Integer overflow in xmlParseNameComplex (libxml2) - CVE-2022-40303
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
https://ift.tt/HQM3oam
Submitted November 10, 2022 at 06:54AM by Gallus
via reddit https://ift.tt/tKNgDLh
GitLab
[CVE-2022-40303] Integer overflow in xmlParseNameComplex (#381) · Issues · GNOME / libxml2 · GitLab
Libxml2 is vulnerable to an integer overflow in xmlParseNameComplex when an attribute list has a very long name (name is >= 2**32 characters).
PcapPlusPlus v22.11 released - C++ library for capturing and analyzing network packets
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
https://ift.tt/p4swx3G
Submitted November 10, 2022 at 01:51PM by seladb
via reddit https://ift.tt/ePjYhb6
GitHub
Release November 2022 Release · seladb/PcapPlusPlus
November 2022 release of PcapPlusPlus (v22.11)
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...
This package contains
Binaries compiled for Ubuntu 22.04 LTS, 20.04 LTS, 18.04 LTS
Binaries compiled for CentOS 7
Binaries compiled for Fedora 34
Bin...
Accidental $70k Google Pixel Lock Screen Bypass
https://ift.tt/aZ2PXF6
Submitted November 10, 2022 at 05:37PM by _vavkamil_
via reddit https://ift.tt/SzvjEG7
https://ift.tt/aZ2PXF6
Submitted November 10, 2022 at 05:37PM by _vavkamil_
via reddit https://ift.tt/SzvjEG7
bugs.xdavidhu.me
Accidental $70k Google Pixel Lock Screen Bypass
David Schütz's bug bounty writeups
ATM/Kiosk Hacking - 2022 Payment Village
https://ift.tt/AYMTLbl
Submitted November 10, 2022 at 09:16PM by WiseTuna
via reddit https://ift.tt/VEoB6nu
https://ift.tt/AYMTLbl
Submitted November 10, 2022 at 09:16PM by WiseTuna
via reddit https://ift.tt/VEoB6nu
Boschko Security Blog
ATM/Kiosk Hacking (Reloaded)
Solving the Banking Software & ATM/Kiosk Hacking Challenges from Positive Hack Days 2022 Payment Village
xterm code execution via font ops (CVE-2022-45063)
https://ift.tt/pUEt8Yv
Submitted November 10, 2022 at 11:17PM by Gallus
via reddit https://ift.tt/MGDNl50
https://ift.tt/pUEt8Yv
Submitted November 10, 2022 at 11:17PM by Gallus
via reddit https://ift.tt/MGDNl50
Block web scanners with ipset & iptables
https://ift.tt/mUjxctq
Submitted November 11, 2022 at 06:41AM by jwizq
via reddit https://ift.tt/xp0uZIn
https://ift.tt/mUjxctq
Submitted November 11, 2022 at 06:41AM by jwizq
via reddit https://ift.tt/xp0uZIn
nbailey.ca
Block web scanners with ipset & iptables
Anybody who runs an internet-facing webserver has seen their fair share of spammy scanners in the logs. It varies server to server, but some of mine get up to 15,000 scans per day.
Almost all of these are harmless network mappers, but they still annoy me.…
Almost all of these are harmless network mappers, but they still annoy me.…
Untangling Azure Active Directory Permissions II: Privileged Access
https://ift.tt/jqn5Kis
Submitted November 11, 2022 at 01:26PM by 0xcsandker
via reddit https://ift.tt/NSy5Lmr
https://ift.tt/jqn5Kis
Submitted November 11, 2022 at 01:26PM by 0xcsandker
via reddit https://ift.tt/NSy5Lmr
csandker.io
Untangling Azure Active Directory Permissions II: Privileged Access
I've focused on using my enumeration learnings to automate the process of identifying high privileged principals in an Azure Active Directory Tenant...
