How to detect Brute Ratel C2 (beacons & server deployments)
https://ift.tt/RCdAKqZ
Submitted August 03, 2022 at 02:31PM by gid0rah
via reddit https://ift.tt/34PIKEC
https://ift.tt/RCdAKqZ
Submitted August 03, 2022 at 02:31PM by gid0rah
via reddit https://ift.tt/34PIKEC
MDSec
PART 3: How I Met Your Beacon - Brute Ratel - MDSec
Introduction In part three of this series, we will analyse Brute Ratel, a command and control framework developed by Dark Vortex. As the C2 is lesser known, we can see...
EMBA Firmware analyzer version 1.1.0 aka Las Vegas Edt. is out now - a lot of new features including system emulation environment, status bar and Ubuntu support
https://ift.tt/rpBMDWE
Submitted August 03, 2022 at 02:13PM by _m-1-k-3_
via reddit https://ift.tt/qrx9WcT
https://ift.tt/rpBMDWE
Submitted August 03, 2022 at 02:13PM by _m-1-k-3_
via reddit https://ift.tt/qrx9WcT
GitHub
Release EMBA v1.1.0 - Las Vegas Edt. · e-m-b-a/emba
Beside bug fixes this release introduces many new features and it was so much fun working on it. We think this release is very beautiful and we are really proud of it! You are invited to celebrate ...
Hijacking email with Cloudflare Email Routing
https://ift.tt/LeRtplj
Submitted August 03, 2022 at 09:53PM by jwizq
via reddit https://ift.tt/oS6F9qw
https://ift.tt/LeRtplj
Submitted August 03, 2022 at 09:53PM by jwizq
via reddit https://ift.tt/oS6F9qw
Albertpedersen
Hijacking email with Cloudflare Email Routing
On Tuesday, December 7th 2021 I discovered a critical vulnerability in Cloudflare’s Email Routing service. This vulnerabilty enabled anyone to modify the routing configuration of any domain using the service. A bad actor could have overwritten the destination…
The Consequences of Inadequate Identity Management in your GitHub Organization
https://ift.tt/OATIlJ3
Submitted August 03, 2022 at 11:54PM by Hefty_Knowledge_7449
via reddit https://ift.tt/vEuohqH
https://ift.tt/OATIlJ3
Submitted August 03, 2022 at 11:54PM by Hefty_Knowledge_7449
via reddit https://ift.tt/vEuohqH
Cider Security Site
The Consequences of Inadequate Identity Management in your Github Organization
Identity and Access Management has always been a major area of concern and focus for organizations, across all the different systems in the estate, including source control management systems (SCM), and specifically GitHub. Organizations spend a great deal…
geopipe: filter by server location inside your pipe chain
https://ift.tt/qhfCPtd
Submitted August 04, 2022 at 02:41AM by lukahacksstuff
via reddit https://ift.tt/B91T4Df
https://ift.tt/qhfCPtd
Submitted August 04, 2022 at 02:41AM by lukahacksstuff
via reddit https://ift.tt/B91T4Df
GitLab
lu|ka / geopipe · GitLab
A tool to take domains from stdin and output to stdout if have at least one IP address associated with the selected country.
Paranoid project checks for well known weaknesses on cryptographic artifacts such as public keys, digital signatures and general pseudorandom numbers
https://ift.tt/4uItmaH
Submitted August 04, 2022 at 05:53AM by Gallus
via reddit https://ift.tt/RSQDGBq
https://ift.tt/4uItmaH
Submitted August 04, 2022 at 05:53AM by Gallus
via reddit https://ift.tt/RSQDGBq
GitHub
GitHub - google/paranoid_crypto: Paranoid's library contains implementations of checks for well known weaknesses on cryptographic…
Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts. - google/paranoid_crypto
PersistenceSniper: Powershell noscript that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines by @last0x00
https://ift.tt/Ho9KEiC
Submitted August 04, 2022 at 12:34PM by last0x00
via reddit https://ift.tt/oLHGdPy
https://ift.tt/Ho9KEiC
Submitted August 04, 2022 at 12:34PM by last0x00
via reddit https://ift.tt/oLHGdPy
GitHub
GitHub - last-byte/PersistenceSniper: Powershell module that can be used by Blue Teams, Incident Responders and System Administrators…
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w...
