Research on Flow Computers Used in Oil and Gas
https://ift.tt/pwYiejN
Submitted November 08, 2022 at 10:30PM by derp6996
via reddit https://ift.tt/9v1y3xW
https://ift.tt/pwYiejN
Submitted November 08, 2022 at 10:30PM by derp6996
via reddit https://ift.tt/9v1y3xW
Claroty
An Oil and Gas Weak Spot: Flow Computers
How to deal with ransomware on Azure
https://ift.tt/N7DuT41
Submitted November 08, 2022 at 11:08PM by MiguelHzBz
via reddit https://ift.tt/ziESCYV
https://ift.tt/N7DuT41
Submitted November 08, 2022 at 11:08PM by MiguelHzBz
via reddit https://ift.tt/ziESCYV
Sysdig
How to deal with ransomware on Azure – Sysdig
Dig deeper into the techniques used by attackers and the mitigations you should implement when ransomware on Azure affects you.
SimpleX Chat: security assessment by Trail of Bits and v4.2 released
https://ift.tt/4mkz87H
Submitted November 08, 2022 at 11:58PM by epoberezkin
via reddit https://ift.tt/CfMkvY9
https://ift.tt/4mkz87H
Submitted November 08, 2022 at 11:58PM by epoberezkin
via reddit https://ift.tt/CfMkvY9
simplex.chat
Security assessment by Trail of Bits, the new website and v4.2 released
SpyGuard:: a forked and enhanced version of TinyCheck. The main objective is to detect signs of compromise by monitoring network flows transmitted by a device.
https://ift.tt/BZv16ST
Submitted November 08, 2022 at 10:49PM by lugh
via reddit https://ift.tt/jPeFum2
https://ift.tt/BZv16ST
Submitted November 08, 2022 at 10:49PM by lugh
via reddit https://ift.tt/jPeFum2
GitHub
GitHub - SpyGuard/SpyGuard: SpyGuard is a forked and enhanced version of TinyCheck. SpyGuard's main objective is to detect signs…
SpyGuard is a forked and enhanced version of TinyCheck. SpyGuard's main objective is to detect signs of compromise by monitoring network flows transmitted by a device. - SpyGuard/SpyGuard
Vulnerabilities in Tenda's W15Ev2 AC1200 Router
https://ift.tt/ZmLrwvM
Submitted November 08, 2022 at 10:57PM by WiseTuna
via reddit https://ift.tt/6FLXR7T
https://ift.tt/ZmLrwvM
Submitted November 08, 2022 at 10:57PM by WiseTuna
via reddit https://ift.tt/6FLXR7T
Boschko Security Blog
Vulnerabilities in Tenda's W15Ev2 AC1200 Router
CVE-2022-40843 CVE-2022-40845 CVE-2022-40847 CVE-2022-40844 CVE-2022-40846 CVE-2022-41395 CVE-2022-41396 CVE-2022-42053 CVE-2022-42058 CVE-2022-42060
Compromising Plesk via its REST API
https://ift.tt/8rfg0lb
Submitted November 09, 2022 at 01:46PM by adrian_rt
via reddit https://ift.tt/AaBH8Md
https://ift.tt/8rfg0lb
Submitted November 09, 2022 at 01:46PM by adrian_rt
via reddit https://ift.tt/AaBH8Md
Cyber Security Services - London
Compromising Plesk via its REST API
Compromising Plesk via its REST API, CSRF, CORS misconfiguration, add db user, add backdoor, add secret token, cookieless CSRF
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
https://ift.tt/ChvIry9
Submitted November 09, 2022 at 02:19PM by CyberMasterV
via reddit https://ift.tt/b52dpSw
https://ift.tt/ChvIry9
Submitted November 09, 2022 at 02:19PM by CyberMasterV
via reddit https://ift.tt/b52dpSw
BREAKDEV
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
Windows ZIP extraction bug (CVE-2022-41049) lets attackers craft ZIP files, which evade warnings on attempts to execute packaged files, even if ZIP file was downloaded from the Internet.
Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)
https://ift.tt/8cGNVix
Submitted November 10, 2022 at 04:17AM by monoimpact
via reddit https://ift.tt/Pioh65R
https://ift.tt/8cGNVix
Submitted November 10, 2022 at 04:17AM by monoimpact
via reddit https://ift.tt/Pioh65R
Sonarsource
Checkmk: Remote Code Execution by Chaining Multiple Bugs (2/3)
The second article of this series outlines how an attacker can leverage the ability to forge arbitrary LQL queries to gain access to the NagVis component.
Write up for the API secure programming challenge that was inspired by the major security incident happened to second largest telco in Australia
https://ift.tt/Sgz9XlH
Submitted November 10, 2022 at 04:52AM by pi3ch
via reddit https://ift.tt/aogmlKI
https://ift.tt/Sgz9XlH
Submitted November 10, 2022 at 04:52AM by pi3ch
via reddit https://ift.tt/aogmlKI
Discuss
Technical analysis of Optus API security challenge - Three must to have API security controls
Tl;dr: Authentication alone could only hide API security weaknesses. Three security controls are required to address the root cause of Optus API secure programming challenge. This article is a technical analysis of nearly 40 submissions that we have received…
Capturing credentials from runZero (formerly Rumble.run) scanners
https://ift.tt/6Xo91y4
Submitted November 10, 2022 at 06:19AM by ss2342-
via reddit https://ift.tt/d6bwYno
https://ift.tt/6Xo91y4
Submitted November 10, 2022 at 06:19AM by ss2342-
via reddit https://ift.tt/d6bwYno
zxsecurity.co.nz
Running a runZero (rumble.run) Rumbler for Zero Dollars - ZX Security
Full spectrum IT security services
Integer overflow in xmlParseNameComplex (libxml2) - CVE-2022-40303
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
GitLab
[CVE-2022-40303] Integer overflow in xmlParseNameComplex (#381) · Issues · GNOME / libxml2 · GitLab
Libxml2 is vulnerable to an integer overflow in xmlParseNameComplex when an attribute list has a very long name (name is >= 2**32 characters).
