Microsoft Azure Arc Logging Passwords in Plaintext
https://ift.tt/Mh1R2oe
Submitted July 19, 2022 at 07:47PM by dinobyt3s
via reddit https://ift.tt/oRq9WjO
https://ift.tt/Mh1R2oe
Submitted July 19, 2022 at 07:47PM by dinobyt3s
via reddit https://ift.tt/oRq9WjO
Medium
Logging Passwords in Plaintext in Azure Arc
Microsoft’s Azure Arc is a management platform designed to bridge multi-cloud and similarly mixed environments together in a convenient…
Building a process to evaluate security tools
https://ift.tt/SXfBs8g
Submitted July 18, 2022 at 09:03PM by LivingInSyn
via reddit https://ift.tt/tYP8fQi
https://ift.tt/SXfBs8g
Submitted July 18, 2022 at 09:03PM by LivingInSyn
via reddit https://ift.tt/tYP8fQi
DEV Community 👩💻👨💻
Evaluating Security Tools
a sample security tool testing procedure
DNS-over-HTTP/3 in Android
https://ift.tt/SQ8Us4M
Submitted July 20, 2022 at 03:12PM by SeanPesce
via reddit https://ift.tt/R90pyj1
https://ift.tt/SQ8Us4M
Submitted July 20, 2022 at 03:12PM by SeanPesce
via reddit https://ift.tt/R90pyj1
Google Online Security Blog
DNS-over-HTTP/3 in Android
Posted by Matthew Maurer and Mike Yu, Android team To help keep Android users’ DNS queries private, Android supports encrypted DNS. I...
Cloud is more fun with an SSRF
https://ift.tt/AEH39IU
Submitted July 20, 2022 at 03:00PM by Ancient_Title_1860
via reddit https://ift.tt/X8Blrbv
https://ift.tt/AEH39IU
Submitted July 20, 2022 at 03:00PM by Ancient_Title_1860
via reddit https://ift.tt/X8Blrbv
[CVE-2022-34918] A crack in the Linux firewall
https://ift.tt/V1e5W4I
Submitted July 20, 2022 at 08:39PM by gquere
via reddit https://ift.tt/GYH9Tlf
https://ift.tt/V1e5W4I
Submitted July 20, 2022 at 08:39PM by gquere
via reddit https://ift.tt/GYH9Tlf
www.randorisec.fr
[CVE-2022-34918] A crack in the Linux firewall
RandoriSec Offensive Security
Multiple Vulnerabilities in Atlassian Products
https://ift.tt/zqfAt81
Submitted July 21, 2022 at 12:22AM by sullivanmatt
via reddit https://ift.tt/nVjzuio
https://ift.tt/zqfAt81
Submitted July 21, 2022 at 12:22AM by sullivanmatt
via reddit https://ift.tt/nVjzuio
Bug Alert
Bug Alert: Multiple Vulnerabilities in Atlassian Products (CVE-2022-26136, CVE-2022-26137, CVE-2022-26138)
Multiple Vulnerabilities have been disclosed in Atlassian Products. A hardcoded credential vulnerability in Questions for Confluence, and Servlet Filter Bypass Vulnerabilities have been found in multiple Atlassian products that may enable Authentication Bypasses…
Django web applications with enabled Debug Mode, DB accounts information and API Keys of more than 3,100 applications were exposed on internet.
https://ift.tt/b8CGA6q
Submitted July 21, 2022 at 10:51AM by zwrinerlucas
via reddit https://ift.tt/EhxuiAr
https://ift.tt/b8CGA6q
Submitted July 21, 2022 at 10:51AM by zwrinerlucas
via reddit https://ift.tt/EhxuiAr
CIP Blog
API Key, a Key to Credential Leakage & Manipulation
Upon searching for Django web applications with enabled Debug Mode on Criminal IP (https://www.criminalip.io/), Database (hereinafter referred to as DB) accounts information and API Keys of more than 3,100 applications were found to be exposed on the internet.…
GitHub - TheOfficialFloW/bd-jb: The first bd-j hack.
https://ift.tt/ulWO9xS
Submitted July 21, 2022 at 11:10AM by jeandrew
via reddit https://ift.tt/1cZmOjF
https://ift.tt/ulWO9xS
Submitted July 21, 2022 at 11:10AM by jeandrew
via reddit https://ift.tt/1cZmOjF
GitHub
GitHub - TheOfficialFloW/bd-jb: The first bd-j hack.
