Kubernetes Security Series - https://ift.tt/mTq6O3Y
https://ift.tt/mTq6O3Y
Submitted April 27, 2022 at 11:40AM by agrawal7
via reddit https://ift.tt/J90KzpU
https://ift.tt/mTq6O3Y
Submitted April 27, 2022 at 11:40AM by agrawal7
via reddit https://ift.tt/J90KzpU
smart7.in
Kubernetes Cluster: Attack and Defense Perspective Part-2 - Security Blogs
Hi all,
CVE-2021-22204 : Exploiting remote code execution within VirusTotal platform in order to gain access to its various scans capabilities
https://ift.tt/UJN8poz
Submitted April 27, 2022 at 09:26AM by Late_Ice_9288
via reddit https://ift.tt/kjDmaU7
https://ift.tt/UJN8poz
Submitted April 27, 2022 at 09:26AM by Late_Ice_9288
via reddit https://ift.tt/kjDmaU7
Reddit
r/netsec on Reddit: CVE-2021-22204 : Exploiting remote code execution within VirusTotal platform in order to gain access to its…
Posted by u/Late_Ice_9288 - 5 votes and 4 comments
Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages?
https://ift.tt/BxUGT65
Submitted April 27, 2022 at 10:36AM by mkatch
via reddit https://ift.tt/xsJBuDQ
https://ift.tt/BxUGT65
Submitted April 27, 2022 at 10:36AM by mkatch
via reddit https://ift.tt/xsJBuDQ
Aquasec
Package Planting: Are You [Unknowingly] Maintaining Poisoned Packages?
Team Nautilus found a flaw in npm that allows attackers to perform package planting and masquerade a malicious package as legitimate to trick developers
Encrypting our way to SSRF in VMWare Workspace One UEM/Airwatch (CVE-2021-22054)
https://ift.tt/zVke5N1
Submitted April 27, 2022 at 03:23PM by FireFart
via reddit https://ift.tt/5j2L3zb
https://ift.tt/zVke5N1
Submitted April 27, 2022 at 03:23PM by FireFart
via reddit https://ift.tt/5j2L3zb
Assetnote
Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054)
Application security issues found by Assetnote
Hands-on lab for exploiting Psychic Signatures in JWTs
https://ift.tt/aMZ4EN6
Submitted April 27, 2022 at 06:05PM by DebugDucky
via reddit https://ift.tt/0OdDzx1
https://ift.tt/aMZ4EN6
Submitted April 27, 2022 at 06:05PM by DebugDucky
via reddit https://ift.tt/0OdDzx1
Securecodewarrior
Psychic Signatures - what you need to know
Psychic Signature vulnerability lies in the crypto for ECDSA signatures, which protects systems for critical tasks like authentication. Hackers can bypass any signature check with this vulnerability. We will explain what it is and how to mitigate it in this…
Reverse Engineering PsExec for fun and knowledge
https://ift.tt/mYSFT9l
Submitted April 27, 2022 at 08:42PM by CyberMasterV
via reddit https://ift.tt/9B6zidH
https://ift.tt/mYSFT9l
Submitted April 27, 2022 at 08:42PM by CyberMasterV
via reddit https://ift.tt/9B6zidH
A flow-based IDS using Machine Learning in eBPF
https://ift.tt/B2EuhqU
Submitted April 27, 2022 at 10:59PM by paran0ide
via reddit https://ift.tt/stf0Tmg
https://ift.tt/B2EuhqU
Submitted April 27, 2022 at 10:59PM by paran0ide
via reddit https://ift.tt/stf0Tmg
Reddit
[deleted by user] : r/netsec
494K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to…
DEGU: userland kit that doesn't use sys_clone/sys_execve call to run
https://ift.tt/9H4OiIJ
Submitted April 28, 2022 at 02:06AM by Background-Degree-50
via reddit https://ift.tt/svRSZrY
