Rolling PWN Attack Affecting Honda Vehicles
https://ift.tt/kber7JT
Submitted July 13, 2022 at 10:52AM by 0xdea
via reddit https://ift.tt/Q0twJNg
https://ift.tt/kber7JT
Submitted July 13, 2022 at 10:52AM by 0xdea
via reddit https://ift.tt/Q0twJNg
CVE-2022-32223 Discovery: DLL Hijacking via npm CLI
https://ift.tt/3LQSwIs
Submitted July 13, 2022 at 12:36PM by mkatch
via reddit https://ift.tt/khUp1IA
https://ift.tt/3LQSwIs
Submitted July 13, 2022 at 12:36PM by mkatch
via reddit https://ift.tt/khUp1IA
Aquasec
CVE-2022-32223 Discovery: DLL Hijacking via npm CLI
Team Nautilus has recently discovered a vulnerability in Node.js that can lead to DLL hijacking on Windows via npm CLI if OpenSSL is installed on the host
Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP ($6,000 Bug Bounty)
https://ift.tt/rbAo5f0
Submitted July 13, 2022 at 12:02PM by numanturle
via reddit https://ift.tt/084Vqas
https://ift.tt/rbAo5f0
Submitted July 13, 2022 at 12:02PM by numanturle
via reddit https://ift.tt/084Vqas
Medium
Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP
During my early stages of employment at Gais Cyber Security in 2021, my manager had reached out to me over the phone and said with…
Introducing Pretender: Your New Sidekick for Relaying Attacks
https://ift.tt/Q23k0ZU
Submitted July 13, 2022 at 05:27PM by RedTeamPentesting
via reddit https://ift.tt/ezdLO0t
https://ift.tt/Q23k0ZU
Submitted July 13, 2022 at 05:27PM by RedTeamPentesting
via reddit https://ift.tt/ezdLO0t
RedTeam Pentesting - Blog
Introducing Pretender - Your New Sidekick for Relaying Attacks
We’ve just released another open-source tool: pretender, a cross-platform tool to obtain a machine-in-the-middle position inside Windows networks in the spirit of Responder and mitm6. It implements local name resolution spoofing using the mDNS, …
From Prototype Pollution to Remote Code Execution in Blitz.js
https://ift.tt/LS3ANcu
Submitted July 13, 2022 at 07:41PM by SonarPaul
via reddit https://ift.tt/0dTqgtl
https://ift.tt/LS3ANcu
Submitted July 13, 2022 at 07:41PM by SonarPaul
via reddit https://ift.tt/0dTqgtl
Sonarsource
Remote Code Execution via Prototype Pollution in Blitz.js
We recently discovered a Prototype Pollution vulnerability in Blitz.js leading to Remote Code Execution. Learn about this bug class and how to avoid it in your code!
Affinis - Subdomain Discovery Through RNN (Recurrent Neural Network)
https://ift.tt/QJVRmDI
Submitted July 13, 2022 at 07:24PM by jibblz
via reddit https://ift.tt/M1g2BUW
https://ift.tt/QJVRmDI
Submitted July 13, 2022 at 07:24PM by jibblz
via reddit https://ift.tt/M1g2BUW
The Long Tail of Log4Shell Exploitation
https://ift.tt/UuJZhkD
Submitted July 13, 2022 at 07:05PM by scopedsecurity
via reddit https://ift.tt/TIAUYEe
https://ift.tt/UuJZhkD
Submitted July 13, 2022 at 07:05PM by scopedsecurity
via reddit https://ift.tt/TIAUYEe
Horizon3.ai
The Long Tail of Log4Shell Exploitation
It's been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.
How Windows Processes Work - Creation, APIs, Data Structures (Part 1)
https://ift.tt/YmgLbN8
Submitted July 13, 2022 at 10:10PM by sciencestudent99
via reddit https://ift.tt/4YhnErx
https://ift.tt/YmgLbN8
Submitted July 13, 2022 at 10:10PM by sciencestudent99
via reddit https://ift.tt/4YhnErx
FourCore
Genesis - The Birth of a Windows Process (Part 1) - FourCore
What happens when you run an executable on your Windows machine? This blog provides a brief overview and the flow for creating a Windows Process, the APIs and structures involved, and the Process Internals.
Attacking Active Directory: 0 to 0.9
https://ift.tt/1uXPGeN
Submitted July 14, 2022 at 12:12AM by CyberMasterV
via reddit https://ift.tt/v9XW1zR
https://ift.tt/1uXPGeN
Submitted July 14, 2022 at 12:12AM by CyberMasterV
via reddit https://ift.tt/v9XW1zR
CVE-2022-29885 - Apache Tomcat Cluster Service DoS
https://ift.tt/GnabYki
Submitted July 14, 2022 at 01:33AM by voidz0r
via reddit https://ift.tt/b1ER5aZ
https://ift.tt/GnabYki
Submitted July 14, 2022 at 01:33AM by voidz0r
via reddit https://ift.tt/b1ER5aZ
Voidzone
CVE-2022-29885 - Apache Tomcat Cluster Service DoS
An analysis of a Denial Of Service vulnerability on the Apache Tomcat Cluster Service listener.