The first bd-j hack. Contribute to TheOfficialFloW/bd-jb development by creating an account on GitHub.
ISSM teaching the new ISSO how to do vulnerability scans.
https://ift.tt/1yIGHEd
Submitted July 21, 2022 at 06:27PM by Individual_Power_489
via reddit https://ift.tt/k615MU2
https://ift.tt/1yIGHEd
Submitted July 21, 2022 at 06:27PM by Individual_Power_489
via reddit https://ift.tt/k615MU2
reddit
ISSM teaching the new ISSO how to do vulnerability scans.
Posted in r/netsec by u/Individual_Power_489 • 10 points and 1 comment
The Return of Candiru: Zero-days in the Middle East
https://ift.tt/tAk3S8f
Submitted July 21, 2022 at 06:00PM by stashing_the_smack
via reddit https://ift.tt/RrM17km
https://ift.tt/tAk3S8f
Submitted July 21, 2022 at 06:00PM by stashing_the_smack
via reddit https://ift.tt/RrM17km
Avast Threat Labs
The Return of Candiru: Zero-days in the Middle East - Avast Threat Labs
We recently discovered a zero-day vulnerability in Google Chrome (CVE-2022-2294) when it was exploited in the wild in an attempt to attack Avast users in the Middle East. The vulnerability was a memory corruption in WebRTC that was abused to achieve shellcode…
Gitlab Project Import RCE Analysis (CVE-2022-2185)
https://ift.tt/eg5TjW1
Submitted July 21, 2022 at 08:18PM by CyberMasterV
via reddit https://ift.tt/6qh2V1k
https://ift.tt/eg5TjW1
Submitted July 21, 2022 at 08:18PM by CyberMasterV
via reddit https://ift.tt/6qh2V1k
STAR Labs
Gitlab Project Import RCE Analysis (CVE-2022-2185)
At the beginning of this month, GitLab released a security patch for versions 14->15. Interestingly in the advisory, there was a mention of a post-auth RCE bug with CVSS 9.9.
The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally…
The bug exists in GitLab’s Project Imports feature, which was found by @vakzz. Incidentally…
Sh*Load exploits: SHA Hardware Offload w/o Error Checking
https://ift.tt/4Q2Jdth
Submitted July 22, 2022 at 05:28AM by Unique-Enthusiasm-54
via reddit https://ift.tt/FnCrUgK
https://ift.tt/4Q2Jdth
Submitted July 22, 2022 at 05:28AM by Unique-Enthusiasm-54
via reddit https://ift.tt/FnCrUgK
Dellfer
Sh*Load Exploits (Episode V: Return of the Error) - Dellfer
Our first post in the Firmware Developers Need To Know blog series, Episode I: The Last Error, pointed out the benefits of adopting clean error codes. And
vSMTP : an alternative to current MTAs. Fully written in Rust, vSMTP now includes SPF and open relay filters in addition to vSL, an email noscripting language that allows full traffic control.
https://ift.tt/ZTE7ei2
Submitted July 22, 2022 at 01:36PM by viridIT
via reddit https://ift.tt/DaIgXi2
https://ift.tt/ZTE7ei2
Submitted July 22, 2022 at 01:36PM by viridIT
via reddit https://ift.tt/DaIgXi2
GitHub
GitHub - viridIT/vSMTP: vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener.
vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener. - GitHub - viridIT/vSMTP: vSMTP : a next-gen mail transfer agent (MTA) written in Rust. Faster and Greener.
