wtfis - A commandline tool that gathers information about a domain or FQDN using various OSINT services and displays them formatted for human consumption.
https://ift.tt/Bh5Ga7P
Submitted August 15, 2022 at 04:49AM by sanitybit
via reddit https://ift.tt/4cL0N9m
https://ift.tt/Bh5Ga7P
Submitted August 15, 2022 at 04:49AM by sanitybit
via reddit https://ift.tt/4cL0N9m
GitHub
GitHub - pirxthepilot/wtfis: Passive hostname, domain and IP lookup tool for non-robots
Passive hostname, domain and IP lookup tool for non-robots - GitHub - pirxthepilot/wtfis: Passive hostname, domain and IP lookup tool for non-robots
From Oscilloscope to Wireshark
https://ift.tt/NCSPFOV
Submitted August 15, 2022 at 04:41AM by sanitybit
via reddit https://ift.tt/GZIJh96
https://ift.tt/NCSPFOV
Submitted August 15, 2022 at 04:41AM by sanitybit
via reddit https://ift.tt/GZIJh96
Hacking Zyxel IP cameras to gain a root shell
https://ift.tt/vAkqBoY
Submitted August 15, 2022 at 04:09AM by hydrogen18
via reddit https://ift.tt/eO901uZ
https://ift.tt/vAkqBoY
Submitted August 15, 2022 at 04:09AM by hydrogen18
via reddit https://ift.tt/eO901uZ
Hydrogen18
Hacking Zyxel IP cameras to gain a root shell
Identifying software vulnerabilities in Zyxel IP cameras to remotely gain a root shell
Evade Windows Defender Mimikatz detection by patching the amsi.dll
https://ift.tt/iMHPTZf
Submitted August 15, 2022 at 05:29AM by sanitybit
via reddit https://ift.tt/hitwRPA
https://ift.tt/iMHPTZf
Submitted August 15, 2022 at 05:29AM by sanitybit
via reddit https://ift.tt/hitwRPA
Medium
Evade Windows Defender Mimikatz detection by patching the amsi.dll
Summary In the article, I will show you how you can use Empire and execute the Mimikatz module to dump the logged in user password hashes.
DC30 Mainframe Buffer Overflow workshop. This docker container has everything you need to learn how to do MVS buffer overflows.
https://ift.tt/nMAcLJb
Submitted August 15, 2022 at 05:28AM by sanitybit
via reddit https://ift.tt/rcobaTp
https://ift.tt/nMAcLJb
Submitted August 15, 2022 at 05:28AM by sanitybit
via reddit https://ift.tt/rcobaTp
GitHub
GitHub - mainframed/DC30_Workshop: DEFCON 30 Mainframe buffer overlow workshop container
DEFCON 30 Mainframe buffer overlow workshop container - GitHub - mainframed/DC30_Workshop: DEFCON 30 Mainframe buffer overlow workshop container
Process injection: breaking all macOS security layers with a single vulnerability
https://ift.tt/WyMaqi9
Submitted August 15, 2022 at 05:25AM by sanitybit
via reddit https://ift.tt/dvhu81q
https://ift.tt/WyMaqi9
Submitted August 15, 2022 at 05:25AM by sanitybit
via reddit https://ift.tt/dvhu81q
sector7.computest.nl
Process injection: breaking all macOS security layers with a single vulnerability
If you have created a new macOS app with Xcode 13.2, you may noticed this new method in the template:
- (BOOL)applicationSupportsSecureRestorableState:(NSApplication *)app { return YES; } This was added to the Xcode template to address a process injection…
- (BOOL)applicationSupportsSecureRestorableState:(NSApplication *)app { return YES; } This was added to the Xcode template to address a process injection…
NthLink VPN found to be regular shadowsocks using same pre-shared keys for all users
https://ift.tt/XEbOGSQ
Submitted August 15, 2022 at 06:15AM by yarmak
via reddit https://ift.tt/VRZcitI
https://ift.tt/XEbOGSQ
Submitted August 15, 2022 at 06:15AM by yarmak
via reddit https://ift.tt/VRZcitI
GitHub
GitHub - Snawoot/nth-dump: nthLink API client
nthLink API client. Contribute to Snawoot/nth-dump development by creating an account on GitHub.
