Windows Firmware Attack Surface Reduction (FASR)
https://ift.tt/fsgbvt2
Submitted September 02, 2022 at 11:33PM by sanitybit
via reddit https://ift.tt/k5dtJbH
https://ift.tt/fsgbvt2
Submitted September 02, 2022 at 11:33PM by sanitybit
via reddit https://ift.tt/k5dtJbH
Docs
Firmware Attack Surface Reduction (FASR) - Windows drivers
Provides information about how to achieve Secured-core PC compliance with Firmware Attack Surface Reduction (FASR).
curl’s TLS fingerprint
https://ift.tt/2wVXuST
Submitted September 02, 2022 at 11:16PM by sanitybit
via reddit https://ift.tt/mxPfVQ3
https://ift.tt/2wVXuST
Submitted September 02, 2022 at 11:16PM by sanitybit
via reddit https://ift.tt/mxPfVQ3
There’s Another Hole In Your SoC: Unisoc ROM Vulnerabilities as used in the Motorola Moto E40 / Teclast T40 5G etc. - disclosure timeline is a thing of wonder
https://ift.tt/nNeTR69
Submitted September 03, 2022 at 12:16AM by digicat
via reddit https://ift.tt/htAbNDu
https://ift.tt/nNeTR69
Submitted September 03, 2022 at 12:16AM by digicat
via reddit https://ift.tt/htAbNDu
NCC Group Research
There’s Another Hole In Your SoC: Unisoc ROM Vulnerabilities
UNISOC (formerly Spreadtrum) is a rapidly growing semiconductor company that is nowadays focused on the Android entry-level smartphone market. While still a rare sight in the west, the company has …
Practical guide for Golden SAML
https://ift.tt/YlQLNIt
Submitted September 03, 2022 at 09:49AM by sanitybit
via reddit https://ift.tt/MQ7RSC5
https://ift.tt/YlQLNIt
Submitted September 03, 2022 at 09:49AM by sanitybit
via reddit https://ift.tt/MQ7RSC5
Nodauf
Practical guide for Golden SAML
Practical guide step by step to create golden SAML
Reviewing macOS Unified Logs
https://ift.tt/eEvkIXc
Submitted September 03, 2022 at 09:47AM by sanitybit
via reddit https://ift.tt/QamwhKN
https://ift.tt/eEvkIXc
Submitted September 03, 2022 at 09:47AM by sanitybit
via reddit https://ift.tt/QamwhKN
Mandiant
Reviewing macOS Unified Logs | Mandiant
SimpleX Chat - the first messaging platform that has no user identifiers (not even random numbers) - v3.2 of iOS and Android apps released - with Incognito mode and support for .onion hostnames.
https://ift.tt/ZEs6Pkd
Submitted September 03, 2022 at 09:43PM by epoberezkin
via reddit https://ift.tt/MuV7aN6
https://ift.tt/ZEs6Pkd
Submitted September 03, 2022 at 09:43PM by epoberezkin
via reddit https://ift.tt/MuV7aN6
GitHub
simplex-chat/blog/20220901-simplex-chat-v3.2-incognito-mode.md at stable · simplex-chat/simplex-chat
SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱! - simplex-chat/simplex-chat
Arti 1.0.0: Rust Tor implementation is ready for production use
https://ift.tt/tSD5LCF
Submitted September 04, 2022 at 12:07AM by sanitybit
via reddit https://ift.tt/auA9SXn
https://ift.tt/tSD5LCF
Submitted September 04, 2022 at 12:07AM by sanitybit
via reddit https://ift.tt/auA9SXn
blog.torproject.org
Arti 1.0.0 is released: Our Rust Tor implementation is ready for production use. | Tor Project
Arti 1.0.0 is released and ready for download.
Chromeloader browser hijacker
https://ift.tt/qpUSQmz
Submitted September 03, 2022 at 11:16PM by CyberMasterV
via reddit https://ift.tt/NrZ6Ym1
https://ift.tt/qpUSQmz
Submitted September 03, 2022 at 11:16PM by CyberMasterV
via reddit https://ift.tt/NrZ6Ym1
Fun with Windows Containers - Popping Calc
https://ift.tt/IAHvwRE
Submitted September 03, 2022 at 11:58PM by sanitybit
via reddit https://ift.tt/qm6x3JX
https://ift.tt/IAHvwRE
Submitted September 03, 2022 at 11:58PM by sanitybit
via reddit https://ift.tt/qm6x3JX
raesene.github.io
Fun with Windows Containers - Popping Calc
Eight-Year Study Shows the Dark Side of WordPress Plugins
https://ift.tt/tk3aqUu
Submitted September 04, 2022 at 06:42PM by jonas02
via reddit https://ift.tt/3NoCh45
https://ift.tt/tk3aqUu
Submitted September 04, 2022 at 06:42PM by jonas02
via reddit https://ift.tt/3NoCh45
Blocking Kiwifarms
https://ift.tt/uJdnbSX
Submitted September 04, 2022 at 06:53PM by 457655676
via reddit https://ift.tt/4WkduRK
https://ift.tt/uJdnbSX
Submitted September 04, 2022 at 06:53PM by 457655676
via reddit https://ift.tt/4WkduRK
WPHash - Fingerprinting WordPress Plugins, now in public beta and open to feedback and collaboration
https://wpha.sh/
Submitted September 05, 2022 at 12:14AM by _cydave
via reddit https://ift.tt/WRndo4L
https://wpha.sh/
Submitted September 05, 2022 at 12:14AM by _cydave
via reddit https://ift.tt/WRndo4L
wpha.sh
WPHash: WordPress Plugin Fingerprinting
WPHash indexes over 75 million SHA256 hashes for fingerprinting the exact version of WordPress plugins.
