The Elastic Container Project for Security Research
https://ift.tt/0GxmbLs
Submitted August 27, 2022 at 06:13AM by sanitybit
via reddit https://ift.tt/uh6XOJ3
https://ift.tt/0GxmbLs
Submitted August 27, 2022 at 06:13AM by sanitybit
via reddit https://ift.tt/uh6XOJ3
Elastic Blog
The Elastic Container Project for Security Research
The Elastic Container Project provides a single shell noscript that will allow you to stand up and manage an entire Elastic Stack using Docker. This open source project enables rapid deployment for testing use cases.
Awesome Security Newsletters
https://ift.tt/Y1xkmNf
Submitted August 27, 2022 at 05:57PM by zuuZuux3
via reddit https://ift.tt/5zEauNK
https://ift.tt/Y1xkmNf
Submitted August 27, 2022 at 05:57PM by zuuZuux3
via reddit https://ift.tt/5zEauNK
GitHub
GitHub - TalEliyahu/awesome-security-newsletters: Periodic cyber security newsletters that capture the latest news, summaries of…
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attac...
Command Injection in the GitHub Pages Build Pipeline
https://ift.tt/1QOnWcD
Submitted August 27, 2022 at 09:18PM by whisperingmime
via reddit https://ift.tt/vtZFUVE
https://ift.tt/1QOnWcD
Submitted August 27, 2022 at 09:18PM by whisperingmime
via reddit https://ift.tt/vtZFUVE
Blog by Joren Vrancken
Command Injection in the GitHub Pages Build Pipeline
Recently, I participated in the GitHub Bug Bounty program (run through HackerOne). This is a writeup of a command injection bug I discovered in GitHub Pages build process.
SATisfying our way into remote code execution in the OPC UA industrial stack
https://ift.tt/izt4D5Y
Submitted August 28, 2022 at 12:06PM by SRMish3
via reddit https://ift.tt/s8PutUJ
https://ift.tt/izt4D5Y
Submitted August 28, 2022 at 12:06PM by SRMish3
via reddit https://ift.tt/s8PutUJ
JFrog
OPC UA Vulnerabilities Discovered Following Pwn2Own 2022 Hacking Competition
Remote code execution vulnerability found by JFrog Security Research, exploiting an Info Leak and Heap Overflow on UA’s C++ OPC demo server.
On Cryptocurrency Wallet Design – defines access control taxonomy, can be reused e.g. for MFA factors
https://ift.tt/ckmaULi
Submitted August 28, 2022 at 12:58PM by D4r1
via reddit https://ift.tt/hCVnlSg
https://ift.tt/ckmaULi
Submitted August 28, 2022 at 12:58PM by D4r1
via reddit https://ift.tt/hCVnlSg
Vision2 this noscript analyses the Nmap XML scanning results parses each CPE context and correlates to search CVE on NIST. You can use that to find public vulnerabilities in services.
https://ift.tt/vT3eInP
Submitted August 29, 2022 at 08:23AM by CoolerVoid
via reddit https://ift.tt/OmiISeX
https://ift.tt/vT3eInP
Submitted August 29, 2022 at 08:23AM by CoolerVoid
via reddit https://ift.tt/OmiISeX
GitHub
GitHub - CoolerVoid/Vision2: Nmap's XML result parse and NVD's CPE correlation to search CVE.
Nmap's XML result parse and NVD's CPE correlation to search CVE. - GitHub - CoolerVoid/Vision2: Nmap's XML result parse and NVD's CPE correlation to search CVE.