https://ift.tt/9H4OiIJ
Submitted April 28, 2022 at 02:06AM by Background-Degree-50
via reddit https://ift.tt/svRSZrY
GitHub
GitHub - io-tl/degu-lib: stealth userland kit that doesn't use sys_clone/sys_execve call
stealth userland kit that doesn't use sys_clone/sys_execve call - GitHub - io-tl/degu-lib: stealth userland kit that doesn't use sys_clone/sys_execve call
Looking For Vulnerable Redis Servers (CVE-2022-0543)
https://ift.tt/c5ULqB9
Submitted April 28, 2022 at 02:40AM by chicksdigthelongrun
via reddit https://ift.tt/uGTWNHm
https://ift.tt/c5ULqB9
Submitted April 28, 2022 at 02:40AM by chicksdigthelongrun
via reddit https://ift.tt/uGTWNHm
AttackerKB
CVE-2022-0543 | AttackerKB
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could resul…
Commit Level Vulnerability Dataset
https://ift.tt/He7FJCB
Submitted April 28, 2022 at 10:45AM by paran0ide
via reddit https://ift.tt/N3sjh8Q
https://ift.tt/He7FJCB
Submitted April 28, 2022 at 10:45AM by paran0ide
via reddit https://ift.tt/N3sjh8Q
Quarkslab
Commit Level Vulnerability Dataset
Elevation of privilege Linux vulnerability: Nimbuspwn
https://ift.tt/TRLyn5D
Submitted April 28, 2022 at 12:01PM by 0xdea
via reddit https://ift.tt/TI89bmY
https://ift.tt/TRLyn5D
Submitted April 28, 2022 at 12:01PM by 0xdea
via reddit https://ift.tt/TI89bmY
Microsoft News
Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn
Microsoft has discovered several vulnerabilities, collectively referred to as Nimbuspwn, that could be chained together, allowing an attacker to elevate privileges to root on many Linux desktop endpoints. Leveraging Nimbuspwn as a vector for root access could…
FindFunc: An IDA plugin for advanced function matching by assembly template, constants, string/name/byte reference
https://ift.tt/zJmV9ct
Submitted April 28, 2022 at 12:23PM by feberx
via reddit https://ift.tt/8iSKp4V
https://ift.tt/zJmV9ct
Submitted April 28, 2022 at 12:23PM by feberx
via reddit https://ift.tt/8iSKp4V
GitHub
GitHub - FelixBer/FindFunc: FindFunc is an IDA Pro plugin to find code functions that contain a certain assembly or byte pattern…
FindFunc is an IDA Pro plugin to find code functions that contain a certain assembly or byte pattern, reference a certain name or string, or conform to various other constraints. - GitHub - FelixBe...
nimbuspwn detector (CVE-2022-29799 & CVE-2022-29800) - check whether local system is possibly vulnerable
https://ift.tt/KrMCyp0
Submitted April 28, 2022 at 06:13PM by SRMish3
via reddit https://ift.tt/yWIRJiS
https://ift.tt/KrMCyp0
Submitted April 28, 2022 at 06:13PM by SRMish3
via reddit https://ift.tt/yWIRJiS
GitHub
GitHub - jfrog/nimbuspwn-tools
Contribute to jfrog/nimbuspwn-tools development by creating an account on GitHub.
ExtraReplica: cross-account database vulnerability in Azure PostgreSQL
https://ift.tt/nrDjFsf
Submitted April 28, 2022 at 06:59PM by sagitz_
via reddit https://ift.tt/o64nucd
https://ift.tt/nrDjFsf
Submitted April 28, 2022 at 06:59PM by sagitz_
via reddit https://ift.tt/o64nucd
wiz.io
Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL | Wiz Blog
Wiz Research discovers a chain of critical vulnerabilities in the widely used Azure Database for PostgreSQL Flexible Server.
