chip-red-pill/MicrocodeDecryptor - understand how Intel mitigated spectre vulnerability, explore the implementation of Intel TXT, SGX,VT-x technologies
https://ift.tt/UuPEkdr
Submitted July 19, 2022 at 07:13AM by Gallus
via reddit https://ift.tt/ve0IupO
https://ift.tt/UuPEkdr
Submitted July 19, 2022 at 07:13AM by Gallus
via reddit https://ift.tt/ve0IupO
GitHub
GitHub - chip-red-pill/MicrocodeDecryptor
Contribute to chip-red-pill/MicrocodeDecryptor development by creating an account on GitHub.
EJS, Server side template injection RCE (CVE-2022-29078)
https://ift.tt/2EmBV0e
Submitted July 19, 2022 at 07:10AM by Gallus
via reddit https://ift.tt/V5sYODi
https://ift.tt/2EmBV0e
Submitted July 19, 2022 at 07:10AM by Gallus
via reddit https://ift.tt/V5sYODi
Eslam Salem blog
EJS, Server side template injection RCE (CVE-2022-29078) - writeup
Note: The objective of this research or any similar researches is to improve the nodejs ecosystem security level.
Recently i was working on a related project using one of the most popular Nodejs templating engines Embedded JavaScript templates - EJS
In my…
Recently i was working on a related project using one of the most popular Nodejs templating engines Embedded JavaScript templates - EJS
In my…
The Workings of Whatsapp's Backups (and why you should enable End-to-End Encrypted Backups)
https://ift.tt/obie6c7
Submitted July 19, 2022 at 05:45PM by IceCereal
via reddit https://ift.tt/92kYKB1
https://ift.tt/obie6c7
Submitted July 19, 2022 at 05:45PM by IceCereal
via reddit https://ift.tt/92kYKB1
sudneela.github.io
The Workings of Whatsapp's Backups (and why you should enable End-to-End Encrypted Backups)
About This Blog Post This blog post is a technical report of a presentation that I presented on June 10, 2022 for the second task of my Mobile Security course. I decided to investigate how WhatsApp backs up messages to the cloud with the “end-to-end encrypted…
Writeup for Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass
https://ift.tt/WE2Hw5k
Submitted July 19, 2022 at 10:21PM by xnyhps
via reddit https://ift.tt/0GOkSlm
https://ift.tt/WE2Hw5k
Submitted July 19, 2022 at 10:21PM by xnyhps
via reddit https://ift.tt/0GOkSlm
sector7.computest.nl
Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass
This write-up is part 1 of a series of write-ups about the 5 vulnerabilities we demonstrated last April at Pwn2Own Miami. This is the write-up for the Trusted Application Check Bypass in the OPC Foundation’s OPC UA .NET Standard.
Session On Android – An App Wrapped in Signal
https://ift.tt/4XRJoSz
Submitted July 20, 2022 at 10:38AM by jeandrew
via reddit https://ift.tt/vBonAT8
https://ift.tt/4XRJoSz
Submitted July 20, 2022 at 10:38AM by jeandrew
via reddit https://ift.tt/vBonAT8
The Binary Hick
Session On Android – An App Wrapped in Signal
NOTE: parts of this article describe steps by which the order of encryption methods are reversed to render encrypted data in clear-text. This was done in order to investigate the app being discusse…
Microsoft Azure Arc Logging Passwords in Plaintext
https://ift.tt/Mh1R2oe
Submitted July 19, 2022 at 07:47PM by dinobyt3s
via reddit https://ift.tt/oRq9WjO
https://ift.tt/Mh1R2oe
Submitted July 19, 2022 at 07:47PM by dinobyt3s
via reddit https://ift.tt/oRq9WjO
Medium
Logging Passwords in Plaintext in Azure Arc
Microsoft’s Azure Arc is a management platform designed to bridge multi-cloud and similarly mixed environments together in a convenient…
Building a process to evaluate security tools
https://ift.tt/SXfBs8g
Submitted July 18, 2022 at 09:03PM by LivingInSyn
via reddit https://ift.tt/tYP8fQi
https://ift.tt/SXfBs8g
Submitted July 18, 2022 at 09:03PM by LivingInSyn
via reddit https://ift.tt/tYP8fQi
DEV Community 👩💻👨💻
Evaluating Security Tools
a sample security tool testing procedure
DNS-over-HTTP/3 in Android
https://ift.tt/SQ8Us4M
Submitted July 20, 2022 at 03:12PM by SeanPesce
via reddit https://ift.tt/R90pyj1
https://ift.tt/SQ8Us4M
Submitted July 20, 2022 at 03:12PM by SeanPesce
via reddit https://ift.tt/R90pyj1
Google Online Security Blog
DNS-over-HTTP/3 in Android
Posted by Matthew Maurer and Mike Yu, Android team To help keep Android users’ DNS queries private, Android supports encrypted DNS. I...
