) to replace traditional password based authentication with a key based trust model. This implementation uses PIN or Bio-metrics which are l…
SHA-256 explained step-by-step visually
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
https://ift.tt/HYaXTK0
Submitted February 07, 2022 at 07:51PM by jandrusk
via reddit https://ift.tt/HMeNXEc
Sha256Algorithm
Sha256 Algorithm Explained
Sha256 algorithm explained online step by step visually
Qbot Likes to Move It, Move It
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
https://ift.tt/XdoRFip
Submitted February 07, 2022 at 07:37PM by TheDFIRReport
via reddit https://ift.tt/IediERC
The DFIR Report
Qbot Likes to Move It, Move It
Qbot (aka QakBot, Quakbot, Pinkslipbot ) has been around for a long time having first been observed back in 2007. More info on Qbot can be found at the following links: Microsoft & Red Canary I…
How to Make Package Signing Useful
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
https://ift.tt/4QCqpOR
Submitted February 07, 2022 at 11:02PM by dlorenc
via reddit https://ift.tt/LqQpmvo
Chainguard, Inc.
How to Make Package Signing Useful
The Case for Farm-to-Table Package SigningThe benefits and limitations of signing an open source package–using a private key to create a unique digital signature–are a surprisingly contentious topic. One of the maintainers associated with the Python Package…
How open-source packages handle releasing security fixes
https://ift.tt/zj1MQ4W
Submitted February 08, 2022 at 07:27AM by Jazzlike-Vegetable69
via reddit https://ift.tt/NeATKmy
https://ift.tt/zj1MQ4W
Submitted February 08, 2022 at 07:27AM by Jazzlike-Vegetable69
via reddit https://ift.tt/NeATKmy
reddit
How open-source packages handle releasing security fixes
Posted in r/netsec by u/Jazzlike-Vegetable69 • 2 points and 0 comments
PPE - Poisoned Pipeline Execution. Running malicious code in your CI, without access to your CI
https://ift.tt/JtLAjOq
Submitted February 08, 2022 at 10:09PM by Hefty_Knowledge_7449
via reddit https://ift.tt/96UyMLg
https://ift.tt/JtLAjOq
Submitted February 08, 2022 at 10:09PM by Hefty_Knowledge_7449
via reddit https://ift.tt/96UyMLg
Medium
PPE — Poisoned Pipeline Execution
Running malicious code in your CI, without access to your CI
How Docker Made Me More Capable and the Host Less Secure
https://ift.tt/eOqJtov
Submitted February 08, 2022 at 11:48PM by jat0369
via reddit https://ift.tt/qPoz6ie
https://ift.tt/eOqJtov
Submitted February 08, 2022 at 11:48PM by jat0369
via reddit https://ift.tt/qPoz6ie
Cyberark
How Docker Made Me More Capable and the Host Less Secure
TL;DR After Docker released a fix [1] for CVE-2021-21284 [2], it unintentionally created a new vulnerability that allows a low-privileged user on the host to execute files from Docker images....
AWS Cloud Security Challenges
https://ift.tt/0U3xr2O
Submitted February 08, 2022 at 11:23PM by 0xdeadbeef0000
via reddit https://ift.tt/L63I8uJ
https://ift.tt/0U3xr2O
Submitted February 08, 2022 at 11:23PM by 0xdeadbeef0000
via reddit https://ift.tt/L63I8uJ
reddit
AWS Cloud Security Challenges
Posted in r/netsec by u/0xdeadbeef0000 • 16 points and 5 comments
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718)
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
Medium
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999)
In this blog post, we’ll look at a Windows Print Spooler local privilege escalation vulnerability that I found and…
SharpSQL: C# MS SQL enum and exploitation
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
GitHub
GitHub - mlcsec/SharpSQL: Simple C# implementation of PowerUpSQL
Simple C# implementation of PowerUpSQL. Contribute to mlcsec/SharpSQL development by creating an account on GitHub.
