SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022–22718)
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
https://ift.tt/MLi8yKl
Submitted February 09, 2022 at 02:04AM by ly4k_
via reddit https://ift.tt/bTC2piW
Medium
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999)
In this blog post, we’ll look at a Windows Print Spooler local privilege escalation vulnerability that I found and…
SharpSQL: C# MS SQL enum and exploitation
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
https://ift.tt/CBG61TO
Submitted February 09, 2022 at 03:46AM by IamaCerealKilla
via reddit https://ift.tt/gLtz8pw
GitHub
GitHub - mlcsec/SharpSQL: Simple C# implementation of PowerUpSQL
Simple C# implementation of PowerUpSQL. Contribute to mlcsec/SharpSQL development by creating an account on GitHub.
My SQLi adventure or: why you should make sure your WAF is configured properly
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
https://ift.tt/CPTb7Bj
Submitted February 09, 2022 at 03:33PM by gsk-upxyz
via reddit https://ift.tt/1p9LZ8z
Astrocamel
Astrocamel - Blog/Portfolio of George Skouroupathis
astrocamel, Blog, Portfolio, George Skouroupathis
New release of 🔥Kubesploit v0.1.3🔥
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
https://ift.tt/CdiUtbQ
Submitted February 09, 2022 at 08:32PM by jat0369
via reddit https://ift.tt/SDc2jq5
GitHub
GitHub - cyberark/kubesploit: Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written…
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments. - GitHub - cyberark/kubesploit: Kubesplo...
Top 10 web hacking techniques of 2021
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
https://ift.tt/diOwPQN
Submitted February 09, 2022 at 08:01PM by albinowax
via reddit https://ift.tt/8vLuXJQ
PortSwigger Research
Top 10 web hacking techniques of 2021
Welcome to the Top 10 (new) Web Hacking Techniques of 2021, the latest iteration of our annual community-powered effort to identify the most significant web security research released in the last year
npm weak links
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
https://ift.tt/hFlp5kA
Submitted February 10, 2022 at 02:42AM by Jazzlike-Vegetable69
via reddit https://ift.tt/Ez4gm1h
reddit
npm weak links
Posted in r/netsec by u/Jazzlike-Vegetable69 • 5 points and 1 comment
4 Ways to Combat the DevOps and Security Workforce Shortage
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
https://ift.tt/lVCr8xF
Submitted February 10, 2022 at 03:41PM by MiguelHzBz
via reddit https://ift.tt/LFfp014
Sysdig
4 Ways to Combat the DevOps and Security Workforce Shortage – Sysdig
Security breaches have increased in recent years. The world is dangerously ill-equipped to handle the magnitude of these threats.
Firejail oopsie
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
https://ift.tt/KtzydUn
Submitted February 10, 2022 at 06:35PM by MonkeeSage
via reddit https://ift.tt/krYloyw
GitHub
private-cwd leaks access to the entire filesystem · Issue #4780 · netblue30/firejail
Denoscription Using firejail --private --private-cwd=. /usr/bin/sh leaks access to the entire filesystem. Steps to Reproduce cd into some subdirectory of $HOME. `firejail --private --private-cwd=. /u...
🇬🇧 Gaining the upper hand(le) - Hunting for privilege escalations and UAC bypasses by looking for leaked handles in unprivileged processes by @APTortellini and @last0x00
https://ift.tt/lWoBU1K
Submitted February 10, 2022 at 09:45PM by last0x00
via reddit https://ift.tt/YsLQrgD
https://ift.tt/lWoBU1K
Submitted February 10, 2022 at 09:45PM by last0x00
via reddit https://ift.tt/YsLQrgD
APT::WTF - APTortellini’s blog
🇬🇧 Gaining the upper hand(le)
Home of the Advanced Persistent Tortellini - aka APTortellini, an Italian collective of hackers publishing technical research regarding offensive security.
Five Vulnerabilities Explained in Moxa MXview for OT Networks
https://ift.tt/7KpmLUI
Submitted February 10, 2022 at 10:36PM by h4ck3dit
via reddit https://ift.tt/3tjqOI0
https://ift.tt/7KpmLUI
Submitted February 10, 2022 at 10:36PM by h4ck3dit
via reddit https://ift.tt/3tjqOI0
Claroty
Moxa MXview Network Management System Vulnerabilities Patched
Claroty Team82 discloses five Moxa MXview network management system vulnerabilities that have been patched by Moxa.
Safer entropy accumulation in Linux 5.18's RNG
https://ift.tt/PmaOHL8
Submitted February 10, 2022 at 10:18PM by zx2c4
via reddit https://ift.tt/RmcNqTu
https://ift.tt/PmaOHL8
Submitted February 10, 2022 at 10:18PM by zx2c4
via reddit https://ift.tt/RmcNqTu
reddit
Safer entropy accumulation in Linux 5.18's RNG
Posted in r/netsec by u/zx2c4 • 121 points and 4 comments
what is Walkme Extension used for? I have it installed and enforced by default without ability to disable it - in all Chrome browsers on the work laptop...
https://ift.tt/LpPErwg
Submitted February 10, 2022 at 09:52PM by One-World-One-Love
via reddit https://ift.tt/Fjc4wG2
https://ift.tt/LpPErwg
Submitted February 10, 2022 at 09:52PM by One-World-One-Love
via reddit https://ift.tt/Fjc4wG2
Google
Walkme Extension
WalkMe enables your business to simplify the online experience and eliminate user confusion.