Cloud is more fun with an SSRF
https://ift.tt/AEH39IU
Submitted July 20, 2022 at 03:00PM by Ancient_Title_1860
via reddit https://ift.tt/X8Blrbv
https://ift.tt/AEH39IU
Submitted July 20, 2022 at 03:00PM by Ancient_Title_1860
via reddit https://ift.tt/X8Blrbv
[CVE-2022-34918] A crack in the Linux firewall
https://ift.tt/V1e5W4I
Submitted July 20, 2022 at 08:39PM by gquere
via reddit https://ift.tt/GYH9Tlf
https://ift.tt/V1e5W4I
Submitted July 20, 2022 at 08:39PM by gquere
via reddit https://ift.tt/GYH9Tlf
www.randorisec.fr
[CVE-2022-34918] A crack in the Linux firewall
RandoriSec Offensive Security
Multiple Vulnerabilities in Atlassian Products
https://ift.tt/zqfAt81
Submitted July 21, 2022 at 12:22AM by sullivanmatt
via reddit https://ift.tt/nVjzuio
https://ift.tt/zqfAt81
Submitted July 21, 2022 at 12:22AM by sullivanmatt
via reddit https://ift.tt/nVjzuio
Bug Alert
Bug Alert: Multiple Vulnerabilities in Atlassian Products (CVE-2022-26136, CVE-2022-26137, CVE-2022-26138)
Multiple Vulnerabilities have been disclosed in Atlassian Products. A hardcoded credential vulnerability in Questions for Confluence, and Servlet Filter Bypass Vulnerabilities have been found in multiple Atlassian products that may enable Authentication Bypasses…
Django web applications with enabled Debug Mode, DB accounts information and API Keys of more than 3,100 applications were exposed on internet.
https://ift.tt/b8CGA6q
Submitted July 21, 2022 at 10:51AM by zwrinerlucas
via reddit https://ift.tt/EhxuiAr
https://ift.tt/b8CGA6q
Submitted July 21, 2022 at 10:51AM by zwrinerlucas
via reddit https://ift.tt/EhxuiAr
CIP Blog
API Key, a Key to Credential Leakage & Manipulation
Upon searching for Django web applications with enabled Debug Mode on Criminal IP (https://www.criminalip.io/), Database (hereinafter referred to as DB) accounts information and API Keys of more than 3,100 applications were found to be exposed on the internet.…
GitHub - TheOfficialFloW/bd-jb: The first bd-j hack.
https://ift.tt/ulWO9xS
Submitted July 21, 2022 at 11:10AM by jeandrew
via reddit https://ift.tt/1cZmOjF
https://ift.tt/ulWO9xS
Submitted July 21, 2022 at 11:10AM by jeandrew
via reddit https://ift.tt/1cZmOjF
GitHub
GitHub - TheOfficialFloW/bd-jb: The first bd-j hack.
The first bd-j hack. Contribute to TheOfficialFloW/bd-jb development by creating an account on GitHub.
ISSM teaching the new ISSO how to do vulnerability scans.
https://ift.tt/1yIGHEd
Submitted July 21, 2022 at 06:27PM by Individual_Power_489
via reddit https://ift.tt/k615MU2
https://ift.tt/1yIGHEd
Submitted July 21, 2022 at 06:27PM by Individual_Power_489
via reddit https://ift.tt/k615MU2
reddit
ISSM teaching the new ISSO how to do vulnerability scans.