STrace: MIT Licensed Windows Reimplementation of DTrace
https://ift.tt/pIQ5SNu
Submitted August 15, 2022 at 07:29AM by sanitybit
via reddit https://ift.tt/9JekhH0
https://ift.tt/pIQ5SNu
Submitted August 15, 2022 at 07:29AM by sanitybit
via reddit https://ift.tt/9JekhH0
GitHub
GitHub - mandiant/STrace: A DTrace on Windows Reimplementation
A DTrace on Windows Reimplementation. Contribute to mandiant/STrace development by creating an account on GitHub.
HijackLibs: an open-source, community-driven project tracking DLL Hijacking opportunities in in Windows
https://hijacklibs.net/
Submitted August 15, 2022 at 07:51AM by sanitybit
via reddit https://ift.tt/l1jzFH7
https://hijacklibs.net/
Submitted August 15, 2022 at 07:51AM by sanitybit
via reddit https://ift.tt/l1jzFH7
reddit
HijackLibs: an open-source, community-driven project tracking DLL...
Posted in r/netsec by u/sanitybit • 3 points and 0 comments
Attacking Google's Titan M Security Key with Only One Byte
https://ift.tt/zGFHPvU
Submitted August 15, 2022 at 10:16AM by sanitybit
via reddit https://ift.tt/5fG4vdk
https://ift.tt/zGFHPvU
Submitted August 15, 2022 at 10:16AM by sanitybit
via reddit https://ift.tt/5fG4vdk
Quarkslab
Attacking Titan M with Only One Byte
EvilPLC Attack: Using a PLC to Gain Code Execution on Engineering Workstation
https://ift.tt/WkNh9AI
Submitted August 15, 2022 at 05:54PM by derp6996
via reddit https://ift.tt/niW1YOA
https://ift.tt/WkNh9AI
Submitted August 15, 2022 at 05:54PM by derp6996
via reddit https://ift.tt/niW1YOA
Claroty
Evil PLC Attack: Hacking PLCs to Attack Engineering Workstations
The Evil PLC Attack uses weaponized PLCs to compromise engineering workstations and move laterally on the OT network to infect other PLCs and systems.
Why Action Bias Is Damaging Your Security Response
https://ift.tt/3uXr4DE
Submitted August 15, 2022 at 09:23PM by mesok8
via reddit https://ift.tt/qwat8LJ
https://ift.tt/3uXr4DE
Submitted August 15, 2022 at 09:23PM by mesok8
via reddit https://ift.tt/qwat8LJ
Information Security Newspaper | Hacking News
Why Action Bias Is Damaging Your Cyber Security Response (And How To Fix it)
Why Action Bias Is Damaging Your Cyber Security Response (And How To Fix it) - Technology Talk - Information Security Newspaper | Hacking News
Tracking Internet facing Industrial Control System devices
https://ift.tt/DwQb0TU
Submitted August 15, 2022 at 10:53PM by Mysterii8
via reddit https://ift.tt/S6Lz359
https://ift.tt/DwQb0TU
Submitted August 15, 2022 at 10:53PM by Mysterii8
via reddit https://ift.tt/S6Lz359
Offensive OSINT
Offensive OSINT s04e03 - Tracking Internet facing Industrial Control System devices with Kamerka Lite
Today I want to present additional big feature to my long time project - Kamerka. From now on you can access statistics about Internet exposed Industrial Control System and Internet of Things devices via comfortable GUI
Kamerka Lite
Kamerka Lite by Offensive…
Kamerka Lite
Kamerka Lite by Offensive…
Process Behaviour Anomaly Detection Using eBPF and Unsupervised-Learning Autoencoders
https://ift.tt/GHOo8yM
Submitted August 16, 2022 at 04:52AM by sanitybit
via reddit https://ift.tt/LRdClO1
https://ift.tt/GHOo8yM
Submitted August 16, 2022 at 04:52AM by sanitybit
via reddit https://ift.tt/LRdClO1
evilsocket
