Ethernet ghosting & NAC bypass - A practical overview
https://ift.tt/Ry8za7q
Submitted October 27, 2022 at 09:18AM by Gallus
via reddit https://ift.tt/USqp4nc
https://ift.tt/Ry8za7q
Submitted October 27, 2022 at 09:18AM by Gallus
via reddit https://ift.tt/USqp4nc
🪄 wb - A wizard that brings old files from Wayback Machine.
https://ift.tt/cNrGa9K
Submitted October 27, 2022 at 12:38PM by rjz4
via reddit https://ift.tt/S1Rdu0z
https://ift.tt/cNrGa9K
Submitted October 27, 2022 at 12:38PM by rjz4
via reddit https://ift.tt/S1Rdu0z
GitHub
GitHub - riza/wb: Quickly fetches files from Wayback Machine.
Quickly fetches files from Wayback Machine. Contribute to riza/wb development by creating an account on GitHub.
Building a multifunctional red team dropbox for USB and Ethernet attacks
https://ift.tt/jTzcLRq
Submitted October 27, 2022 at 02:50PM by RoganDawes
via reddit https://ift.tt/Kag5nxC
https://ift.tt/jTzcLRq
Submitted October 27, 2022 at 02:50PM by RoganDawes
via reddit https://ift.tt/Kag5nxC
Sensepost
SensePost | Making the perfect red team dropbox (part 1)
Leaders in Information Security
Divin'n'phishin with executable filetypes on Windows
https://ift.tt/lniyuE2
Submitted October 27, 2022 at 03:36PM by ljulolsen
via reddit https://ift.tt/LnXgDG7
https://ift.tt/lniyuE2
Submitted October 27, 2022 at 03:36PM by ljulolsen
via reddit https://ift.tt/LnXgDG7
Rubrique-a-brac
Divin'n'phishin with executable filetypes on Windows
In order to find phishing payloads, one needs to understand how executable filetypes on Windows are handled, finding which ones can be delivered to mail clients, thus users, without being caught by mail defences in between and without requesting multiple…
Visual Studio Code Jupyter Notebook RCE (CVE-2021-26437)
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
https://ift.tt/3ImKWHL
Submitted October 27, 2022 at 06:15PM by nibblesec
via reddit https://ift.tt/IQOrZ5n
Doyensec
Visual Studio Code Jupyter Notebook RCE · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Open source automated Tailscale security best practices benchmark assessment just released by Steampipe.io
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
https://ift.tt/com1XG3
Submitted October 27, 2022 at 08:01PM by stevecio
via reddit https://ift.tt/13HP64j
Steampipe Hub
Tailscale Compliance Mod for Steampipe
Run individual configuration, compliance and security controls or full compliance benchmarks for Tailscale.
control flow unflattening of an android rasp sdk
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
https://ift.tt/9MhZwaj
Submitted October 27, 2022 at 10:30PM by eybisi_
via reddit https://ift.tt/JwX3CIf
hedgehog's cave
Control Flow Unflattening
TargetRecently I have analyzed a RASP solution called Approov. Although there are some novel detection techniques, overall it’s not that interesting. Instead, I will focus on the obfuscation part of
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
https://ift.tt/KIfpqHS
Submitted October 28, 2022 at 12:43AM by karimhabush
via reddit https://ift.tt/RQGFXA7
GitHub
GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.
A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark. - GitHub - karimhabush/cis-vsphere: A tool to assess the compliance of a VMware vSphere environment agains...