How to save fiddler everywhere result in SEQUENCE it captured ? I'm trying to save the raw date IN SEQUENCE it captured but unable to save in sequece it captured.
https://ift.tt/B1Gsnar
Submitted April 28, 2022 at 09:36PM by sahastra
via reddit https://ift.tt/i0dqYyk
https://ift.tt/B1Gsnar
Submitted April 28, 2022 at 09:36PM by sahastra
via reddit https://ift.tt/i0dqYyk
Telerik.com
The Ultimate Web Debugging Tool - Download Fiddler Everywhere | Telerik
Download Fiddler Everywhere, the professionally built and supported web debugging proxy tool for Windows, macOS, and Linux. Free and fully-functional trial.
How to master Google Hacking (Dorking)
https://ift.tt/61sRBU4
Submitted April 28, 2022 at 09:33PM by hisfuntie
via reddit https://ift.tt/UIEFB63
https://ift.tt/61sRBU4
Submitted April 28, 2022 at 09:33PM by hisfuntie
via reddit https://ift.tt/UIEFB63
Medium
How to master Google Hacking (Dorking)
Google hacking, sometimes, referred to as Google Dorking, is an information-gathering technique used by an attacker leveraging advanced…
Bypassing LDAP Channel Binding with StartTLS
https://ift.tt/FUA1g5S
Submitted April 28, 2022 at 09:33PM by AlmondOffSec
via reddit https://ift.tt/kLH57zN
https://ift.tt/FUA1g5S
Submitted April 28, 2022 at 09:33PM by AlmondOffSec
via reddit https://ift.tt/kLH57zN
reddit
Bypassing LDAP Channel Binding with StartTLS
Posted in r/netsec by u/AlmondOffSec • 14 points and 0 comments
Anatomy of a Zero Day - How to decrypt....a robot?
https://ift.tt/3ZcE2MO
Submitted April 28, 2022 at 10:12PM by 312sec
via reddit https://ift.tt/lG2VRje
https://ift.tt/3ZcE2MO
Submitted April 28, 2022 at 10:12PM by 312sec
via reddit https://ift.tt/lG2VRje
Dolos Group
Anatomy of a Zero Day - How to decrypt....a robot? — Dolos Group
That noscript would have sounded very weird to me a year ago but that’s exactly what happened. Let me walk you through how we were approached by a client for a code review, had to find a zero day just to get started (CVE-2022-29856), and ultimately “decrypted…
reposaur - use Rego to audit your GitHub org security posture
https://ift.tt/oOM4fxU
Submitted April 28, 2022 at 11:48PM by fproulx
via reddit https://ift.tt/RfSMA94
https://ift.tt/oOM4fxU
Submitted April 28, 2022 at 11:48PM by fproulx
via reddit https://ift.tt/RfSMA94
GitHub
GitHub - reposaur/reposaur: Open source compliance tool for development platforms.
Open source compliance tool for development platforms. - GitHub - reposaur/reposaur: Open source compliance tool for development platforms.
Colibri Loader's Unique Persistence Technique Using Get-Variable Cmdlet
https://ift.tt/hRTAMZE
Submitted April 28, 2022 at 11:10PM by sciencestudent99
via reddit https://ift.tt/wlmnZhG
https://ift.tt/hRTAMZE
Submitted April 28, 2022 at 11:10PM by sciencestudent99
via reddit https://ift.tt/wlmnZhG
FourCore
Colibri Loader's unique Persistence Technique using Get-Variable cmdlet - FourCore
Colibri Loader uses a novel method of Persistence which makes use of Get-Variable cmdlet to run its executable every time powershell is launched. Here we cover the method, why it works, and how to detect such TTPs.
Kubernetes Goat - Interactive Kubernetes Security Learning Playground 🚀
https://ift.tt/Z2IQ76o
Submitted April 29, 2022 at 12:42AM by madhuakula
via reddit https://ift.tt/r3yZC58
https://ift.tt/Z2IQ76o
Submitted April 29, 2022 at 12:42AM by madhuakula
via reddit https://ift.tt/r3yZC58
Madhuakula
Welcome to Kubernetes Goat | Kubernetes Goat
Interactive Kubernetes Security Learning Playground