Trends at Blackhat Asia 2022 - Kubernetes, Cloud Security and more
https://ift.tt/jLZYeWr
Submitted May 13, 2022 at 09:06PM by MiguelHzBz
via reddit https://ift.tt/C35P8sq
https://ift.tt/jLZYeWr
Submitted May 13, 2022 at 09:06PM by MiguelHzBz
via reddit https://ift.tt/C35P8sq
Sysdig
Trends at Blackhat Asia 2022 - Kubernetes, Cloud Security and more – Sysdig
Three major trends, Kubernetes security, cloud security, and supply chain attacks, keep on the rise and on everyone's radar at Blackhat.
PowerShell Scripts used to run malicious shellcode. Reverse Shell vs Bind Shell
https://ift.tt/ZBkrQRP
Submitted May 13, 2022 at 11:27PM by CyberMasterV
via reddit https://ift.tt/ozWPibR
https://ift.tt/ZBkrQRP
Submitted May 13, 2022 at 11:27PM by CyberMasterV
via reddit https://ift.tt/ozWPibR
reddit
PowerShell Scripts used to run malicious shellcode. Reverse Shell...
Posted in r/netsec by u/CyberMasterV • 59 points and 0 comments
Reverse engineering Flutter apps
https://ift.tt/JhQYo0R
Submitted May 14, 2022 at 11:29PM by lmpact_
via reddit https://ift.tt/IY36KtM
https://ift.tt/JhQYo0R
Submitted May 14, 2022 at 11:29PM by lmpact_
via reddit https://ift.tt/IY36KtM
GitHub
GitHub - Impact-I/reFlutter: Flutter Reverse Engineering Framework
Flutter Reverse Engineering Framework. Contribute to Impact-I/reFlutter development by creating an account on GitHub.
Exploiting a Use-After-Free for code execution in every version of Python 3
https://ift.tt/MAJLRDj
Submitted May 15, 2022 at 12:10AM by DOTheLOGA
via reddit https://ift.tt/pha4HZM
https://ift.tt/MAJLRDj
Submitted May 15, 2022 at 12:10AM by DOTheLOGA
via reddit https://ift.tt/pha4HZM
pwn.win
Exploiting a Use-After-Free for code execution in every version of Python 3
A while ago I was browsing the Python bug tracker, and I stumbled upon this bug - “memoryview to freed memory can cause segfault”. It was created in 2012, originally present in Python 2.7, but remains open to this day, 10 years later. This piqued my interest…
"Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains
https://ift.tt/9qF8dmJ
Submitted May 15, 2022 at 05:13AM by mandatoryprogrammer
via reddit https://ift.tt/G90qvnN
https://ift.tt/9qF8dmJ
Submitted May 15, 2022 at 05:13AM by mandatoryprogrammer
via reddit https://ift.tt/G90qvnN
The Hacker Blog
"Zero-Days" Without Incident - Compromising Angular via Expired npm Publisher Email Domains – The Hacker Blog
A Hacker's Blog of Unintended Use and Insomnia.
MITM_Intercept: A little less hackish way to intercept and modify non-HTTP protocols through Burp & others.
https://ift.tt/SrGklXy
Submitted May 15, 2022 at 10:44PM by jat0369
via reddit https://ift.tt/nyEqijI
https://ift.tt/SrGklXy
Submitted May 15, 2022 at 10:44PM by jat0369
via reddit https://ift.tt/nyEqijI
GitHub
GitHub - cyberark/MITM_Intercept: A little bit less hackish way to intercept and modify non-HTTP protocols through Burp & others.
A little bit less hackish way to intercept and modify non-HTTP protocols through Burp & others. - GitHub - cyberark/MITM_Intercept: A little bit less hackish way to intercept and modify non...
Using Stolen IAM Credentials - Hacking The Cloud
https://ift.tt/PfvRYgQ
Submitted May 16, 2022 at 03:18AM by RedTermSession
via reddit https://ift.tt/FRjzcY6
https://ift.tt/PfvRYgQ
Submitted May 16, 2022 at 03:18AM by RedTermSession
via reddit https://ift.tt/FRjzcY6
hackingthe.cloud
Using Stolen IAM Credentials - Hacking The Cloud
How to work with stolen IAM credentials and things to consider.
