GitHub - jafarlihi/connmap: connmap is an X11 desktop widget that shows location of your current network peers on a world map (tested only with i3wm). Made with C and libcairo.
https://ift.tt/jW1RQDs
Submitted September 28, 2022 at 09:01PM by jafarlihi
via reddit https://ift.tt/DbpOBPH
https://ift.tt/jW1RQDs
Submitted September 28, 2022 at 09:01PM by jafarlihi
via reddit https://ift.tt/DbpOBPH
GitHub
GitHub - jafarlihi/connmap: connmap is an X11 desktop widget that shows location of your current network peers on a world map
connmap is an X11 desktop widget that shows location of your current network peers on a world map - GitHub - jafarlihi/connmap: connmap is an X11 desktop widget that shows location of your current ...
LuaJIT hacking: Crafting Shellcodes
https://ift.tt/QzjCv3p
Submitted September 29, 2022 at 01:50AM by pwntheplanet
via reddit https://ift.tt/QWxrBEs
https://ift.tt/QzjCv3p
Submitted September 29, 2022 at 01:50AM by pwntheplanet
via reddit https://ift.tt/QWxrBEs
GitHub
GitHub - 0xbigshaq/luajit-pwn: Vuln-dev environment for LuaJIT
Vuln-dev environment for LuaJIT. Contribute to 0xbigshaq/luajit-pwn development by creating an account on GitHub.
Kerberos: New Attack Paths? AS Requested Service Tickets
https://ift.tt/xrX82bV
Submitted September 29, 2022 at 02:35AM by sanitybit
via reddit https://ift.tt/jBeQzE3
https://ift.tt/xrX82bV
Submitted September 29, 2022 at 02:35AM by sanitybit
via reddit https://ift.tt/jBeQzE3
Semperis
New Attack Paths? AS Requested Service Tickets - Semperis
Could AS Requested Service Tickets open new attack paths? Read "New Attack Paths? AS Requested Service Tickets" to learn more.
Talking Trojan: Analyzing an Industry-Wide Disclosure
https://ift.tt/I6enrJ2
Submitted September 29, 2022 at 02:33AM by sanitybit
via reddit https://ift.tt/7tsqLRl
https://ift.tt/I6enrJ2
Submitted September 29, 2022 at 02:33AM by sanitybit
via reddit https://ift.tt/7tsqLRl
The Confusing Lifetimes of AWS IAM Identity Center Access Tokens
https://ift.tt/j5uQS3z
Submitted September 29, 2022 at 03:28AM by csanders_
via reddit https://ift.tt/eHoRi43
https://ift.tt/j5uQS3z
Submitted September 29, 2022 at 03:28AM by csanders_
via reddit https://ift.tt/eHoRi43
Medium
The Confusing Lifetimes of AWS IAM Identity Center Access Tokens
Every week, almost without fail, I come across one thing that confuses, entertains, or most commonly infuriates me. I’ve decided to keep a…
GitHub - swanandx/lemmeknow: The fastest way to identify anything! Blazingly Fast alternative to PyWhat made with Rust.
https://ift.tt/IUE46G2
Submitted September 29, 2022 at 12:39PM by swanandx
via reddit https://ift.tt/bo8GP79
https://ift.tt/IUE46G2
Submitted September 29, 2022 at 12:39PM by swanandx
via reddit https://ift.tt/bo8GP79
GitHub
GitHub - swanandx/lemmeknow: The fastest way to identify anything!
The fastest way to identify anything! Contribute to swanandx/lemmeknow development by creating an account on GitHub.
New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server
https://ift.tt/k6CZvfz
Submitted September 30, 2022 at 01:19AM by CyberMasterV
via reddit https://ift.tt/5QnovCM
https://ift.tt/k6CZvfz
Submitted September 30, 2022 at 01:19AM by CyberMasterV
via reddit https://ift.tt/5QnovCM
Detecting Mimikatz with Busylight
https://ift.tt/Ego5Vbi
Submitted September 30, 2022 at 01:48PM by digicat
via reddit https://ift.tt/3ZEzGbm
https://ift.tt/Ego5Vbi
Submitted September 30, 2022 at 01:48PM by digicat
via reddit https://ift.tt/3ZEzGbm
NCC Group Research Blog
Detecting Mimikatz with Busylight
In 2015 Raphael Mudge released an article [1] that detailed that versions of mimikatz released after 8th of October, 2015 had a new module that was utilising certain types of external USB devices t…
Arbitrary cache poisoning on all Akamai websites via 'Connection: Content-Length'
https://ift.tt/lpUtn2r
Submitted September 30, 2022 at 01:37PM by albinowax
via reddit https://ift.tt/PqjQCDb
https://ift.tt/lpUtn2r
Submitted September 30, 2022 at 01:37PM by albinowax
via reddit https://ift.tt/PqjQCDb
Medium
Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)
Introduction And Context
What I learnt from reading 220 IDOR bug reports.
https://ift.tt/8AGlkvj
Submitted September 30, 2022 at 06:08PM by _nynan
via reddit https://ift.tt/FlI6uBk
https://ift.tt/8AGlkvj
Submitted September 30, 2022 at 06:08PM by _nynan
via reddit https://ift.tt/FlI6uBk
Medium
What I learnt from reading 220* IDOR bug reports.
