Wiresocks for easy proxied routing
https://ift.tt/AOqN6WL
Submitted October 01, 2022 at 07:16AM by sanitybit
via reddit https://ift.tt/YdKqOZD
https://ift.tt/AOqN6WL
Submitted October 01, 2022 at 07:16AM by sanitybit
via reddit https://ift.tt/YdKqOZD
Sensepost
SensePost | Wiresocks for easy proxied routing
Leaders in Information Security
Emulate Shellcode with Radare2
https://ift.tt/xJ4P83j
Submitted October 01, 2022 at 07:11AM by sanitybit
via reddit https://ift.tt/tLrKqYs
https://ift.tt/xJ4P83j
Submitted October 01, 2022 at 07:11AM by sanitybit
via reddit https://ift.tt/tLrKqYs
www.sans.org
Emulate Shellcode with Radare2 | SANS Institute
If you are troubleshooting custom shellcode, you need to work through the instructions patiently and deliberately. This article looks at how to emulate 32-bit ARM shellcode on an x86_64 Ubuntu system.
/r/netsec's Q4 2022 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesOne post per company; it may contain multiple open positions. Please do not use multiple comments to post multiple positions, as the additional comments will be removed.Include the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 01, 2022 at 06:55AM by sanitybit
via reddit https://ift.tt/0ukYd74
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesOne post per company; it may contain multiple open positions. Please do not use multiple comments to post multiple positions, as the additional comments will be removed.Include the company name in the post. If you want to be topsykret, go recruit elsewhere.Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 01, 2022 at 06:55AM by sanitybit
via reddit https://ift.tt/0ukYd74
reddit
reddit.com: search results - "Information Security Hiring Thread"
r/netsec: /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise …
Report on Secure Compilation
https://ift.tt/T05isVe
Submitted October 02, 2022 at 04:17AM by 0x414141
via reddit https://ift.tt/C2Ijbq3
https://ift.tt/T05isVe
Submitted October 02, 2022 at 04:17AM by 0x414141
via reddit https://ift.tt/C2Ijbq3
Tillitis - Open Source USB security key inspired by measured boot and DICE
https://ift.tt/LNa5Smq
Submitted October 02, 2022 at 04:16AM by 0x414141
via reddit https://ift.tt/4HmbkGC
https://ift.tt/LNa5Smq
Submitted October 02, 2022 at 04:16AM by 0x414141
via reddit https://ift.tt/4HmbkGC
Analyzing BSD Kernels for Uninitialized Memory Disclosures using Binary Ninja
https://ift.tt/9awGz5T
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/FpDtr91
https://ift.tt/9awGz5T
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/FpDtr91
Zero Day Initiative
Zero Day Initiative — MindShaRE: Analyzing BSD Kernels for Uninitialized Memory Disclosures using Binary Ninja
Disclosure of uninitialized memory is one of the common problems faced when copying data across trust boundaries. This can happen between the hypervisor and guest OS, kernel and user space, or across the network. The most common bug pattern noticed among…
HTTPT: A Probe-Resistant Proxy
https://ift.tt/KQIxqTt
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/3XSDynY
https://ift.tt/KQIxqTt
Submitted October 02, 2022 at 04:14AM by 0x414141
via reddit https://ift.tt/3XSDynY
pizauth, an OAuth2 token requester daemon
https://ift.tt/buRHVax
Submitted October 02, 2022 at 04:13AM by 0x414141
via reddit https://ift.tt/5nYdhSX
https://ift.tt/buRHVax
Submitted October 02, 2022 at 04:13AM by 0x414141
via reddit https://ift.tt/5nYdhSX
What I learnt from reading 126 Information Disclosure bug reports/writeups.
https://ift.tt/gJPh7CX
Submitted October 02, 2022 at 01:42PM by _nynan
via reddit https://ift.tt/dJfX4MT
https://ift.tt/gJPh7CX
Submitted October 02, 2022 at 01:42PM by _nynan
via reddit https://ift.tt/dJfX4MT
Medium
What I learned from reading 126* Information Disclosure Writeups
Let’s tackle the most valuable and mysterious bug type…
Phishing With Chromium's Application Mode
https://ift.tt/GMF4D7Z
Submitted October 02, 2022 at 02:27PM by CyberMasterV
via reddit https://ift.tt/0jvPshg
https://ift.tt/GMF4D7Z
Submitted October 02, 2022 at 02:27PM by CyberMasterV
via reddit https://ift.tt/0jvPshg
Mrd0X
Security Research | mr.d0x
Providing security research and red team techniques
An updated list of PoC's CVE's
https://ift.tt/HefDA0m
Submitted October 02, 2022 at 04:37PM by DevOpsMuffin39
via reddit https://ift.tt/upQS9m1
https://ift.tt/HefDA0m
Submitted October 02, 2022 at 04:37PM by DevOpsMuffin39
via reddit https://ift.tt/upQS9m1
GitHub
GitHub - tg12/PoC_CVEs: PoC_CVEs
PoC_CVEs. Contribute to tg12/PoC_CVEs development by creating an account on GitHub.