Risky Business: Determining Malicious Probabilities Through ASNs
https://ift.tt/6esSPyn
Submitted August 04, 2022 at 01:06PM by sanitybit
via reddit https://ift.tt/D6lvwp1
https://ift.tt/6esSPyn
Submitted August 04, 2022 at 01:06PM by sanitybit
via reddit https://ift.tt/D6lvwp1
Akamai
Risky Business: Determining Malicious Probabilities Through ASNs
Akamai researchers have analyzed ASNs to determine some shocking stats about the state of malicious IPs and where they are from.
Building did someone clone me: a free service that notifies its users when their website is cloned and used in a phishing attack
https://ift.tt/xNAsiFU
Submitted August 04, 2022 at 02:48PM by wez32
via reddit https://ift.tt/eJLktHF
https://ift.tt/xNAsiFU
Submitted August 04, 2022 at 02:48PM by wez32
via reddit https://ift.tt/eJLktHF
forsec.nl
Building: Did someone clone me? | forsec
Last months I’ve been working on a new project called didsomeoneclone.me. Last years I’ve been analyzing many phishing websites for fun. During those analysi...
Community version released - OSS Malware risk
https://ift.tt/i8r16SB
Submitted August 04, 2022 at 06:32PM by MoTownMeatballs
via reddit https://ift.tt/A7MObD6
https://ift.tt/i8r16SB
Submitted August 04, 2022 at 06:32PM by MoTownMeatballs
via reddit https://ift.tt/A7MObD6
QNAP Poisoned XML Command Injection (Silently Patched)
https://ift.tt/CYzfwd1
Submitted August 04, 2022 at 11:06PM by chicksdigthelongrun
via reddit https://ift.tt/7BRmKNd
https://ift.tt/CYzfwd1
Submitted August 04, 2022 at 11:06PM by chicksdigthelongrun
via reddit https://ift.tt/7BRmKNd
Rapid7
QNAP Poisoned XML Command Injection (Silently Patched) | Rapid7 Blog
In researching the mystery surrounding alleged exploitation in the wild of CVE-2020-2509, we found what make be an entirely new vulnerability.
Certipy 4.0: ESC9 & ESC10, BloodHound GUI, New Authentication and Request Methods — and more!
https://ift.tt/euTaSO8
Submitted August 04, 2022 at 11:57PM by ly4k_
via reddit https://ift.tt/mlVqbYj
https://ift.tt/euTaSO8
Submitted August 04, 2022 at 11:57PM by ly4k_
via reddit https://ift.tt/mlVqbYj
Medium
Certipy 4.0: ESC9 & ESC10, BloodHound GUI, New Authentication and Request Methods — and more!
A new version of Certipy has been released along with a forked BloodHound GUI that has PKI support! In this blog post, we will look at…
Cloudflare Implements Experimental Support for Post-Quantum Cryptography
https://ift.tt/Fi0JgOG
Submitted August 05, 2022 at 03:35AM by sanitybit
via reddit https://ift.tt/l4wuvrJ
https://ift.tt/Fi0JgOG
Submitted August 05, 2022 at 03:35AM by sanitybit
via reddit https://ift.tt/l4wuvrJ
Tool that automates the tedious process of searching leaks through format string vulnerabilities. It will allow you to find stack leaks, pie leaks and canary leaks, in each case indicating the payload that provides the leak.
https://ift.tt/CtJXlcN
Submitted August 04, 2022 at 06:51PM by Diego-AltF4
via reddit https://ift.tt/JxploUv
https://ift.tt/CtJXlcN
Submitted August 04, 2022 at 06:51PM by Diego-AltF4
via reddit https://ift.tt/JxploUv
GitHub
GitHub - Diego-AltF4/GLUFS: GLUFS allows you to automate the tedious process of finding leaks using format string vulnerabilities.