CVE-2022-30190, AKA Follina, Uses Macro-less Word Docs to Drop RCE Files
https://ift.tt/4QtJU8f
Submitted September 05, 2022 at 01:43PM by anyore909
via reddit https://ift.tt/bG5jCPx
https://ift.tt/4QtJU8f
Submitted September 05, 2022 at 01:43PM by anyore909
via reddit https://ift.tt/bG5jCPx
Cymulate
CVE-2022-30190, AKA Follina, Uses Macro-less Word Docs to Drop RCE Files
Rated a 7.8 high CVSS 3.x severity base score, CVE-2022-30190 takes advantage of the MSDT, an official tool built-in all versions of Windows.
PoC: resolving dynamically System Service Numbers (SSN) for syscalling in VBA (x64) using FreshyCalls technique
https://ift.tt/qJcR7U3
Submitted September 05, 2022 at 01:30PM by gid0rah
via reddit https://ift.tt/4C3HnQ9
https://ift.tt/qJcR7U3
Submitted September 05, 2022 at 01:30PM by gid0rah
via reddit https://ift.tt/4C3HnQ9
Gist
Retrieving SSN for syscalling in VBA following FreshyCalls technique
Retrieving SSN for syscalling in VBA following FreshyCalls technique - FreshyCalls-VBA.vba
Walkthrough of an unauthenticated RCE affecting pfBlockerNG <= 2.1.4_26 (CVE-2022-31814)
https://ift.tt/U6W5MV1
Submitted September 05, 2022 at 02:10PM by IHTeam
via reddit https://ift.tt/BAfDcke
https://ift.tt/U6W5MV1
Submitted September 05, 2022 at 02:10PM by IHTeam
via reddit https://ift.tt/BAfDcke
IHTeam Security Blog
pfBlockerNG Unauth RCE Vulnerability - IHTeam Security Blog
TL;DR IHTeam undertook an independent security assessment of pfsense’s pfBlockerNG plugin version 2.1.4_26 and identified the following vulnerability: Unauthenticated Remote Command Execution as root (CVE-2022-31814) What’s pfBlockerNG pfBlockerNG (https…
Hacking my Helium Crypto Miner
https://ift.tt/tSzYriG
Submitted September 05, 2022 at 04:23PM by wez32
via reddit https://ift.tt/ULVMrKm
https://ift.tt/tSzYriG
Submitted September 05, 2022 at 04:23PM by wez32
via reddit https://ift.tt/ULVMrKm
Zolder B.V.
Hacking my Helium Crypto Miner
Recently I came across an interesting cryptocurrency project called Helium. Its a wireless network built by people all around the world. The people that help expanding the network by adding a hotsp…
Simple IBM i (AS/400) hacking
https://ift.tt/etArhDc
Submitted September 05, 2022 at 05:36PM by buherator
via reddit https://ift.tt/0hQGDlb
https://ift.tt/etArhDc
Submitted September 05, 2022 at 05:36PM by buherator
via reddit https://ift.tt/0hQGDlb
Shielder - How to Decrypt Manage Engine PMP Passwords for Fun and Domain Admin - a Red Teaming Tale
https://ift.tt/PZHsAzi
Submitted September 05, 2022 at 08:17PM by smaury
via reddit https://ift.tt/5fghyk3
https://ift.tt/PZHsAzi
Submitted September 05, 2022 at 08:17PM by smaury
via reddit https://ift.tt/5fghyk3
Shielder
Shielder - How to Decrypt Manage Engine PMP Passwords for Fun and Domain Admin - a Red Teaming Tale
Reverse engineering and analysis of a fiscal printer device for fun and (real) profit.
Anatomy of an exploit in Windows win32k - CVE-2022-21882 - Avira Blog
https://ift.tt/SDntOkU
Submitted September 06, 2022 at 12:09AM by jeandrew
via reddit https://ift.tt/CVJqul6
https://ift.tt/SDntOkU
Submitted September 06, 2022 at 12:09AM by jeandrew
via reddit https://ift.tt/CVJqul6
Avira Blog
Anatomy of an exploit in Windows win32k - CVE-2022-21882 - Avira Blog
CVE-2022-21882: A new manipulation technique of window objects in kernel memory that leads to privilege escalation
SAT/SMT Solvers by Example
https://ift.tt/koBdGHx
Submitted September 06, 2022 at 07:36AM by ambray_
via reddit https://ift.tt/iBqfujR
https://ift.tt/koBdGHx
Submitted September 06, 2022 at 07:36AM by ambray_
via reddit https://ift.tt/iBqfujR
TA505 Group's TeslaGun In-Depth Analysis
https://ift.tt/UzDlwxr
Submitted September 06, 2022 at 03:43PM by wtfse
via reddit https://ift.tt/dNQsiM3
https://ift.tt/UzDlwxr
Submitted September 06, 2022 at 03:43PM by wtfse
via reddit https://ift.tt/dNQsiM3
Prodaft
[TA505] TA505 Group's TeslaGun In-Depth Analysis - PRODAFT
Prodaft is a cyber threat intelligence company helping organizations to mitigate cyber threats. Our expert engineers put forth proactive defense mechanisms to safeguard your business from cyber attacks.