Posted in r/netsec by u/Individual_Power_489 • 10 points and 1 comment
The Return of Candiru: Zero-days in the Middle East
https://ift.tt/tAk3S8f
Submitted July 21, 2022 at 06:00PM by stashing_the_smack
via reddit https://ift.tt/RrM17km
https://ift.tt/tAk3S8f
Submitted July 21, 2022 at 06:00PM by stashing_the_smack
via reddit https://ift.tt/RrM17km
Avast Threat Labs
The Return of Candiru: Zero-days in the Middle East - Avast Threat Labs
We recently discovered a zero-day vulnerability in Google Chrome (CVE-2022-2294) when it was exploited in the wild in an attempt to attack Avast users in the Middle East. The vulnerability was a memory corruption in WebRTC that was abused to achieve shellcode…
Gitlab Project Import RCE Analysis (CVE-2022-2185)
https://ift.tt/eg5TjW1
Submitted July 21, 2022 at 08:18PM by CyberMasterV
via reddit https://ift.tt/6qh2V1k
https://ift.tt/eg5TjW1
Submitted July 21, 2022 at 08:18PM by CyberMasterV
via reddit https://ift.tt/6qh2V1k
STAR Labs
Gitlab Project Import RCE Analysis (CVE-2022-2185)
At the beginning of this month, GitLab released a security patch for versions 14->15. Interestingly in the advisory, there was a mention of a post-auth RCE bug with CVSS 9.9.
The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally…
The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally…
Sh*Load exploits: SHA Hardware Offload w/o Error Checking
https://ift.tt/4Q2Jdth
Submitted July 22, 2022 at 05:28AM by Unique-Enthusiasm-54
via reddit https://ift.tt/FnCrUgK
https://ift.tt/4Q2Jdth
Submitted July 22, 2022 at 05:28AM by Unique-Enthusiasm-54
via reddit https://ift.tt/FnCrUgK
Dellfer
Sh*Load Exploits (Episode V: Return of the Error) - Dellfer
Our first post in the Firmware Developers Need To Know blog series, Episode I: The Last Error, pointed out the benefits of adopting clean error codes. And
vSMTP : an alternative to current MTAs. Fully written in Rust, vSMTP now includes SPF and open relay filters in addition to vSL, an email noscripting language that allows full traffic control.
https://ift.tt/ZTE7ei2
Submitted July 22, 2022 at 01:36PM by viridIT
via reddit https://ift.tt/DaIgXi2
https://ift.tt/ZTE7ei2
Submitted July 22, 2022 at 01:36PM by viridIT
via reddit https://ift.tt/DaIgXi2
GitHub
GitHub - viridIT/vSMTP: vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener.
vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener. - GitHub - viridIT/vSMTP: vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener.
PART 1: How I Met Your Beacon - Overview
https://ift.tt/OepZlqs
Submitted July 22, 2022 at 01:07PM by gid0rah
via reddit https://ift.tt/f7OJV4i
https://ift.tt/OepZlqs
Submitted July 22, 2022 at 01:07PM by gid0rah
via reddit https://ift.tt/f7OJV4i
MDSec
PART 1: How I Met Your Beacon - Overview - MDSec
Introduction Its no secret that MDSec provides a commercial command-and-control framework with a focus on evasion for covert operations. With this in mind, we are continuously performing on-going R&D in...
A repository of Windows persistence mechanisms
https://ift.tt/2pCoyue
Submitted July 22, 2022 at 10:25PM by CyberMasterV
via reddit https://ift.tt/D8hwvVa
https://ift.tt/2pCoyue
Submitted July 22, 2022 at 10:25PM by CyberMasterV
via reddit https://ift.tt/D8hwvVa
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://ift.tt/srV8pLj
Submitted July 22, 2022 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/EmR6NFn
https://ift.tt/srV8pLj
Submitted July 22, 2022 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/EmR6NFn
Microsoft Security Blog
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware | Microsoft Security Blog
A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021. This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name.