PART 1: How I Met Your Beacon - Overview
https://ift.tt/OepZlqs
Submitted July 22, 2022 at 01:07PM by gid0rah
via reddit https://ift.tt/f7OJV4i
https://ift.tt/OepZlqs
Submitted July 22, 2022 at 01:07PM by gid0rah
via reddit https://ift.tt/f7OJV4i
MDSec
PART 1: How I Met Your Beacon - Overview - MDSec
Introduction Its no secret that MDSec provides a commercial command-and-control framework with a focus on evasion for covert operations. With this in mind, we are continuously performing on-going R&D in...
A repository of Windows persistence mechanisms
https://ift.tt/2pCoyue
Submitted July 22, 2022 at 10:25PM by CyberMasterV
via reddit https://ift.tt/D8hwvVa
https://ift.tt/2pCoyue
Submitted July 22, 2022 at 10:25PM by CyberMasterV
via reddit https://ift.tt/D8hwvVa
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://ift.tt/srV8pLj
Submitted July 22, 2022 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/EmR6NFn
https://ift.tt/srV8pLj
Submitted July 22, 2022 at 10:17PM by SCI_Rusher
via reddit https://ift.tt/EmR6NFn
Microsoft Security Blog
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware | Microsoft Security Blog
A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021. This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name.
Confuser - New Dependency Confusion Detection Tool
https://ift.tt/nTEVfbY
Submitted July 22, 2022 at 10:55PM by nibblesec
via reddit https://ift.tt/AwRiClH
https://ift.tt/nTEVfbY
Submitted July 22, 2022 at 10:55PM by nibblesec
via reddit https://ift.tt/AwRiClH
Doyensec
Dependency Confusion · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Defeating Javanoscript Obfuscation
https://ift.tt/BvHFM67
Submitted July 23, 2022 at 12:00AM by baryoing
via reddit https://ift.tt/xKYoNrG
https://ift.tt/BvHFM67
Submitted July 23, 2022 at 12:00AM by baryoing
via reddit https://ift.tt/xKYoNrG
PerimeterX
Defeating Javanoscript Obfuscation | PerimeterX
The story of REstringer - a new open source Javanoscript deobfuscator.
Investigating a Hacked WordPress site on Linode. Step by step.
https://ift.tt/8aKyn2D
Submitted July 24, 2022 at 10:35PM by nykzhang
via reddit https://ift.tt/qp4KwF0
https://ift.tt/8aKyn2D
Submitted July 24, 2022 at 10:35PM by nykzhang
via reddit https://ift.tt/qp4KwF0
Trunc Logging
Investigating a Hacked Linode server
Investigating and recovering a compromised Linode server running WordPress and latest Ubuntu.
The End of PPLdump
https://ift.tt/cQTD9Fz
Submitted July 24, 2022 at 11:13PM by 0xdea
via reddit https://ift.tt/qjU5hIX
https://ift.tt/cQTD9Fz
Submitted July 24, 2022 at 11:13PM by 0xdea
via reddit https://ift.tt/qjU5hIX
itm4n’s blog
The End of PPLdump
A few days ago, an issue was opened for PPLdump on GitHub, stating that it no longer worked on Windows 10 21H2 Build 19044.1826. I was skeptical at first so I fired up a new VM and started investigating. Here is what I found…
Since Microsoft patched PPLDump's exploit I'm open sourcing RIPPL, a a tool based off PPLDump which enabled more offensive capabilities against PPL processes like EDRs - @last0x00
https://ift.tt/8JpLvkg
Submitted July 25, 2022 at 01:46PM by last0x00
via reddit https://ift.tt/PfnVgwY
https://ift.tt/8JpLvkg
Submitted July 25, 2022 at 01:46PM by last0x00
via reddit https://ift.tt/PfnVgwY
GitHub
GitHub - last-byte/RIPPL: RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows
RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processes on Windows - GitHub - last-byte/RIPPL: RIPPL is a tool that abuses a usermode only exploit to manipulate PPL processe...