Zero Trust - From Zero to One Hundred
https://ift.tt/eWYRSAX
Submitted September 25, 2022 at 03:20AM by Khryse
via reddit https://ift.tt/xSei35d
https://ift.tt/eWYRSAX
Submitted September 25, 2022 at 03:20AM by Khryse
via reddit https://ift.tt/xSei35d
Sleep obfuscation technique leveraging waitable timers to evade memory scanners.
https://ift.tt/9ojuCsv
Submitted September 25, 2022 at 04:59PM by Idov31
via reddit https://ift.tt/VWBOXxp
https://ift.tt/9ojuCsv
Submitted September 25, 2022 at 04:59PM by Idov31
via reddit https://ift.tt/VWBOXxp
GitHub
GitHub - Idov31/Cronos: PoC for a new sleep obfuscation technique leveraging waitable timers to evade memory scanners.
PoC for a new sleep obfuscation technique leveraging waitable timers to evade memory scanners. - GitHub - Idov31/Cronos: PoC for a new sleep obfuscation technique leveraging waitable timers to evad...
Cpplumber 0.1.0 - Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects.
https://ift.tt/ZByT9Xo
Submitted September 25, 2022 at 07:57PM by ergrelet
via reddit https://ift.tt/eG64nO0
https://ift.tt/ZByT9Xo
Submitted September 25, 2022 at 07:57PM by ergrelet
via reddit https://ift.tt/eG64nO0
GitHub
GitHub - ergrelet/cpplumber: Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++…
Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects - GitHub - ergrelet/cpplumber: Static analysis tool based on clang, which detects source-...
Google VRP Teaser - Today I Learned
https://ift.tt/JVftbiX
Submitted September 25, 2022 at 09:56PM by TechbrunchFR
via reddit https://ift.tt/li1uKah
https://ift.tt/JVftbiX
Submitted September 25, 2022 at 09:56PM by TechbrunchFR
via reddit https://ift.tt/li1uKah
www.techbrunch.fr
Google VRP Teaser - Today I Learned
On August 9, the @GoogleVRP Twitter account as well as multiple Googlers started teasing an event with a link to a login page as well as a video. This small post exlains how to get the password and what it reveals.
Microsoft Shift F10 bypass + Autopilot privilege escalation
https://ift.tt/fI326WG
Submitted September 26, 2022 at 04:54PM by k4m1ll0
via reddit https://ift.tt/rzR8XYt
https://ift.tt/fI326WG
Submitted September 26, 2022 at 04:54PM by k4m1ll0
via reddit https://ift.tt/rzR8XYt
K4M1Ll0
Shift F10 bypass and Autopilot privilge escalation
Shift + F10 bypass and privilege escalation
When Athletic Abilities Just Aren't Enough - Scoreboard Hacking Part 2
https://ift.tt/gPwhunt
Submitted September 26, 2022 at 08:13PM by mdulin2
via reddit https://ift.tt/pzk6v5F
https://ift.tt/gPwhunt
Submitted September 26, 2022 at 08:13PM by mdulin2
via reddit https://ift.tt/pzk6v5F
A study of cracked passwords from breaches demonstrates which geographical factors have the most impact on password strength
https://ift.tt/5rfVbPv
Submitted September 26, 2022 at 09:22PM by obilodeau
via reddit https://ift.tt/oZN2XnK
https://ift.tt/5rfVbPv
Submitted September 26, 2022 at 09:22PM by obilodeau
via reddit https://ift.tt/oZN2XnK
GoSecure
Tell Me Where You Live and I Will Tell You About Your P@ssw0rd: Understanding the Macrosocial Factors Influencing Password’s Strength…
Your password strength is influenced by where you live. Understand which macrosocial factors influence your password selection strategies in this article.