A technical analysis of Pegasus for Android – Part 1
https://ift.tt/ULJRH1n
Submitted August 29, 2022 at 06:33PM by CyberMasterV
via reddit https://ift.tt/TmDHwWE
https://ift.tt/ULJRH1n
Submitted August 29, 2022 at 06:33PM by CyberMasterV
via reddit https://ift.tt/TmDHwWE
Blind exploits to rule WatchGuard firewalls: pre-auth RCE as root on WG appliances
https://ift.tt/sg61dLU
Submitted August 29, 2022 at 07:52PM by cfambionics
via reddit https://ift.tt/gV9uciq
https://ift.tt/sg61dLU
Submitted August 29, 2022 at 07:52PM by cfambionics
via reddit https://ift.tt/gV9uciq
Ambionics
Blind exploits to rule WatchGuard firewalls
Early this year we had the opportunity to pentest Watchguard firewalls (XTM, Firebox) for a red team engagement. This blogpost will follow the journey in which I discover 5 vulnerabilities - 2 patched along the way - and build 8 distinct exploits, and finally…
Part 1 – SingPass RASP Analysis
https://ift.tt/koZGfLs
Submitted August 29, 2022 at 09:50PM by jeandrew
via reddit https://ift.tt/BnMCjYT
https://ift.tt/koZGfLs
Submitted August 29, 2022 at 09:50PM by jeandrew
via reddit https://ift.tt/BnMCjYT
Romain Thomas
Part 1 – SingPass RASP Analysis | Romain Thomas
This first blog post introduces the RASP checks used in SingPass
jscythe: Abuse the node.js inspector mechanism to force any node.js/electron/v8 based process to execute arbitrary javanoscript code.
https://ift.tt/Tk4Js0Z
Submitted August 30, 2022 at 01:07AM by sanitybit
via reddit https://ift.tt/5KFExb7
https://ift.tt/Tk4Js0Z
Submitted August 30, 2022 at 01:07AM by sanitybit
via reddit https://ift.tt/5KFExb7
GitHub
GitHub - evilsocket/jscythe: Abuse the node.js inspector mechanism in order to force any node.js/electron/v8 based process to execute…
Abuse the node.js inspector mechanism in order to force any node.js/electron/v8 based process to execute arbitrary javanoscript code. - GitHub - evilsocket/jscythe: Abuse the node.js inspector mechan...
Ethernaut CTF walkthrough with Brownie framework
https://ift.tt/wEfzxkc
Submitted August 30, 2022 at 04:32AM by Glittering_Audience8
via reddit https://ift.tt/yQvYaJ1
https://ift.tt/wEfzxkc
Submitted August 30, 2022 at 04:32AM by Glittering_Audience8
via reddit https://ift.tt/yQvYaJ1
securitypills.news
Ethernaut Challenges
Please read This is a work in progress article that will receive updates as we continue publishing detailed walkthroughs for each level.
Ethernaut is OpenZeppelin Web3/Solidity based wargame to learn about Ethereum smart contract security and become familiar…
Ethernaut is OpenZeppelin Web3/Solidity based wargame to learn about Ethereum smart contract security and become familiar…
Truth Behind the Celer Network cBridge cross-chain bridge incident: BGP hijacking
https://ift.tt/DwcvRUt
Submitted August 30, 2022 at 11:18AM by sanitybit
via reddit https://ift.tt/BxYv5ys
https://ift.tt/DwcvRUt
Submitted August 30, 2022 at 11:18AM by sanitybit
via reddit https://ift.tt/BxYv5ys
Medium
Truth Behind the Celer Network cBridge cross-chain bridge incident: BGP hijacking
BGP hijacking
Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later
https://ift.tt/6SiXT4z
Submitted August 30, 2022 at 11:16AM by sanitybit
via reddit https://ift.tt/ECXLMiI
https://ift.tt/6SiXT4z
Submitted August 30, 2022 at 11:16AM by sanitybit
via reddit https://ift.tt/ECXLMiI
Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later
Tetsuji: Remote Code Execution on a GameBoy Colour 22 Years Later :: TheXcellerator
Introduction It’s that time of year again - the Binary Golf Grand Prix is back for a third year running! You can also check out my entries to the first and second times this amazing competition ran.
The theme this year was to produce a binary that crashes…
The theme this year was to produce a binary that crashes…
Incident Response in AWS
https://ift.tt/hgBvZRT
Submitted August 30, 2022 at 11:11AM by sanitybit
via reddit https://ift.tt/cf2rnyZ
https://ift.tt/hgBvZRT
Submitted August 30, 2022 at 11:11AM by sanitybit
via reddit https://ift.tt/cf2rnyZ
https://www.chrisfarris.com/
Incident Response in AWS - Chris Farris
At BSides Atlanta I gave a talk on how to handle an incident in AWS. The talk and this post is intended to help those already familiar with the principles of Incident Response to understand what to do when the incident involves the AWS Control Plane.