Process Behaviour Anomaly Detection Using eBPF and Unsupervised-Learning Autoencoders
Hello everybody, I hope you’ve been enjoying this summer after two years of Covid and lockdowns :D In this post I’m going to describe how to use eBPF syscall tracing in a creative way in order to dete
CVE-2022-31793: Arris Routers and Muhttpd
https://ift.tt/CE2Q3ok
Submitted August 16, 2022 at 08:54AM by Glad_Living3908
via reddit https://ift.tt/RuOhYkg
https://ift.tt/CE2Q3ok
Submitted August 16, 2022 at 08:54AM by Glad_Living3908
via reddit https://ift.tt/RuOhYkg
Censys
CVE-2022-31793: Arris Routers and Muhttpd
SOVA malware is back and is evolving rapidly
https://ift.tt/bp1dNxT
Submitted August 16, 2022 at 01:37PM by Frank538
via reddit https://ift.tt/P7tzim4
https://ift.tt/bp1dNxT
Submitted August 16, 2022 at 01:37PM by Frank538
via reddit https://ift.tt/P7tzim4
Cleafy
SOVA malware is back and is evolving rapidly | Cleafy Labs
SOVA, a new Android Banking Trojan, is spreading across Europe. Already appeared in different versions, this malware is now evolving, and it is targeting more than 200 mobile applications, ranging from banking apps to crypto exchanges/wallets. Here's the…
A Deep Dive Into Black Basta Ransomware
https://ift.tt/0lPcTdG
Submitted August 16, 2022 at 07:30PM by CyberMasterV
via reddit https://ift.tt/1yunMTg
https://ift.tt/0lPcTdG
Submitted August 16, 2022 at 07:30PM by CyberMasterV
via reddit https://ift.tt/1yunMTg
SecurityScorecard
A Deep Dive Into Black Basta Ransomware
AEPIC Leak: Intel SGX PoC/exploit
https://ift.tt/XfACbiS
Submitted August 16, 2022 at 07:07PM by hardenedvault
via reddit https://ift.tt/CcjHZdu
https://ift.tt/XfACbiS
Submitted August 16, 2022 at 07:07PM by hardenedvault
via reddit https://ift.tt/CcjHZdu
GitHub
GitHub - IAIK/AEPIC
Contribute to IAIK/AEPIC development by creating an account on GitHub.
Disrupting SEABORGIUM’s ongoing phishing operations
https://ift.tt/iaAOxwC
Submitted August 16, 2022 at 10:30PM by SCI_Rusher
via reddit https://ift.tt/AWQTGfE
https://ift.tt/iaAOxwC
Submitted August 16, 2022 at 10:30PM by SCI_Rusher
via reddit https://ift.tt/AWQTGfE
Microsoft Security Blog
Disrupting SEABORGIUM’s ongoing phishing operations - Microsoft Security Blog
The Microsoft Threat Intelligence Center (MSTIC) has observed and taken actions to disrupt campaigns launched by SEABORGIUM in campaigns involve persistent phishing and credential theft campaigns leading to intrusions and data theft.
Wheel of Fortune Outcome Prediction – Taking the Luck out of Gambling
https://ift.tt/yLrvuVF
Submitted August 17, 2022 at 12:21PM by digicat
via reddit https://ift.tt/40QgDSc
https://ift.tt/yLrvuVF
Submitted August 17, 2022 at 12:21PM by digicat
via reddit https://ift.tt/40QgDSc
NCC Group Research
Wheel of Fortune Outcome Prediction – Taking the Luck out of Gambling
I decided to carry out research on a real casino game in search of new vulnerabilities and exploit techniques. In case of success, I planned to share the results with the affected vendor and afterwards with the community. While I was looking for a target…
Return to Sender - Detecting Kernel Exploits with eBPF
https://ift.tt/sDoldeF
Submitted August 17, 2022 at 02:54PM by thorn42
via reddit https://ift.tt/VZp5jlz
https://ift.tt/sDoldeF
Submitted August 17, 2022 at 02:54PM by thorn42
via reddit https://ift.tt/VZp5jlz