Certipy 2.0: BloodHound, New Domain Privilege Escalation Techniques, Shadow Credentials, Golden Certificates, and more!
https://ift.tt/6w3r4og
Submitted February 19, 2022 at 06:48PM by ly4k_
via reddit https://ift.tt/5aJpyfU
https://ift.tt/6w3r4og
Submitted February 19, 2022 at 06:48PM by ly4k_
via reddit https://ift.tt/5aJpyfU
Medium
Certipy 2.0: BloodHound, New Escalations, Shadow Credentials, Golden Certificates, and more!
As the noscript states, the latest release of Certipy contains many new features, techniques and improvements. This blog post dives into the…
rconn - Consume services behind NAT or firewall without opening ports or port-forwarding
https://ift.tt/KSAwjMX
Submitted February 20, 2022 at 06:56PM by jafarlihi
via reddit https://ift.tt/5GMzB3K
https://ift.tt/KSAwjMX
Submitted February 20, 2022 at 06:56PM by jafarlihi
via reddit https://ift.tt/5GMzB3K
GitHub
GitHub - jafarlihi/rconn: rconn is a multiplatform program for creating generic reverse connections. Lets you consume services…
rconn is a multiplatform program for creating generic reverse connections. Lets you consume services that are behind firewall or NAT without opening ports or port-forwarding. - GitHub - jafarlihi/r...
Analysis of CVE-2021-36260: Exploited in the Wild Hikvision Camera Vulnerability
https://ift.tt/hHw3VlW
Submitted February 21, 2022 at 03:22AM by chicksdigthelongrun
via reddit https://ift.tt/AbLxXtu
https://ift.tt/hHw3VlW
Submitted February 21, 2022 at 03:22AM by chicksdigthelongrun
via reddit https://ift.tt/AbLxXtu
AttackerKB
CVE-2021-36260 | AttackerKB
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability…
Linux kernel NFC Use-After-Free (CVE-2021-23134) PoC
https://ift.tt/mScgaFO
Submitted February 21, 2022 at 11:53AM by awarau888
via reddit https://ift.tt/x7VnaX4
https://ift.tt/mScgaFO
Submitted February 21, 2022 at 11:53AM by awarau888
via reddit https://ift.tt/x7VnaX4
ruia-ruia.github.io
Linux kernel Use-After-Free (CVE-2021-23134) PoC.
Warning to the reader
This is my first time doing kernel exploit development - so the following probably contains some errors which I apologise in advance for.
This is my first time doing kernel exploit development - so the following probably contains some errors which I apologise in advance for.
nrich: a new tool to quickly find open ports and vulnerabilities via Shodan
https://ift.tt/4ZuMvDg
Submitted February 21, 2022 at 02:48PM by 0xdea
via reddit https://ift.tt/VfNEkLi
https://ift.tt/4ZuMvDg
Submitted February 21, 2022 at 02:48PM by 0xdea
via reddit https://ift.tt/VfNEkLi
GitLab
shodan-public / nrich
A command-line tool to quickly analyze all IPs in a file and see which ones have open ports/ vulnerabilities. Can also be fed data from stdin to be...
Plone Scanner Version 0.01
https://ift.tt/IxEAiqf
Submitted February 21, 2022 at 04:58PM by halencarjunior
via reddit https://ift.tt/KAviyj4
https://ift.tt/IxEAiqf
Submitted February 21, 2022 at 04:58PM by halencarjunior
via reddit https://ift.tt/KAviyj4
GitHub
GitHub - halencarjunior/plsc4n
Contribute to halencarjunior/plsc4n development by creating an account on GitHub.
CodeCat is an open-source tool to help you find/track user input sinks and bugs using static code analysis. These points follow regex rules.
https://ift.tt/Y9W6NM0
Submitted February 21, 2022 at 06:10PM by CoolerVoid
via reddit https://ift.tt/QAEiCND
https://ift.tt/Y9W6NM0
Submitted February 21, 2022 at 06:10PM by CoolerVoid
via reddit https://ift.tt/QAEiCND
My first vulnerability - Arista gNMI authentication bypass CVE-2021-28500
https://ift.tt/oBIupxE
Submitted February 21, 2022 at 09:50PM by MilesTails
via reddit https://ift.tt/p0d9eQo
https://ift.tt/oBIupxE
Submitted February 21, 2022 at 09:50PM by MilesTails
via reddit https://ift.tt/p0d9eQo
sutcliffe.it
My First Vulnerability
CVE-2021-28500 Talkative Marmot For those of you who that don’t want to read the whole back story and just want to see what CVE-2021-28500 (#TalkativeMarmot) is, you can review Arista’s full detailed security advisory here.
