Internet-Wide Study: State Of SPF, DKIM, And DMARC - RedHunt Labs
https://ift.tt/7sBv5Pq
Submitted February 11, 2022 at 12:24PM by redhuntlabs
via reddit https://ift.tt/XjOgvPc
https://ift.tt/7sBv5Pq
Submitted February 11, 2022 at 12:24PM by redhuntlabs
via reddit https://ift.tt/XjOgvPc
RedHunt Labs
Internet-Wide Study: State Of SPF, DKIM, And DMARC (Wave 6) - RedHunt Labs
At RedHunt Labs, (under Project Resonance), we frequently conduct internet-wide research in different shapes and formats to understand the state of security across the internet. In this iteration, we conducted a study about the current state of DNS configurations…
AD CS: from ManageCA to RCE - BlackArrow
https://ift.tt/I7WuOG3
Submitted February 11, 2022 at 04:37PM by Margaruga
via reddit https://ift.tt/2K1Q3Zr
https://ift.tt/I7WuOG3
Submitted February 11, 2022 at 04:37PM by Margaruga
via reddit https://ift.tt/2K1Q3Zr
Tarlogic Security
AD CS: from ManageCA to RCE
Disclosure of two novel techniques to attack and compromise a CA server by abusing the ManageCA permissions (AD CS)
A simple tool to audit Linux system libraries to find public security vulnerabilities.
https://ift.tt/Q6OZ8Uy
Submitted February 11, 2022 at 05:11PM by CoolerVoid
via reddit https://ift.tt/dw73la0
https://ift.tt/Q6OZ8Uy
Submitted February 11, 2022 at 05:11PM by CoolerVoid
via reddit https://ift.tt/dw73la0
PDFRip - A high-performance PDF password cracking utility written in Rust
https://ift.tt/QrCoxK6
Submitted February 11, 2022 at 09:00PM by mufeedvh
via reddit https://ift.tt/pACQTxR
https://ift.tt/QrCoxK6
Submitted February 11, 2022 at 09:00PM by mufeedvh
via reddit https://ift.tt/pACQTxR
GitHub
GitHub - mufeedvh/pdfrip: A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders…
A multi-threaded PDF password cracking utility equipped with commonly encountered password format builders and dictionary attacks. - GitHub - mufeedvh/pdfrip: A multi-threaded PDF password cracking...
Cisco ASDM: Manage at Your Own Risk
https://ift.tt/CkXOHfp
Submitted February 11, 2022 at 11:31PM by chicksdigthelongrun
via reddit https://ift.tt/xKP93bZ
https://ift.tt/CkXOHfp
Submitted February 11, 2022 at 11:31PM by chicksdigthelongrun
via reddit https://ift.tt/xKP93bZ
AttackerKB
CVE-2021-1585 | AttackerKB
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a us…
WordPress < 5.8.3 - Object Injection Vulnerability
https://ift.tt/Acw9MkE
Submitted February 11, 2022 at 11:00PM by monoimpact
via reddit https://ift.tt/EJh0f3c
https://ift.tt/Acw9MkE
Submitted February 11, 2022 at 11:00PM by monoimpact
via reddit https://ift.tt/EJh0f3c
Sonarsource
WordPress < 5.8.3 - Object Injection Vulnerability
We discovered an interesting code vulnerability that could be used to bypass hardening mechanisms in the popular WordPress CMS.
Pre-auth WAN remote root for Cisco RV340 VPN Gateway Router
https://ift.tt/ANtfoEX
Submitted February 11, 2022 at 11:53PM by ChoiceGrapefruit0
via reddit https://ift.tt/cdBWw8K
https://ift.tt/ANtfoEX
Submitted February 11, 2022 at 11:53PM by ChoiceGrapefruit0
via reddit https://ift.tt/cdBWw8K
GitHub
PoC/advisories/Pwn2Own/Austin_2021/flashback_connects/flashback_connects.md at master · pedrib/PoC
Advisories, proof of concept files and exploits that have been made public by @pedrib. - pedrib/PoC
Simple tool to find client side prototype pollution vulnerability
https://ift.tt/g9bsoyD
Submitted February 12, 2022 at 05:15AM by boch33n
via reddit https://ift.tt/m85CvkJ
https://ift.tt/g9bsoyD
Submitted February 12, 2022 at 05:15AM by boch33n
via reddit https://ift.tt/m85CvkJ
GitHub
GitHub - kosmosec/proto-find: Let's check if your target is vulnerable for client side prototype pollution.