GLUFS allows you to automate the tedious process of finding leaks using format string vulnerabilities. - Diego-AltF4/GLUFS
Exploring the SameSite cookie attribute for preventing CSRF!
https://ift.tt/dtAYMf6
Submitted August 05, 2022 at 03:28AM by macropng
via reddit https://ift.tt/h9ba7Hw
https://ift.tt/dtAYMf6
Submitted August 05, 2022 at 03:28AM by macropng
via reddit https://ift.tt/h9ba7Hw
simonwillison.net
Exploring the SameSite cookie attribute for preventing CSRF
In reading Yan Zhu’s excellent write-up of the JSON CSRF vulnerability she found in OkCupid one thing puzzled me: I was under the impression that browsers these days default to …
How To Implement JSON Web Token (JWT) in Java Spring Boot
https://ift.tt/MHdKo9v
Submitted August 05, 2022 at 03:08AM by sanitybit
via reddit https://ift.tt/iXcP27t
https://ift.tt/MHdKo9v
Submitted August 05, 2022 at 03:08AM by sanitybit
via reddit https://ift.tt/iXcP27t
Medium
How To Implement JSON Web Token (JWT) in Java Spring Boot
A brief guide to this helpful feature
Azure Threat Research Matrix
https://ift.tt/HaOvGLX
Submitted August 05, 2022 at 04:29AM by sanitybit
via reddit https://ift.tt/aEcZu9U
https://ift.tt/HaOvGLX
Submitted August 05, 2022 at 04:29AM by sanitybit
via reddit https://ift.tt/aEcZu9U
HyperDbg: Reinventing Hardware-Assisted Debugging
https://hyperdbg.org/
Submitted August 05, 2022 at 04:01AM by sanitybit
via reddit https://ift.tt/zpFNMq9
https://hyperdbg.org/
Submitted August 05, 2022 at 04:01AM by sanitybit
via reddit https://ift.tt/zpFNMq9
reddit
HyperDbg: Reinventing Hardware-Assisted Debugging
Posted in r/netsec by u/sanitybit • 3 points and 1 comment
Sharpening Your Tools: Updating bulk_extractor for the 2020s
https://ift.tt/E2hKBVj
Submitted August 05, 2022 at 03:56AM by sanitybit
via reddit https://ift.tt/GIz3Wfe
https://ift.tt/E2hKBVj
Submitted August 05, 2022 at 03:56AM by sanitybit
via reddit https://ift.tt/GIz3Wfe
Elastic Open Sources Their Endpoint Security Protection YARA Ruleset
https://ift.tt/WdhB43m
Submitted August 05, 2022 at 04:53AM by sanitybit
via reddit https://ift.tt/RzWf0AL
https://ift.tt/WdhB43m
Submitted August 05, 2022 at 04:53AM by sanitybit
via reddit https://ift.tt/RzWf0AL
Elastic Blog
Continued leadership in open and transparent security
Elastic Security has long had open source roots. Learn how we're continuing to build on that foundation today by opening a new public repo, protection-artifacts.
PentesterLab - Bootcamp: Everything you need to get started in infosec
https://pentesterlab.com/bootcamp
Submitted August 05, 2022 at 10:24AM by Gallus
via reddit https://www.reddit.com/r/netsec/comments/wgmcsr/pentesterlab_bootcamp_everything_you_need_to_get/?utm_source=ifttt
https://pentesterlab.com/bootcamp
Submitted August 05, 2022 at 10:24AM by Gallus
via reddit https://www.reddit.com/r/netsec/comments/wgmcsr/pentesterlab_bootcamp_everything_you_need_to_get/?utm_source=ifttt
reddit
PentesterLab - Bootcamp: Everything you need to get started in infosec
Posted in r/netsec by u/Gallus • 0 points and 0 comments