Essentially, this is an authentication…
Essentially, this is an authentication…
Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
https://ift.tt/FnCjsRa
Submitted February 21, 2022 at 09:44PM by toyojuni
via reddit https://ift.tt/4KBavro
https://ift.tt/FnCjsRa
Submitted February 21, 2022 at 09:44PM by toyojuni
via reddit https://ift.tt/4KBavro
Medium
Finding an unseen SQL Injection by bypassing escape functions in mysqljs/mysql
It was found that unexpected behaviors in the query’s escape function could cause a SQL injection in mysqljs/mysql
Find You: Building a stealth AirTag clone
https://ift.tt/CS1jcOE
Submitted February 21, 2022 at 09:24PM by breakingsystems
via reddit https://ift.tt/wJDbEiH
https://ift.tt/CS1jcOE
Submitted February 21, 2022 at 09:24PM by breakingsystems
via reddit https://ift.tt/wJDbEiH
positive.security
Find You: Building a stealth AirTag clone | Positive Security
We built an AirTag clone capable of silently and continuously tracking someone. The device accomplishes this by sending just one beacon per generated public key, thereby staying invisible to tracking notifications for iOS users and Apple’s Tracker Detect…
Wrote a new blog post on injecting fake credentials into lsass memory using New-HoneyHash and alerting with Elastic.
https://ift.tt/5m906bO
Submitted February 21, 2022 at 11:34PM by m_edmondson
via reddit https://ift.tt/1HwuPMi
https://ift.tt/5m906bO
Submitted February 21, 2022 at 11:34PM by m_edmondson
via reddit https://ift.tt/1HwuPMi
Marcus Edmondson | Threat Hunting | Information Security
Dripping a Little Honey in Your Environment
Today I wanted to talk about using the deception technology called New-HoneyHash.ps1. This is a tool that was inspired by Mark Baggett and authored by Matt Graeber, that will inject fake credential…
Command line execution fuzzer and bruteforcer (Equivalent of wfuzz for all command line)
https://ift.tt/3Jx6DVw
Submitted February 22, 2022 at 02:40AM by cryptaureau
via reddit https://ift.tt/EqB0LyG
https://ift.tt/3Jx6DVw
Submitted February 22, 2022 at 02:40AM by cryptaureau
via reddit https://ift.tt/EqB0LyG
GitHub
GitHub - ariary/cfuzz: Command line fuzzer and bruteforcer 🌪 wfuzz for command
Command line fuzzer and bruteforcer 🌪 wfuzz for command - GitHub - ariary/cfuzz: Command line fuzzer and bruteforcer 🌪 wfuzz for command
A Practical Guide To Attacking JWT (JSON Web Tokens) - RedHunt Labs
https://ift.tt/LCpB3jD
Submitted February 22, 2022 at 08:39PM by redhuntlabs
via reddit https://ift.tt/nBpz0Dy
https://ift.tt/LCpB3jD
Submitted February 22, 2022 at 08:39PM by redhuntlabs
via reddit https://ift.tt/nBpz0Dy
RedHunt Labs
Guide To Attacking JWT (JSON Web Tokens) [Free Download] - RedHunt Labs
Download the Practical Guide to Attacking JWT (JSON Web Tokens). Must read for pentesters, developers, security professionals and researchers.
Horde Webmail 5.2.22 - Account Takeover via Email
https://ift.tt/r6bwP8N
Submitted February 22, 2022 at 09:33PM by monoimpact
via reddit https://ift.tt/Yb6RkOH
https://ift.tt/r6bwP8N
Submitted February 22, 2022 at 09:33PM by monoimpact
via reddit https://ift.tt/Yb6RkOH
Sonarsource
Horde Webmail 5.2.22 - Account Takeover via Email
We recently discovered a code vulnerability in Horde Webmail that can be used by attackers to take over email accounts by sending a malicious email.