Vultron: A Protocol for Coordinated Vulnerability Disclosure
https://ift.tt/z4iUmI8
Submitted September 27, 2022 at 02:33AM by sanitybit
via reddit https://ift.tt/MTJkuli
https://ift.tt/z4iUmI8
Submitted September 27, 2022 at 02:33AM by sanitybit
via reddit https://ift.tt/MTJkuli
SEI Blog
Vultron: A Protocol for Coordinated Vulnerability Disclosure
This post introduces Vultron, a protocol for multi-party coordinated vulnerability disclosure (MPCVD).
MemProcFS: An easy and convenient way of viewing physical memory as files in a virtual file system.
https://ift.tt/1KdCN4V
Submitted September 27, 2022 at 03:18AM by sanitybit
via reddit https://ift.tt/2H0CjP4
https://ift.tt/1KdCN4V
Submitted September 27, 2022 at 03:18AM by sanitybit
via reddit https://ift.tt/2H0CjP4
GitHub
GitHub - ufrisk/MemProcFS: The Memory Process File System
The Memory Process File System. Contribute to ufrisk/MemProcFS development by creating an account on GitHub.
monomorph: MD5-Monomorphic Shellcode Packer - Pack arbitrary shellcode into an executable that always has the same MD5 hash
https://ift.tt/EjVduO9
Submitted September 27, 2022 at 03:12AM by sanitybit
via reddit https://ift.tt/7IT6jsd
https://ift.tt/EjVduO9
Submitted September 27, 2022 at 03:12AM by sanitybit
via reddit https://ift.tt/7IT6jsd
GitHub
GitHub - DavidBuchanan314/monomorph: MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash
MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash - GitHub - DavidBuchanan314/monomorph: MD5-Monomorphic Shellcode Packer - all payloads have the same MD5 hash
Designing an end-to-end encrypted note sharing service
https://ift.tt/Us1c7Vw
Submitted September 27, 2022 at 02:59AM by 0x414141
via reddit https://ift.tt/kRipA6S
https://ift.tt/Us1c7Vw
Submitted September 27, 2022 at 02:59AM by 0x414141
via reddit https://ift.tt/kRipA6S
mcndt.dev
Designing an end-to-end encrypted note sharing service 🔐📝
How can you share data securely via the web browser, using a third-party server? In this article, I explain how I created a end-to-end encrypted note sharing service called Noteshare.space, how the security mechanism works, and how to securely encode decryption…
Vulnerability in WhatsApp mobile apps could result in remote code execution in an established video call (CVSS 9.8)
https://ift.tt/6XPTc3U
Submitted September 27, 2022 at 04:45PM by qwerty0x41
via reddit https://ift.tt/Zi64NE0
https://ift.tt/6XPTc3U
Submitted September 27, 2022 at 04:45PM by qwerty0x41
via reddit https://ift.tt/Zi64NE0
Skidaddle Skideldi - I just pwnd your PKI
https://ift.tt/l2qtNAL
Submitted September 27, 2022 at 05:43PM by 0xdea
via reddit https://ift.tt/hZPsJnz
https://ift.tt/l2qtNAL
Submitted September 27, 2022 at 05:43PM by 0xdea
via reddit https://ift.tt/hZPsJnz
luemmelsec.github.io
Skidaddle Skideldi - I just pwnd your PKI
My dear Bagginses and Boffins, Tooks and Brandybucks, Grubbs, Chubbs, Hornblowers, Bolgers, Bracegirdles and Proudfoots - it is time for some new shit.
We are going to explore the wonderful world of Active Directory Certificate Services, aka ADCS.
If you…
We are going to explore the wonderful world of Active Directory Certificate Services, aka ADCS.