Censys CTF - WriteUp
https://ift.tt/CtoqyM9
Submitted October 02, 2022 at 05:04PM by TechbrunchFR
via reddit https://ift.tt/dGWr4Oh
https://ift.tt/CtoqyM9
Submitted October 02, 2022 at 05:04PM by TechbrunchFR
via reddit https://ift.tt/dGWr4Oh
GitHub - jafarlihi/rconn: rconn is a multiplatform program for creating generic reverse connections. Lets you consume services that are behind firewall or NAT without opening ports or port-forwarding.
https://ift.tt/ZIO95VE
Submitted October 02, 2022 at 08:12PM by jafarlihi
via reddit https://ift.tt/YTlO1PV
https://ift.tt/ZIO95VE
Submitted October 02, 2022 at 08:12PM by jafarlihi
via reddit https://ift.tt/YTlO1PV
GitHub
GitHub - jafarlihi/rconn: rconn is a multiplatform program for creating generic reverse connections. Lets you consume services…
rconn is a multiplatform program for creating generic reverse connections. Lets you consume services that are behind firewall or NAT without opening ports or port-forwarding. - GitHub - jafarlihi/r...
BSides San Francisco 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLbZzXF2qC3RtbIyOKsjYzAN6rIjsKiZCt
Submitted October 03, 2022 at 03:15AM by sanitybit
via reddit https://ift.tt/AOMZdHo
https://www.youtube.com/playlist?list=PLbZzXF2qC3RtbIyOKsjYzAN6rIjsKiZCt
Submitted October 03, 2022 at 03:15AM by sanitybit
via reddit https://ift.tt/AOMZdHo
YouTube
BSidesSF 2022 - YouTube
Passkeys feat. Adam Langley [audio]
https://ift.tt/GpiCwar
Submitted October 03, 2022 at 01:16AM by self
via reddit https://ift.tt/qdQNYGn
https://ift.tt/GpiCwar
Submitted October 03, 2022 at 01:16AM by self
via reddit https://ift.tt/qdQNYGn
Buzzsprout
Passkeys with Adam Langley - Security Cryptography Whatever
Adam Langley (Google) comes on the podcast to talk about the evolution of WebAuthN and Passkeys!David's audio was a little finicky in this one. Believe us, it sounded worse before we edited it. Also, we occasionally accidentally refer to U2F as UTF. That's…
Dank: The greatest encoder you've never heard of
https://ift.tt/Vj8zDox
Submitted October 02, 2022 at 11:10PM by Quick-Ingenuity-7024
via reddit https://ift.tt/P7QuLtZ
https://ift.tt/Vj8zDox
Submitted October 02, 2022 at 11:10PM by Quick-Ingenuity-7024
via reddit https://ift.tt/P7QuLtZ
PS5-4.03-Kernel-Exploit: An experimental webkit-based kernel exploit (Arbitrary R/W) for the PS5 on 4.03FW
https://ift.tt/uF4xLBU
Submitted October 03, 2022 at 05:20AM by sanitybit
via reddit https://ift.tt/Pcz3lwk
https://ift.tt/uF4xLBU
Submitted October 03, 2022 at 05:20AM by sanitybit
via reddit https://ift.tt/Pcz3lwk
GitHub
GitHub - Cryptogenic/PS5-IPV6-Kernel-Exploit: An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW
An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW - GitHub - Cryptogenic/PS5-IPV6-Kernel-Exploit: An experimental webkit-based kernel exploit (Arb. R/W) for the...
SCORES (Seconize Contextual Risk Enumeration System) is a free risk scoring tool for vulnerabilities.
https://riskscore.info/
Submitted October 03, 2022 at 12:58PM by sashankdvk
via reddit https://ift.tt/k6QyFJD
https://riskscore.info/
Submitted October 03, 2022 at 12:58PM by sashankdvk
via reddit https://ift.tt/k6QyFJD
riskscore.info
SCORES: Seconize Contextual Risk Enumeration System
A free cyber risk scoring tool for vulnerabilities
spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.
https://ift.tt/E9vhkMr
Submitted October 03, 2022 at 02:55AM by BananaBounty
via reddit https://ift.tt/U9zPpjK
https://ift.tt/E9vhkMr
Submitted October 03, 2022 at 02:55AM by BananaBounty
via reddit https://ift.tt/U9zPpjK
GitHub
GitHub - dhn/spk: spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.
spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization. - GitHub - dhn/spk: spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong t...
When Athletic Abilities Just Aren't Enough - Scoreboard Hacking Part 3
https://ift.tt/PKhQpDW
Submitted October 03, 2022 at 08:13PM by mdulin2
via reddit https://ift.tt/r5QjGDk
https://ift.tt/PKhQpDW
Submitted October 03, 2022 at 08:13PM by mdulin2
via reddit https://ift.tt/r5QjGDk
Strikeout Security Blog
Scoreboard Hacking - Part 3 - Building a Controller
Scoreboard hacking. Creating our own wireless controller with GNU radio and Python.
Secure your machine learning with Semgrep
https://ift.tt/QM5WnHY
Submitted October 04, 2022 at 05:57AM by Khryse
via reddit https://ift.tt/LBKfgUx
https://ift.tt/QM5WnHY
Submitted October 04, 2022 at 05:57AM by Khryse
via reddit https://ift.tt/LBKfgUx
Trail of Bits Blog
Secure your machine learning with Semgrep
By Suha Hussain tl;dr: Our publicly available Semgrep ruleset now has 11 rules dedicated to the misuse of machine learning libraries. Try it out now! Picture this: You’ve spent months curating imag…