Challenge-3 Weekly Cloud Security Challenge
https://ift.tt/O59lJ3t
Submitted February 22, 2022 at 11:19PM by 0xdeadbeef0000
via reddit https://ift.tt/REiaIMu
https://ift.tt/O59lJ3t
Submitted February 22, 2022 at 11:19PM by 0xdeadbeef0000
via reddit https://ift.tt/REiaIMu
reddit
Challenge-3 Weekly Cloud Security Challenge
Posted in r/netsec by u/0xdeadbeef0000 • 13 points and 0 comments
Cyrus SASL 2.1.28 has been released with SCRAM improvements and CVE fixes
https://ift.tt/aHW3Jfh
Submitted February 23, 2022 at 05:53AM by Neustradamus
via reddit https://ift.tt/prjcStz
https://ift.tt/aHW3Jfh
Submitted February 23, 2022 at 05:53AM by Neustradamus
via reddit https://ift.tt/prjcStz
reddit
Cyrus SASL 2.1.28 has been released with SCRAM improvements and...
Posted in r/netsec by u/Neustradamus • 3 points and 0 comments
You can still CSRF POST requests under the default browser SameSite cookie policy. How to jump through the required hoops.
https://ift.tt/lmc8TDz
Submitted February 23, 2022 at 06:16AM by MysteriousHotel3017
via reddit https://ift.tt/ZsrzLdD
https://ift.tt/lmc8TDz
Submitted February 23, 2022 at 06:16AM by MysteriousHotel3017
via reddit https://ift.tt/ZsrzLdD
reddit
You can still CSRF POST requests under the default browser...
Posted in r/netsec by u/MysteriousHotel3017 • 1 point and 0 comments
tmp.0ut Volume 2
https://tmpout.sh/2/
Submitted February 23, 2022 at 07:46AM by VVX7
via reddit https://ift.tt/Pm3zJIi
https://tmpout.sh/2/
Submitted February 23, 2022 at 07:46AM by VVX7
via reddit https://ift.tt/Pm3zJIi
reddit
tmp.0ut Volume 2
Posted in r/netsec by u/VVX7 • 1 point and 0 comments
Remote Code Execution in pfSense <= 2.5.2
https://ift.tt/KM4YRoP
Submitted February 23, 2022 at 07:36PM by smaury
via reddit https://ift.tt/Kd6035x
https://ift.tt/KM4YRoP
Submitted February 23, 2022 at 07:36PM by smaury
via reddit https://ift.tt/Kd6035x
Shielder
Shielder - Remote Code Execution in pfSense <= 2.5.2
pfSense <= 2.5.2 allows authenticated users to inject arbitrary sed-specific code, which leads to an Arbitrary File Write, resulting in a Remote Code Execution. The vulnerability is also exploitable through a Cross-Site Request Forgery.
The vulnerability research team @GitLab is introducing an open-source community-driven advisory database for third-party security dependencies
https://ift.tt/XOq5Yrj
Submitted February 23, 2022 at 10:12PM by howie1001
via reddit https://ift.tt/7rI19bk
https://ift.tt/XOq5Yrj
Submitted February 23, 2022 at 10:12PM by howie1001
via reddit https://ift.tt/7rI19bk
GitLab
Introducing a community-driven advisory database for third-party software dependencies
The advisory data can be readily adopted, adapted, and exchanged. Learn more here.
Automating bug bounties
https://ift.tt/7yVEbiH
Submitted February 24, 2022 at 03:52AM by pedro_benteveo
via reddit https://ift.tt/1sUa9L5
https://ift.tt/7yVEbiH
Submitted February 24, 2022 at 03:52AM by pedro_benteveo
via reddit https://ift.tt/1sUa9L5
Benteveo
Automating bug bounties — Benteveo
I have bad news. I first noticed this one day like any other, and once I noticed it, I couldn’t escape the reality. Hacking is boring. This may seem counter-intuitive at first. If you looked at your average hacker, they wouldn’t look bored. More like a mixture…