Let's check if your target is vulnerable for client side prototype pollution. - kosmosec/proto-find
CISSP Domain 1 - Episode 5 - Security Roles and Responsibilities, Control Frameworks, Due care & Due Diligence, Policies, Standards, Procedures, Guidelines & Baseline and Threat Modeling by Get Set CISSP
https://ift.tt/cvAMCJl
Submitted February 12, 2022 at 10:31AM by Tradition_Wonderful
via reddit https://ift.tt/ctGAPJe
https://ift.tt/cvAMCJl
Submitted February 12, 2022 at 10:31AM by Tradition_Wonderful
via reddit https://ift.tt/ctGAPJe
Spotify for Podcasters
CISSP Domain 1 - Episode 5 - Security Roles and Responsibilities, Control Frameworks, Due care & Due Diligence, Policies, Standards…
In this episode I talk about the concept of Security Roles and Responsibilities, Control Frameworks, Due care & Due Diligence, Policies, Standards, Procedures, Guidelines & Baseline and Threat Modeling which are essentials from an exam and real life security…
MyloBot 2022 – Analysis of the new version of this evasive botnet that appears to just send extortion emails, but has the potential to do much more.
https://ift.tt/QSUz3km
Submitted February 14, 2022 at 07:57PM by woja111
via reddit https://ift.tt/2X3kruZ
https://ift.tt/QSUz3km
Submitted February 14, 2022 at 07:57PM by woja111
via reddit https://ift.tt/2X3kruZ
Rapid7
Managed Threat Complete: MDR Security Solution - Rapid7
Rapid7’s Managed Threat Complete with unlimited incident response and vulnerability management. Contain costs and eliminate threats. Get Started Now.
Dropping Files on a Domain Controller Using CVE-2021-43893
https://ift.tt/6FJIvRp
Submitted February 14, 2022 at 09:15PM by chicksdigthelongrun
via reddit https://ift.tt/GTNOtf1
https://ift.tt/6FJIvRp
Submitted February 14, 2022 at 09:15PM by chicksdigthelongrun
via reddit https://ift.tt/GTNOtf1
Rapid7
Dropping Files on a Domain Controller Using CVE-2021-43893 | Rapid7 Blog
Multiple vulnerabilities in Concrete CMS part2 (Privesc/SSRF/etc.)
https://ift.tt/MJbhjqN
Submitted February 14, 2022 at 11:02PM by adrian_rt
via reddit https://ift.tt/fiHnrlm
https://ift.tt/MJbhjqN
Submitted February 14, 2022 at 11:02PM by adrian_rt
via reddit https://ift.tt/fiHnrlm
Cyber Security Services - London
Multiple vulnerabilities in Concrete CMS - part2 (PrivEsc/SSRF/etc)
multiple vulnerabilities in concrete cms part2. Privilege escalation, SSRF, password reset poisoning. Concrete CMS pentest
Eliminating Dangling Elastic IP Takeovers with Ghostbuster
https://ift.tt/74rWauG
Submitted February 15, 2022 at 01:44AM by Mempodipper
via reddit https://ift.tt/zt6TAWw
https://ift.tt/74rWauG
Submitted February 15, 2022 at 01:44AM by Mempodipper
via reddit https://ift.tt/zt6TAWw
Persistence – Notepad++ Plugins
https://ift.tt/4iFkwuy
Submitted February 15, 2022 at 12:59AM by netbiosX
via reddit https://ift.tt/KlIt3cb
https://ift.tt/4iFkwuy
Submitted February 15, 2022 at 12:59AM by netbiosX
via reddit https://ift.tt/KlIt3cb
Penetration Testing Lab
Persistence – Notepad++ Plugins
It is not uncommon a windows environment especially dedicated servers which are managed by developers or IT staff to have installed the Notepad++ text editor. Except of the storage of noscripts and a…
PrivateLoader to new Anubis Loader
https://ift.tt/TX1YGtW
Submitted February 15, 2022 at 03:41AM by sysopfb
via reddit https://ift.tt/qQK1pvc
https://ift.tt/TX1YGtW
Submitted February 15, 2022 at 03:41AM by sysopfb
via reddit https://ift.tt/qQK1pvc
Medium
PrivateLoader to Anubis Loader
By: Jason Reaves and Joshua Platt
Advisory: Western Digital My Cloud Pro Series PR4100 RCE
https://ift.tt/xY06KWE
Submitted February 15, 2022 at 04:47PM by g_e_r_h_a_r_d
via reddit https://ift.tt/XP71Skz
https://ift.tt/xY06KWE
Submitted February 15, 2022 at 04:47PM by g_e_r_h_a_r_d
via reddit https://ift.tt/XP71Skz
IoT Inspector
Advisory: Western Digital My Cloud Pro Series PR4100 RCE
The IoT Inspector Research Lab uncovered a command injection vulnerability on Western Digital My Cloud Pro Series PR4100.