IDOR — Insecure Direct Object Reference, abuse of the lack of authentication at every stage.
VNCERT/CC has just developed a tool to check Exchange's 0-day exploit http request blocking. #exchange #0day #exploit #vncertcc
https://ift.tt/AOxfMmW
Submitted September 30, 2022 at 10:06PM by InterestingEmu4225
via reddit https://ift.tt/ad0GYwP
https://ift.tt/AOxfMmW
Submitted September 30, 2022 at 10:06PM by InterestingEmu4225
via reddit https://ift.tt/ad0GYwP
GitHub
GitHub - VNCERT-CC/0dayex-checker: Zeroday Microsoft Exchange Server checker (Virtual Patching checker)
Zeroday Microsoft Exchange Server checker (Virtual Patching checker) - VNCERT-CC/0dayex-checker
Reddit is looking for a Security Data Engineer
https://ift.tt/hMOJgv3
Submitted October 01, 2022 at 02:06AM by mr_snoobot
via reddit https://ift.tt/0xdRD6s
https://ift.tt/hMOJgv3
Submitted October 01, 2022 at 02:06AM by mr_snoobot
via reddit https://ift.tt/0xdRD6s
boards.greenhouse.io
Reddit
H4CK1NG G00GL3 - Security challenges
https://h4ck1ng.google/
Submitted October 01, 2022 at 05:00AM by foxTN
via reddit https://ift.tt/URCsOI3
https://h4ck1ng.google/
Submitted October 01, 2022 at 05:00AM by foxTN
via reddit https://ift.tt/URCsOI3
h4ck1ng.google
H4CK1NG G00GL3
The best way to stop a hacker is to think like one.
Wiresocks for easy proxied routing
https://ift.tt/AOqN6WL
Submitted October 01, 2022 at 07:16AM by sanitybit
via reddit https://ift.tt/YdKqOZD
https://ift.tt/AOqN6WL
Submitted October 01, 2022 at 07:16AM by sanitybit
via reddit https://ift.tt/YdKqOZD
Sensepost
SensePost | Wiresocks for easy proxied routing
Leaders in Information Security
Emulate Shellcode with Radare2
https://ift.tt/xJ4P83j
Submitted October 01, 2022 at 07:11AM by sanitybit
via reddit https://ift.tt/tLrKqYs
https://ift.tt/xJ4P83j
Submitted October 01, 2022 at 07:11AM by sanitybit
via reddit https://ift.tt/tLrKqYs
www.sans.org
Emulate Shellcode with Radare2 | SANS Institute
If you are troubleshooting custom shellcode, you need to work through the instructions patiently and deliberately. This article looks at how to emulate 32-bit ARM shellcode on an x86_64 Ubuntu system.
/r/netsec's Q4 2022 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesOne post per company; it may contain multiple open positions. Please do not use multiple comments to post multiple positions, as the additional comments will be removed.Include the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 01, 2022 at 06:55AM by sanitybit
via reddit https://ift.tt/0ukYd74
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesOne post per company; it may contain multiple open positions. Please do not use multiple comments to post multiple positions, as the additional comments will be removed.Include the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 01, 2022 at 06:55AM by sanitybit
via reddit https://ift.tt/0ukYd74
reddit
reddit.com: search results - "Information Security Hiring Thread"
r/netsec: /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise …
Report on Secure Compilation
https://ift.tt/T05isVe
Submitted October 02, 2022 at 04:17AM by 0x414141
via reddit https://ift.tt/C2Ijbq3
https://ift.tt/T05isVe
Submitted October 02, 2022 at 04:17AM by 0x414141
via reddit https://ift.tt/C2Ijbq3
Tillitis - Open Source USB security key inspired by measured boot and DICE
https://ift.tt/LNa5Smq
Submitted October 02, 2022 at 04:16AM by 0x414141
via reddit https://ift.tt/4HmbkGC
https://ift.tt/LNa5Smq
Submitted October 02, 2022 at 04:16AM by 0x414141
via reddit https://ift.tt/4HmbkGC
Analyzing BSD Kernels for Uninitialized Memory Disclosures using Binary Ninja
https://ift.tt/9awGz5T
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/FpDtr91
https://ift.tt/9awGz5T
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/FpDtr91
Zero Day Initiative
Zero Day Initiative — MindShaRE: Analyzing BSD Kernels for Uninitialized Memory Disclosures using Binary Ninja
Disclosure of uninitialized memory is one of the common problems faced when copying data across trust boundaries. This can happen between the hypervisor and guest OS, kernel and user space, or across the network. The most common bug pattern noticed among…
HTTPT: A Probe-Resistant Proxy
https://ift.tt/KQIxqTt
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/3XSDynY
https://ift.tt/KQIxqTt
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/3XSDynY
pizauth, an OAuth2 token requester daemon
https://ift.tt/buRHVax
Submitted October 02, 2022 at 04:13AM by 0x414141
via reddit https://ift.tt/5nYdhSX
https://ift.tt/buRHVax
Submitted October 02, 2022 at 04:13AM by 0x414141
via reddit https://ift.tt/5nYdhSX