Technical Advisory – Blueooth Low Energy Proximity Authentication Vulnerable to Relay Attacks
https://ift.tt/UJAStsR
Submitted May 16, 2022 at 11:06AM by digicat
via reddit https://ift.tt/IX5OFyG
https://ift.tt/UJAStsR
Submitted May 16, 2022 at 11:06AM by digicat
via reddit https://ift.tt/IX5OFyG
NCC Group Research
Technical Advisory – BLE Proximity Authentication Vulnerable to Relay Attacks
NCC Group has developed a tool for conducting a new type of BLE relay attack operating at the link layer, for which added latency is within the range of normal GATT response timing variation, and which is capable of relaying encrypted link layer communications.…
GitHub - gabriel-sztejnworcel/pipe-intercept: Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools
https://ift.tt/tHe8zmG
Submitted May 16, 2022 at 04:05PM by gabrielszt
via reddit https://ift.tt/WY9t3Aw
https://ift.tt/tHe8zmG
Submitted May 16, 2022 at 04:05PM by gabrielszt
via reddit https://ift.tt/WY9t3Aw
GitHub
GitHub - gabriel-sztejnworcel/pipe-intercept: Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools
Intercept Windows Named Pipes communication using Burp or similar HTTP proxy tools - GitHub - gabriel-sztejnworcel/pipe-intercept: Intercept Windows Named Pipes communication using Burp or similar ...
SMM Callouts in HP Products
https://ift.tt/0EzDM2o
Submitted May 16, 2022 at 05:52PM by lightgrains
via reddit https://ift.tt/K7iTNvz
https://ift.tt/0EzDM2o
Submitted May 16, 2022 at 05:52PM by lightgrains
via reddit https://ift.tt/K7iTNvz
StarkeBlog
SMM Callouts in HP Products
My HP PSRT case was PSR-2021-0177 which I have been working to make public since early November 2021. The advisory was released May 10th, 2022 and did not, at least in the initial draft, credit me anywhere.
From Project File to Code Execution: Exploiting XINJE PLC Program Tool
https://ift.tt/Yl4CITv
Submitted May 16, 2022 at 07:14PM by derp6996
via reddit https://ift.tt/2iGevKh
https://ift.tt/Yl4CITv
Submitted May 16, 2022 at 07:14PM by derp6996
via reddit https://ift.tt/2iGevKh
Claroty
From Project File to Code Execution: Exploiting Vulnerabilities in XINJE PLC Program Tool
Shielder - Printing Fake Fiscal Receipts - An Italian Job p.2
https://ift.tt/DZSrPUO
Submitted May 16, 2022 at 09:47PM by smaury
via reddit https://ift.tt/RhoQkya
https://ift.tt/DZSrPUO
Submitted May 16, 2022 at 09:47PM by smaury
via reddit https://ift.tt/RhoQkya
Shielder
Shielder - Printing Fake Fiscal Receipts - An Italian Job p.2
Reverse engineering and analysis of a fiscal printer device for fun and (real) profit.
F5 BIG-IP critical vulnerability exploited by attackers to gain unauthenticated RCE
https://ift.tt/hsriCot
Submitted May 16, 2022 at 10:38PM by sciencestudent99
via reddit https://ift.tt/Cr69IRy
https://ift.tt/hsriCot
Submitted May 16, 2022 at 10:38PM by sciencestudent99
via reddit https://ift.tt/Cr69IRy
FourCore
F5 BIG-IP critical vulnerability exploited by attackers to gain unauthenticated RCE - FourCore
If you are a user of F5 BIG-IP, go patch! CVE-2022-1388 is a vulnerability in F5 BIG-IP that allows an unauthenticated attacker to run arbitrary commands, modify files, or disable services on unpatched systems.
Malcolm v6 released on GitHub, now including Suricata and more new protocol parsers
https://ift.tt/7wusW9P
Submitted May 17, 2022 at 02:36AM by mmguero
via reddit https://ift.tt/1gULACw
https://ift.tt/7wusW9P
Submitted May 17, 2022 at 02:36AM by mmguero
via reddit https://ift.tt/1gULACw
GitHub
GitHub - idaholab/Malcolm: Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture…
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts. - GitHub - idaholab/Malcolm: Malcolm is a...