merOS-virt - Build and Interact with a Set of Virtual Machines.
https://ift.tt/zIiVRDh
Submitted February 15, 2022 at 04:58PM by AranAilbhe
via reddit https://ift.tt/KaX9Yix
https://ift.tt/zIiVRDh
Submitted February 15, 2022 at 04:58PM by AranAilbhe
via reddit https://ift.tt/KaX9Yix
GitHub
GitHub - AranAilbhe/merOS-virt: Build and Interact with a Set of Virtual Machines
Build and Interact with a Set of Virtual Machines. Contribute to AranAilbhe/merOS-virt development by creating an account on GitHub.
CVE-2021-44521 – Exploiting Apache Cassandra User-Defined Functions for Remote Code Execution
https://ift.tt/opN8hIr
Submitted February 15, 2022 at 10:47PM by SRMish3
via reddit https://ift.tt/uoVKHBU
https://ift.tt/opN8hIr
Submitted February 15, 2022 at 10:47PM by SRMish3
via reddit https://ift.tt/uoVKHBU
JFrog
CVE-2021-44521: Exploiting Apache Cassandra User-Defined Functions for Remote Code Execution
JFrog’s Security Research team recently disclosed an RCE (remote code execution) issue in Apache Cassandra, which has been assigned to CVE-2021-44521 (CVSS 8.4). This Apache security vulnerability is easy to exploit and has the potential to wreak havoc on…
A CLI SAST (Static application security testing) tool which was built with the intent of finding vulnerable Clojure code via rules that use a simple pattern language.
https://ift.tt/oM30tUH
Submitted February 15, 2022 at 10:45PM by mthbernardes
via reddit https://ift.tt/ZiSQXEJ
https://ift.tt/oM30tUH
Submitted February 15, 2022 at 10:45PM by mthbernardes
via reddit https://ift.tt/ZiSQXEJ
GitHub
GitHub - clj-holmes/clj-holmes: A CLI SAST (Static application security testing) tool which was built with the intent of finding…
A CLI SAST (Static application security testing) tool which was built with the intent of finding vulnerable Clojure code via rules that use a simple pattern language. - GitHub - clj-holmes/clj-holm...
Dependabot alternative for Clojure
https://ift.tt/Hz2TOL9
Submitted February 16, 2022 at 12:50AM by mthbernardes
via reddit https://ift.tt/z0aYiSl
https://ift.tt/Hz2TOL9
Submitted February 16, 2022 at 12:50AM by mthbernardes
via reddit https://ift.tt/z0aYiSl
GitHub
GitHub - clj-holmes/clj-watson: clojure deps SCA
clojure deps SCA. Contribute to clj-holmes/clj-watson development by creating an account on GitHub.
GoIP-1 GSM gateway could be harnessed for phone fraud by hackers
https://ift.tt/7W0YQ8r
Submitted February 16, 2022 at 01:13AM by ValtteriLe
via reddit https://ift.tt/xhUS9Pc
https://ift.tt/7W0YQ8r
Submitted February 16, 2022 at 01:13AM by ValtteriLe
via reddit https://ift.tt/xhUS9Pc
Shufflingbytes
GoIP-1 GSM gateway could be harnessed for phone fraud by hackers
GoIP-1 GSM gateway contains vulnerabilities that allow hackers to send SMS messages and make calls for free