Dealing with Failure: Failure Escalation Policy in CLR Hosts
https://ift.tt/q5WwQ3s
Submitted July 14, 2022 at 01:13AM by jeandrew
via reddit https://ift.tt/VBtwMmg
https://ift.tt/q5WwQ3s
Submitted July 14, 2022 at 01:13AM by jeandrew
via reddit https://ift.tt/VBtwMmg
Medium
Dealing with Failure: Failure Escalation Policy in CLR Hosts
Offensive tooling built upon the .NET framework and its runtime environment, the Common Language Runtime (CLR), is an important part of…
Introducing Decompiler Explorer (🐶⚡️)
https://ift.tt/edNoWkj
Submitted July 14, 2022 at 03:28AM by Psifertex
via reddit https://ift.tt/7bcQAld
https://ift.tt/edNoWkj
Submitted July 14, 2022 at 03:28AM by Psifertex
via reddit https://ift.tt/7bcQAld
Binary Ninja
Binary Ninja - Introducing Decompiler Explorer
Binary Ninja is a modern reverse engineering platform with a noscriptable and extensible decompiler.
This Salesforce Tableau Server XSS vulnerability will not get a CVE attributed. Here is the PoC and the fixed versions.
https://ift.tt/zGUqmpH
Submitted July 13, 2022 at 09:22PM by obilodeau
via reddit https://ift.tt/4BRrS8O
https://ift.tt/zGUqmpH
Submitted July 13, 2022 at 09:22PM by obilodeau
via reddit https://ift.tt/4BRrS8O
GoSecure
Tableau Server Leaks Sensitive Information From Reflected XSS - GoSecure
Penetration testing identifies Tableau Server was vulnerable to reflected XSS which could lead to exposure of sensitive data.
Researching access tokens for fun and knowledge
https://ift.tt/Cl4Tzhn
Submitted July 14, 2022 at 04:15PM by One-Assistance-8552
via reddit https://ift.tt/qxgfnRJ
https://ift.tt/Cl4Tzhn
Submitted July 14, 2022 at 04:15PM by One-Assistance-8552
via reddit https://ift.tt/qxgfnRJ
Huntandhackett
Researching access tokens for fun and knowledge
In this blog we dive into compound identities, Azure Key Vault, JWT tokens and bound identities. For fun and to understand their inner workings.
BGGP3: Crash on the Cob
https://ift.tt/yV2IAlP
Submitted July 14, 2022 at 08:36PM by netsecfriends
via reddit https://ift.tt/Jm5PkTD
https://ift.tt/yV2IAlP
Submitted July 14, 2022 at 08:36PM by netsecfriends
via reddit https://ift.tt/Jm5PkTD
remyhax.xyz
BGGP3: Crash on the Cob
For this years Binary Golf Grand Prix I started off by learning to fuzz properly, use a debugger properly, and various tooling. The objective was originally to hit all of the bonus points:
+1024 pts, if you submit a writeup about your process and details…
+1024 pts, if you submit a writeup about your process and details…
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
https://ift.tt/TSJPy54
Submitted July 14, 2022 at 08:34PM by albinowax
via reddit https://ift.tt/dihQfJZ
https://ift.tt/TSJPy54
Submitted July 14, 2022 at 08:34PM by albinowax
via reddit https://ift.tt/dihQfJZ
PT SWARM
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
We discovered an application with "new $a($b)" and no user-defined classes. We turned it to RCE.
CVE-2022-29593
https://ift.tt/OYv1ncg
Submitted July 15, 2022 at 09:30AM by 9lyph
via reddit https://ift.tt/bJAdhCf
https://ift.tt/OYv1ncg
Submitted July 15, 2022 at 09:30AM by 9lyph
via reddit https://ift.tt/bJAdhCf
GitHub
GitHub - 9lyph/CVE-2022-29593
Contribute to 9lyph/CVE-2022-29593 development by creating an account on GitHub.
IDA Plugin to reconstruct .proto files used in the analyzed binary
https://ift.tt/63ujKXB
Submitted July 15, 2022 at 01:02PM by Martypx00
via reddit https://ift.tt/UxrhDdl
https://ift.tt/63ujKXB
Submitted July 15, 2022 at 01:02PM by Martypx00
via reddit https://ift.tt/UxrhDdl
GitHub
GitHub - Accenture/protobuf-finder: IDA Pro plugin for reconstructing original .proto files from binary.
IDA Pro plugin for reconstructing original .proto files from binary. - GitHub - Accenture/protobuf-finder: IDA Pro plugin for reconstructing original .proto files from binary.
Mantis - The most powerful botnet
https://ift.tt/T8GnaBF
Submitted July 15, 2022 at 06:45PM by MiguelHzBz
via reddit https://ift.tt/P02Od7W
https://ift.tt/T8GnaBF
Submitted July 15, 2022 at 06:45PM by MiguelHzBz
via reddit https://ift.tt/P02Od7W
How Windows Processes Work - CreateProcess Workflow (Part 2)
https://ift.tt/alR9jeQ
Submitted July 16, 2022 at 10:49PM by sciencestudent99
via reddit https://ift.tt/fXCzL0y
https://ift.tt/alR9jeQ
Submitted July 16, 2022 at 10:49PM by sciencestudent99
via reddit https://ift.tt/fXCzL0y
FourCore
Genesis - The Birth of a Windows Process (Part 2) - FourCore
What happens when you run an executable on your Windows machine? In this second and final part of the series, we will go through the exact flow CreateProcess carries out to launch a process on Windows.
Build your first LLVM Obfuscator
https://ift.tt/zoBuEWT
Submitted July 17, 2022 at 03:59PM by CyberMasterV
via reddit https://ift.tt/a8Ev3Hj
https://ift.tt/zoBuEWT
Submitted July 17, 2022 at 03:59PM by CyberMasterV
via reddit https://ift.tt/a8Ev3Hj
Medium
Build your first LLVM Obfuscator
Welcome to a tutorial on building your first LLVM based obfuscator. In this post we will list the advantages of using LLVM tools, briefly…