My SQLi adventure or: why you should make sure your WAF is configured properly
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
Astrocamel
Astrocamel - Blog/Portfolio of George Skouroupathis
astrocamel, Blog, Portfolio, George Skouroupathis
New release of 🔥Kubesploit v0.1.3🔥
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
GitHub
GitHub - cyberark/kubesploit: Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written…
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments. - GitHub - cyberark/kubesploit: Kubesplo...
Top 10 web hacking techniques of 2021
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
PortSwigger Research
Top 10 web hacking techniques of 2021
Welcome to the Top 10 (new) Web Hacking Techniques of 2021, the latest iteration of our annual community-powered effort to identify the most significant web security research released in the last year
npm weak links
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
reddit
npm weak links
Posted in r/netsec by u/Jazzlike-Vegetable69 • 5 points and 1 comment
4 Ways to Combat the DevOps and Security Workforce Shortage
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
Sysdig
4 Ways to Combat the DevOps and Security Workforce Shortage – Sysdig
Security breaches have increased in recent years. The world is dangerously ill-equipped to handle the magnitude of these threats.
Firejail oopsie
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
GitHub
private-cwd leaks access to the entire filesystem · Issue #4780 · netblue30/firejail
Denoscription Using firejail --private --private-cwd=. /usr/bin/sh leaks access to the entire filesystem. Steps to Reproduce cd into some subdirectory of $HOME. `firejail --private --private-cwd=. /u...
🇬🇧 Gaining the upper hand(le) - Hunting for privilege escalations and UAC bypasses by looking for leaked handles in unprivileged processes by @APTortellini and @last0x00
https://ift.tt/lWoBU1K
Submitted February 10, 2022 at 09:45PM by last0x00
via reddit https://ift.tt/YsLQrgD
https://ift.tt/lWoBU1K
Submitted February 10, 2022 at 09:45PM by last0x00
via reddit https://ift.tt/YsLQrgD
APT::WTF - APTortellini’s blog
🇬🇧 Gaining the upper hand(le)
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
Five Vulnerabilities Explained in Moxa MXview for OT Networks
https://ift.tt/7KpmLUI
Submitted February 10, 2022 at 10:36PM by h4ck3dit
via reddit https://ift.tt/3tjqOI0
https://ift.tt/7KpmLUI
Submitted February 10, 2022 at 10:36PM by h4ck3dit
via reddit https://ift.tt/3tjqOI0
Claroty
Moxa MXview Network Management System Vulnerabilities Patched
Claroty Team82 discloses five Moxa MXview network management system vulnerabilities that have been patched by Moxa.
Safer entropy accumulation in Linux 5.18's RNG
https://ift.tt/PmaOHL8
Submitted February 10, 2022 at 10:18PM by zx2c4
via reddit https://ift.tt/RmcNqTu
https://ift.tt/PmaOHL8
Submitted February 10, 2022 at 10:18PM by zx2c4
via reddit https://ift.tt/RmcNqTu
reddit
Safer entropy accumulation in Linux 5.18's RNG
Posted in r/netsec by u/zx2c4 • 121 points and 4 comments
what is Walkme Extension used for? I have it installed and enforced by default without ability to disable it - in all Chrome browsers on the work laptop...
https://ift.tt/LpPErwg
Submitted February 10, 2022 at 09:52PM by One-World-One-Love
via reddit https://ift.tt/Fjc4wG2
https://ift.tt/LpPErwg
Submitted February 10, 2022 at 09:52PM by One-World-One-Love
via reddit https://ift.tt/Fjc4wG2
Google
Walkme Extension
WalkMe enables your business to simplify the online experience and eliminate user confusion.
Web3 and Security: It’s Time To Grow Up
https://ift.tt/8HgXqKN
Submitted February 11, 2022 at 08:43AM by ArgumentException
via reddit https://ift.tt/xc0BmuH
https://ift.tt/8HgXqKN
Submitted February 11, 2022 at 08:43AM by ArgumentException
via reddit https://ift.tt/xc0BmuH
Kudelski Security Research
Web3 and Security: It’s Time To Grow Up
Hello Web3/blockchain world, great job. You got people to take you seriously, trusting your projects and investing their money. You’ve sold people on your innovations, and people believe in your pr…