Web3 and Security: It’s Time To Grow Up
https://ift.tt/8HgXqKN
Submitted February 11, 2022 at 08:43AM by ArgumentException
via reddit https://ift.tt/xc0BmuH
https://ift.tt/8HgXqKN
Submitted February 11, 2022 at 08:43AM by ArgumentException
via reddit https://ift.tt/xc0BmuH
Kudelski Security Research
Web3 and Security: It’s Time To Grow Up
Hello Web3/blockchain world, great job. You got people to take you seriously, trusting your projects and investing their money. You’ve sold people on your innovations, and people believe in your pr…
Internet-Wide Study: State Of SPF, DKIM, And DMARC - RedHunt Labs
https://ift.tt/7sBv5Pq
Submitted February 11, 2022 at 12:24PM by redhuntlabs
via reddit https://ift.tt/XjOgvPc
https://ift.tt/7sBv5Pq
Submitted February 11, 2022 at 12:24PM by redhuntlabs
via reddit https://ift.tt/XjOgvPc
RedHunt Labs
Internet-Wide Study: State Of SPF, DKIM, And DMARC (Wave 6) - RedHunt Labs
At RedHunt Labs, (under Project Resonance), we frequently conduct internet-wide research in different shapes and formats to understand the state of security across the internet. In this iteration, we conducted a study about the current state of DNS configurations…
AD CS: from ManageCA to RCE - BlackArrow
https://ift.tt/I7WuOG3
Submitted February 11, 2022 at 04:37PM by Margaruga
via reddit https://ift.tt/2K1Q3Zr
https://ift.tt/I7WuOG3
Submitted February 11, 2022 at 04:37PM by Margaruga
via reddit https://ift.tt/2K1Q3Zr
Tarlogic Security
AD CS: from ManageCA to RCE
Disclosure of two novel techniques to attack and compromise a CA server by abusing the ManageCA permissions (AD CS)
A simple tool to audit Linux system libraries to find public security vulnerabilities.
https://ift.tt/Q6OZ8Uy
Submitted February 11, 2022 at 05:11PM by CoolerVoid
via reddit https://ift.tt/dw73la0
https://ift.tt/Q6OZ8Uy
Submitted February 11, 2022 at 05:11PM by CoolerVoid
via reddit https://ift.tt/dw73la0
PDFRip - A high-performance PDF password cracking utility written in Rust
https://ift.tt/QrCoxK6
Submitted February 11, 2022 at 09:00PM by mufeedvh
via reddit https://ift.tt/pACQTxR
https://ift.tt/QrCoxK6
Submitted February 11, 2022 at 09:00PM by mufeedvh
via reddit https://ift.tt/pACQTxR
GitHub
GitHub - mufeedvh/pdfrip: A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders…
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks. - GitHub - mufeedvh/pdfrip: A multi-threaded PDF password cracking...
Cisco ASDM: Manage at Your Own Risk
https://ift.tt/CkXOHfp
Submitted February 11, 2022 at 11:31PM by chicksdigthelongrun
via reddit https://ift.tt/xKP93bZ
https://ift.tt/CkXOHfp
Submitted February 11, 2022 at 11:31PM by chicksdigthelongrun
via reddit https://ift.tt/xKP93bZ
AttackerKB
CVE-2021-1585 | AttackerKB
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a us…
WordPress < 5.8.3 - Object Injection Vulnerability
https://ift.tt/Acw9MkE
Submitted February 11, 2022 at 11:00PM by monoimpact
via reddit https://ift.tt/EJh0f3c
https://ift.tt/Acw9MkE
Submitted February 11, 2022 at 11:00PM by monoimpact
via reddit https://ift.tt/EJh0f3c
Sonarsource
WordPress < 5.8.3 - Object Injection Vulnerability
We discovered an interesting code vulnerability that could be used to bypass hardening mechanisms in the popular WordPress CMS.
Pre-auth WAN remote root for Cisco RV340 VPN Gateway Router
https://ift.tt/ANtfoEX
Submitted February 11, 2022 at 11:53PM by ChoiceGrapefruit0
via reddit https://ift.tt/cdBWw8K
https://ift.tt/ANtfoEX
Submitted February 11, 2022 at 11:53PM by ChoiceGrapefruit0
via reddit https://ift.tt/cdBWw8K
GitHub
PoC/advisories/Pwn2Own/Austin_2021/flashback_connects/flashback_connects.md at master · pedrib/PoC
Advisories, proof of concept files and exploits that have been made public by @pedrib. - pedrib/PoC
Simple tool to find client side prototype pollution vulnerability
https://ift.tt/g9bsoyD
Submitted February 12, 2022 at 05:15AM by boch33n
via reddit https://ift.tt/m85CvkJ
https://ift.tt/g9bsoyD
Submitted February 12, 2022 at 05:15AM by boch33n
via reddit https://ift.tt/m85CvkJ
GitHub
GitHub - kosmosec/proto-find: Let's check if your target is vulnerable for client side prototype pollution.
Let's check if your target is vulnerable for client side prototype pollution. - kosmosec/proto-find