If you…
A technical analysis of Pegasus for Android – Part 2
https://ift.tt/SNVgGdw
Submitted September 27, 2022 at 06:32PM by CyberMasterV
via reddit https://ift.tt/AES9XaO
https://ift.tt/SNVgGdw
Submitted September 27, 2022 at 06:32PM by CyberMasterV
via reddit https://ift.tt/AES9XaO
Diving Into Electron Web API Permissions
https://ift.tt/r9xApBZ
Submitted September 27, 2022 at 08:26PM by nibblesec
via reddit https://ift.tt/A2ukEVF
https://ift.tt/r9xApBZ
Submitted September 27, 2022 at 08:26PM by nibblesec
via reddit https://ift.tt/A2ukEVF
Doyensec
Diving Into Electron Web API Permissions · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment
https://ift.tt/9ZfuGL2
Submitted September 28, 2022 at 01:46AM by sanitybit
via reddit https://ift.tt/vsMEUTS
https://ift.tt/9ZfuGL2
Submitted September 28, 2022 at 01:46AM by sanitybit
via reddit https://ift.tt/vsMEUTS
Medium
Jumping Over the Gate
Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment
Audit your DNS config, you'd be shocked at how bad it can get
https://ift.tt/Taeqszm
Submitted September 28, 2022 at 01:16AM by punksecurity_simon
via reddit https://ift.tt/vXkzVOp
https://ift.tt/Taeqszm
Submitted September 28, 2022 at 01:16AM by punksecurity_simon
via reddit https://ift.tt/vXkzVOp
GitHub
GitHub - punk-security/dnsReaper: dnsReaper - subdomain takeover tool for attackers, bug bounty hunters and the blue team!
dnsReaper - subdomain takeover tool for attackers, bug bounty hunters and the blue team! - GitHub - punk-security/dnsReaper: dnsReaper - subdomain takeover tool for attackers, bug bounty hunters an...
The difference between signature-based and behavioural detections
https://ift.tt/B25nLxl
Submitted September 28, 2022 at 02:23AM by S3cur3Th1sSh1t
via reddit https://ift.tt/jr5dziq
https://ift.tt/B25nLxl
Submitted September 28, 2022 at 02:23AM by S3cur3Th1sSh1t
via reddit https://ift.tt/jr5dziq
s3cur3th1ssh1t.github.io
The difference between signature-based and behavioural detections | S3cur3Th1sSh1t
In this blog post, the main difference between signature-based and behavior-based Detections are explained. In addition, examples are shown with respective D...
Ken Thompson Really Did Launch His "Trusting Trust" Trojan Attack in Real Life
https://ift.tt/a0Xf9B2
Submitted September 28, 2022 at 01:54AM by nic0nicon1
via reddit https://ift.tt/QE041Ou
https://ift.tt/a0Xf9B2
Submitted September 28, 2022 at 01:54AM by nic0nicon1
via reddit https://ift.tt/QE041Ou
niconiconi.neocities.org
Ken Thompson Really Did Launch His "Trusting Trust" Trojan Attack in Real Life
Ken Thompson's "Trusting Trust" compiler Trojan attack was not just a thought experiment. In fact, Usenet poster Jay Ashworth stated that, from personal communications, Thompson really did launch this attack in real life and successfully compromised the Unix…
Enhance your malware detection with WAF + YARA (WAFARAY)
https://ift.tt/B3SaJT7
Submitted September 28, 2022 at 10:33AM by alt3kx
via reddit https://ift.tt/DTxVKYj
https://ift.tt/B3SaJT7
Submitted September 28, 2022 at 10:33AM by alt3kx
via reddit https://ift.tt/DTxVKYj
GitHub
GitHub - alt3kx/wafaray: Enhance your malware detection with WAF + YARA (WAFARAY)
Enhance your malware detection with WAF + YARA (WAFARAY) - GitHub - alt3kx/wafaray: Enhance your malware detection with WAF + YARA (WAFARAY)
When Hypervisor Met Snapshot Fuzzing
https://ift.tt/ErWmcLd
Submitted September 28, 2022 at 11:08AM by jeandrew
via reddit https://ift.tt/x6TYcOm
https://ift.tt/ErWmcLd
Submitted September 28, 2022 at 11:08AM by jeandrew
via reddit https://ift.tt/x6TYcOm
安全代码
When Hypervisor Met Snapshot Fuzzing
source: https://null2root.github.io/blog/2022/07/21/When-Hypervisor-Met-Snapshot-Fuzzing.html 1. IntroductionHypervisor was known as hard target to fuzz over several years. Even though, lots of prior