EMBA v1.0 - Black Hat Singapore Edt. - Version 1.0 of the firmware security analyzer EMBA is released
https://ift.tt/mlVD6yk
Submitted May 17, 2022 at 11:44AM by _m-1-k-3_
via reddit https://ift.tt/Wyx50wf
https://ift.tt/mlVD6yk
Submitted May 17, 2022 at 11:44AM by _m-1-k-3_
via reddit https://ift.tt/Wyx50wf
GitHub
GitHub - e-m-b-a/emba: EMBA - The firmware security analyzer
EMBA - The firmware security analyzer. Contribute to e-m-b-a/emba development by creating an account on GitHub.
A dev's critique of OAUTH2, based on their experience. "OAUTH2 ... places the viability of [client developers'] products in the hands of corporate entities who are in no way accountable to anyone except their major shareholders."
https://ift.tt/mMzD6ua
Submitted May 17, 2022 at 11:13AM by flexibeast
via reddit https://ift.tt/wnlgSUc
https://ift.tt/mMzD6ua
Submitted May 17, 2022 at 11:13AM by flexibeast
via reddit https://ift.tt/wnlgSUc
Reddit
From the netsec community on Reddit: A dev's critique of OAUTH2, based on their experience. "OAUTH2 ... places the viability of…
Posted by flexibeast - 5 votes and 0 comments
Hacking Swagger-UI - from XSS to account takeovers
https://ift.tt/TvGgnH8
Submitted May 17, 2022 at 03:47PM by albinowax
via reddit https://ift.tt/VfBSJAW
https://ift.tt/TvGgnH8
Submitted May 17, 2022 at 03:47PM by albinowax
via reddit https://ift.tt/VfBSJAW
Vidoc Security Lab - blog
Hacking Swagger-UI - from XSS to account takeovers
We have reported more than 60 instances of this bug across a wide range of bug bounty programs including companies like Paypal, Atlassian, Microsoft, GitLab, Yahoo, ...
In hot pursuit of ‘cryware’: Defending hot wallets from attacks
https://ift.tt/JeoEiQz
Submitted May 17, 2022 at 09:52PM by SCI_Rusher
via reddit https://ift.tt/NoFkOvH
https://ift.tt/JeoEiQz
Submitted May 17, 2022 at 09:52PM by SCI_Rusher
via reddit https://ift.tt/NoFkOvH
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
We Love Relaying Credentials: A Technical Guide to Relaying Credentials Everywhere
https://ift.tt/neGO1rN
Submitted May 18, 2022 at 12:27AM by mgalloar
via reddit https://ift.tt/C8MnhWi
https://ift.tt/neGO1rN
Submitted May 18, 2022 at 12:27AM by mgalloar
via reddit https://ift.tt/C8MnhWi
SecureAuth
We Love Relaying Credentials: A Technical Guide to Relaying Credentials Everywhere
A guide to relaying credentials everywhere in 2022 NTLM relay is a well-known technique that has been with us for many years and never seems to go away. Almost every article about NTLM relay could start with that phrase. It could be a cliché but it’s almost…
Stealing Google Drive OAuth tokens from Dropbox
https://ift.tt/FU16xvG
Submitted May 18, 2022 at 01:48AM by staz0t
via reddit https://ift.tt/R28tPBj
https://ift.tt/FU16xvG
Submitted May 18, 2022 at 01:48AM by staz0t
via reddit https://ift.tt/R28tPBj
Stazot
Sivanesh Ashok
Blog about bug bounty and infosec research
TProxy: Wireshark dissection with manual and noscripted interception
https://ift.tt/5NPbKgZ
Submitted May 18, 2022 at 10:25AM by mexicanw
via reddit https://ift.tt/xDcfqwp
https://ift.tt/5NPbKgZ
Submitted May 18, 2022 at 10:25AM by mexicanw
via reddit https://ift.tt/xDcfqwp
Reddit
From the netsec community on Reddit: TProxy: Wireshark dissection with manual and noscripted interception
Posted by mexicanw - 21 votes and 5 comments