Hexacon conference videos
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
https://www.youtube.com/channel/UCtzuVwPhBVFAQnes0NrqxBA/videos
Submitted October 27, 2022 at 05:45PM by gquere
via reddit https://ift.tt/zM6Tdkb
reddit
Hexacon conference videos
Posted in r/netsec by u/gquere • 15 points and 1 comment
OpenSSL: CRITICAL vulnerability will be fixed in upcoming release
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
https://ift.tt/0cqfOsT
Submitted October 26, 2022 at 04:57PM by josephnoir
via reddit https://ift.tt/lMDXWOy
Towards the next generation of XNU memory safety: kalloc_type
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
https://ift.tt/Tw5x9zD
Submitted October 28, 2022 at 02:29AM by sanitybit
via reddit https://ift.tt/ACXzjnJ
Blog - Towards the next generation of XNU memory safety: kalloc_type - Apple Security Research
Improving software memory safety is a key security objective for engineering teams across the industry. Here we begin a journey into the XNU kernel at the core of iOS and explore the intricate work our engineering teams have done to harden the memory allocator…
One-Time Programs
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
https://ift.tt/vey3IYW
Submitted October 28, 2022 at 12:17AM by feross
via reddit https://ift.tt/qW9iYSN
A Few Thoughts on Cryptographic Engineering
One-Time Programs
One of the things I like to do on this blog is write about new research that has a practical angle. Most of the time (I swear) this involves writing about other folks’ research: it’s no…
TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis
https://ift.tt/PA5RrJh
Submitted October 28, 2022 at 09:04AM by sanitybit
via reddit https://ift.tt/lo2qpXd
https://ift.tt/PA5RrJh
Submitted October 28, 2022 at 09:04AM by sanitybit
via reddit https://ift.tt/lo2qpXd
Medium
Analysis and Summary of TCP/IP Protocol Remote Code Execution Vulnerability CVE-2022–34718
An Analysis of Remote Code Execution Vulnerability CVE-2022–34718
Spartacus DLL Hijacking Discovery Tool - "all in one"
https://ift.tt/eIKawur
Submitted October 28, 2022 at 06:54PM by h0wlett
via reddit https://ift.tt/5ZctT1w
https://ift.tt/eIKawur
Submitted October 28, 2022 at 06:54PM by h0wlett
via reddit https://ift.tt/5ZctT1w
GitHub
GitHub - Accenture/Spartacus: Spartacus DLL Hijacking Discovery Tool
Spartacus DLL Hijacking Discovery Tool. Contribute to Accenture/Spartacus development by creating an account on GitHub.
EDR: Detections, Bypassess and other Shenanigans
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
https://ift.tt/becG4tZ
Submitted October 28, 2022 at 08:21PM by sciencestudent99
via reddit https://ift.tt/ukRp4SW
FourCore
EDR: Detections, Bypassess and other Shenanigans
EDR or Endpoint Detection and Response refers to an integrated endpoint security solution which continuously monitors end-point user's devices and try to prevent anomalies like Malware, Ransomware by using automated rule based response method.
Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
https://ift.tt/mFelc15
Submitted October 28, 2022 at 11:26PM by Khryse
via reddit https://ift.tt/o6w0IRf
PortSwigger Blog
Free: Dastardly from Burp Suite
Introducing Dastardly - a free, lightweight web application security scanner for your CI/CD pipeline, from the makers of Burp Suite. Secure web development ain't easy Ensuring your code is written sec
Hardware Trojans Under a Microscope
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
https://ift.tt/kYjhuLM
Submitted October 28, 2022 at 06:49AM by Ryancor
via reddit https://ift.tt/PjHNq34
Medium
Hardware Trojans Under a Microscope
Table of Contents
CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities – Blog
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
https://ift.tt/lJZA2DB
Submitted October 28, 2022 at 10:58PM by spacedust65
via reddit https://ift.tt/SXUl1Fx
A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing remote attackers to trigger a remote command execution in the phone.
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
https://ift.tt/Q0Fh4r8
Submitted October 27, 2022 at 06:58PM by SSDisclosure
via reddit https://ift.tt/toqHUJx
SSD Secure Disclosure
SSD Advisory – Galaxy Store Applications Installation/Launching without User Interaction - SSD Secure Disclosure
TL;DR A vulnerability in the Galaxy Store allows attackers through an XSS to cause the store to install and/or launch an application, allowing […]
Australian organisations under increasing attack - Medibank and Optus were just part of an overall 81% increase in targeting
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
https://ift.tt/ZtHVUJb
Submitted October 29, 2022 at 12:28AM by SuaveHobo
via reddit https://ift.tt/ngXYr3B
Substack
Australia in the Crosshairs
Preparing for increasing cyber attacks and enhanced regulatory obligations
Passkeys as a tool for user retention
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
https://ift.tt/162IzvA
Submitted October 29, 2022 at 01:22AM by Khryse
via reddit https://ift.tt/CHvnqgG
Mat Duggan
Passkeys as a tool for user retention
With the release of iOS 16 and MacOS Ventura, we are now in the age of passkeys. This is happening through WebAuthn, a specification written by the W3C and FIDO with the involvement of all of the major vendors such as Google, Mozilla, etc. The basic premise…