Write-up of N-day exploit for CVE-2022-2586: Linux kernel nft_object UAF
https://ift.tt/ZyGupHY
Submitted August 30, 2022 at 01:51PM by gid0rah
via reddit https://ift.tt/JWsX6OK
https://ift.tt/ZyGupHY
Submitted August 30, 2022 at 01:51PM by gid0rah
via reddit https://ift.tt/JWsX6OK
CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM
https://ift.tt/wa0yNA1
Submitted August 30, 2022 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/fDOM235
https://ift.tt/wa0yNA1
Submitted August 30, 2022 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/fDOM235
Rhino Security Labs
CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM - Rhino Security Labs
CVE-2022-26113: Arbitrary file write as SYSTEM in Fortinet VPN, with privilege escalation implications.
hashcathelper: Convenience tool for hashcat - crack NT hashes by taking LM hashes into account; generate analytics for cracked passwords; visualize "SamePassword" clusters in Bloodhound
https://ift.tt/aAVpRew
Submitted August 30, 2022 at 11:45PM by 0xfffffg
via reddit https://ift.tt/4TIHvpz
https://ift.tt/aAVpRew
Submitted August 30, 2022 at 11:45PM by 0xfffffg
via reddit https://ift.tt/4TIHvpz
GitHub
GitHub - SySS-Research/hashcathelper: Convenience tool for hashcat
Convenience tool for hashcat . Contribute to SySS-Research/hashcathelper development by creating an account on GitHub.
Bootkitting Windows Sandbox
https://ift.tt/wjiNn0A
Submitted August 31, 2022 at 12:14AM by mrexodia
via reddit https://ift.tt/6rPjKZ5
https://ift.tt/wjiNn0A
Submitted August 31, 2022 at 12:14AM by mrexodia
via reddit https://ift.tt/6rPjKZ5
secret club
Bootkitting Windows Sandbox
Introduction & Motivation Windows Sandbox is a feature that Microsoft added to Windows back in May 2019. As Microsoft puts it: Windows Sandbox provides a lightweight desktop environment to safely run applications in isolation. Software installed inside the…
reinschauer - A PoC to remotely control Windows machines over Websockets.
https://ift.tt/TZe1MbB
Submitted August 31, 2022 at 04:30AM by sanitybit
via reddit https://ift.tt/Kgmt86T
https://ift.tt/TZe1MbB
Submitted August 31, 2022 at 04:30AM by sanitybit
via reddit https://ift.tt/Kgmt86T
GitHub
GitHub - ps1337/reinschauer: it is very good
it is very good. Contribute to ps1337/reinschauer development by creating an account on GitHub.
Going Atomic: The Strengths and Weaknesses of a Technique-centric Purple Teaming Approach
https://ift.tt/ANKUiCf
Submitted August 31, 2022 at 04:20AM by sanitybit
via reddit https://ift.tt/D7uGUrY
https://ift.tt/ANKUiCf
Submitted August 31, 2022 at 04:20AM by sanitybit
via reddit https://ift.tt/D7uGUrY
ajpc500
Blue Team Con: Going Atomic
The Strengths and Weaknesses of a Technique-centric Purple Teaming Approach
MATE: Interactive Program Analysis with Code Property Graphs
https://ift.tt/UtEOuyw
Submitted August 31, 2022 at 05:35AM by sanitybit
via reddit https://ift.tt/ItlKvSb
https://ift.tt/UtEOuyw
Submitted August 31, 2022 at 05:35AM by sanitybit
via reddit https://ift.tt/ItlKvSb
Galois, Inc.
MATE: Interactive Program Analysis with Code Property Graphs - Galois, Inc.
Galois is open-sourcing MATE, a suite of tools for interactive program analysis with a focus on hunting for bugs in C and C++ code. MATE unifies application-specific and low-level vulnerability analysis using code property graphs (CPGs), enabling the discovery…