PcapPlusPlus v22.11 released - C++ library for capturing and analyzing network packets
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
GitHub
Release November 2022 Release · seladb/PcapPlusPlus
November 2022 release of PcapPlusPlus (v22.11)
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...
Accidental $70k Google Pixel Lock Screen Bypass
https://ift.tt/aZ2PXF6
Submitted November 10, 2022 at 05:37PM by _vavkamil_
via reddit https://ift.tt/SzvjEG7
https://ift.tt/aZ2PXF6
Submitted November 10, 2022 at 05:37PM by _vavkamil_
via reddit https://ift.tt/SzvjEG7
bugs.xdavidhu.me
Accidental $70k Google Pixel Lock Screen Bypass
David Schütz's bug bounty writeups
ATM/Kiosk Hacking - 2022 Payment Village
https://ift.tt/AYMTLbl
Submitted November 10, 2022 at 09:16PM by WiseTuna
via reddit https://ift.tt/VEoB6nu
https://ift.tt/AYMTLbl
Submitted November 10, 2022 at 09:16PM by WiseTuna
via reddit https://ift.tt/VEoB6nu
Boschko Security Blog
ATM/Kiosk Hacking (Reloaded)
Solving the Banking Software & ATM/Kiosk Hacking Challenges from Positive Hack Days 2022 Payment Village
xterm code execution via font ops (CVE-2022-45063)
https://ift.tt/pUEt8Yv
Submitted November 10, 2022 at 11:17PM by Gallus
via reddit https://ift.tt/MGDNl50
https://ift.tt/pUEt8Yv
Submitted November 10, 2022 at 11:17PM by Gallus
via reddit https://ift.tt/MGDNl50
Block web scanners with ipset & iptables
https://ift.tt/mUjxctq
Submitted November 11, 2022 at 06:41AM by jwizq
via reddit https://ift.tt/xp0uZIn
https://ift.tt/mUjxctq
Submitted November 11, 2022 at 06:41AM by jwizq
via reddit https://ift.tt/xp0uZIn
nbailey.ca
Block web scanners with ipset & iptables
Anybody who runs an internet-facing webserver has seen their fair share of spammy scanners in the logs. It varies server to server, but some of mine get up to 15,000 scans per day.
Almost all of these are harmless network mappers, but they still annoy me.…
Almost all of these are harmless network mappers, but they still annoy me.…
Untangling Azure Active Directory Permissions II: Privileged Access
https://ift.tt/jqn5Kis
Submitted November 11, 2022 at 01:26PM by 0xcsandker
via reddit https://ift.tt/NSy5Lmr
https://ift.tt/jqn5Kis
Submitted November 11, 2022 at 01:26PM by 0xcsandker
via reddit https://ift.tt/NSy5Lmr
csandker.io
Untangling Azure Active Directory Permissions II: Privileged Access
I've focused on using my enumeration learnings to automate the process of identifying high privileged principals in an Azure Active Directory Tenant...
NSA guidance on how to protect against software memory safety issues [pdf]
https://ift.tt/RtoUOFv
Submitted November 11, 2022 at 09:47AM by Gallus
via reddit https://ift.tt/8uxneyD
https://ift.tt/RtoUOFv
Submitted November 11, 2022 at 09:47AM by Gallus
via reddit https://ift.tt/8uxneyD
Find & exploit client-side prototype pollution, with labs
https://ift.tt/S0a39rx
Submitted November 11, 2022 at 02:58PM by albinowax
via reddit https://ift.tt/tIcpkN4
https://ift.tt/S0a39rx
Submitted November 11, 2022 at 02:58PM by albinowax
via reddit https://ift.tt/tIcpkN4
portswigger.net
Client-side prototype pollution | Web Security Academy
Prototype pollution is a JavaScript vulnerability that enables an attacker to add arbitrary properties to global prototypes, which may then be inherited by ...
Raccoon Can’t Believe Someone Would Throw Away Perfectly Good Trash
https://ift.tt/MWjomBI
Submitted November 11, 2022 at 07:45PM by hellostella
via reddit https://ift.tt/XIu9e10
https://ift.tt/MWjomBI
Submitted November 11, 2022 at 07:45PM by hellostella
via reddit https://ift.tt/XIu9e10
The Hard Times
Raccoon Can’t Believe Someone Would Throw Away Perfectly Good Trash
A local raccoon known around the neighborhood simply as “that thing in the yard” could not believe someone would throw away a pile of perfectly good garbage.
NETGEAR Nighthawk aws_json Pre-authentication Double Stack Overflow.
https://ift.tt/xNAQMdY
Submitted November 11, 2022 at 04:44PM by luci_morningstart
via reddit https://ift.tt/QuI1Hfc
https://ift.tt/xNAQMdY
Submitted November 11, 2022 at 04:44PM by luci_morningstart
via reddit https://ift.tt/QuI1Hfc