NSA guidance on how to protect against software memory safety issues [pdf]
https://ift.tt/RtoUOFv
Submitted November 11, 2022 at 09:47AM by Gallus
via reddit https://ift.tt/8uxneyD
https://ift.tt/RtoUOFv
Submitted November 11, 2022 at 09:47AM by Gallus
via reddit https://ift.tt/8uxneyD
Find & exploit client-side prototype pollution, with labs
https://ift.tt/S0a39rx
Submitted November 11, 2022 at 02:58PM by albinowax
via reddit https://ift.tt/tIcpkN4
https://ift.tt/S0a39rx
Submitted November 11, 2022 at 02:58PM by albinowax
via reddit https://ift.tt/tIcpkN4
portswigger.net
Client-side prototype pollution | Web Security Academy
Prototype pollution is a JavaScript vulnerability that enables an attacker to add arbitrary properties to global prototypes, which may then be inherited by ...
Raccoon Can’t Believe Someone Would Throw Away Perfectly Good Trash
https://ift.tt/MWjomBI
Submitted November 11, 2022 at 07:45PM by hellostella
via reddit https://ift.tt/XIu9e10
https://ift.tt/MWjomBI
Submitted November 11, 2022 at 07:45PM by hellostella
via reddit https://ift.tt/XIu9e10
The Hard Times
Raccoon Can’t Believe Someone Would Throw Away Perfectly Good Trash
A local raccoon known around the neighborhood simply as “that thing in the yard” could not believe someone would throw away a pile of perfectly good garbage.
NETGEAR Nighthawk aws_json Pre-authentication Double Stack Overflow.
https://ift.tt/xNAQMdY
Submitted November 11, 2022 at 04:44PM by luci_morningstart
via reddit https://ift.tt/QuI1Hfc
https://ift.tt/xNAQMdY
Submitted November 11, 2022 at 04:44PM by luci_morningstart
via reddit https://ift.tt/QuI1Hfc
ScrapPY: a Python utility for scraping manuals, documents, and other sensitive PDFs to generate wordlists to perform brute force, forced browsing, and dictionary attacks. Updated with word frequency analysis!
https://ift.tt/mANDqi7
Submitted November 11, 2022 at 05:40PM by Martial-Tartist2
via reddit https://ift.tt/1IEG7pu
https://ift.tt/mANDqi7
Submitted November 11, 2022 at 05:40PM by Martial-Tartist2
via reddit https://ift.tt/1IEG7pu
GitHub
GitHub - RoseSecurity/ScrapPY: ScrapPY is a Python utility for scraping manuals, documents, and other sensitive PDFs to generate…
ScrapPY is a Python utility for scraping manuals, documents, and other sensitive PDFs to generate wordlists that can be utilized by offensive security tools to perform brute force, forced browsing,...
USENIX Security '22 Technical Sessions Talk Recordings
https://ift.tt/ADQYrJq
Submitted November 12, 2022 at 02:42PM by sanitybit
via reddit https://ift.tt/5omClti
https://ift.tt/ADQYrJq
Submitted November 12, 2022 at 02:42PM by sanitybit
via reddit https://ift.tt/5omClti
USENIX
USENIX Security '22 Technical Sessions
USENIX Security brings together researchers, practitioners, system administrators, system programmers, and others to share and explore the latest advances in the security and privacy of computer systems and networks.
Reverse engineering an EV charger
https://ift.tt/HyIfYEo
Submitted November 12, 2022 at 09:42PM by FrankTr3nd
via reddit https://ift.tt/vCEmnYW
https://ift.tt/HyIfYEo
Submitted November 12, 2022 at 09:42PM by FrankTr3nd
via reddit https://ift.tt/vCEmnYW
Mnemonic
Reverse engineering an EV charger
We decided to look into one of the most prevalent chargers on Norwegian roads
Introducing Shufflecake: plausible deniability for multiple hidden filesystems on Linux
https://ift.tt/vixokAX
Submitted November 13, 2022 at 04:36AM by 0xdea
via reddit https://ift.tt/XlCDjAw
https://ift.tt/vixokAX
Submitted November 13, 2022 at 04:36AM by 0xdea
via reddit https://ift.tt/XlCDjAw
Kudelski Security Research
Introducing Shufflecake: plausible deniability for multiple hidden filesystems on Linux
Today we are excited to release Shufflecake, a tool aimed at helping people whose freedom of expression is threatened by repressive authorities or dangerous criminal organizations, in particular: w…
Tunneling Internet through WhatsApp to avoid network restrictions
https://ift.tt/6mStIco
Submitted November 12, 2022 at 07:11AM by aleixrodriala
via reddit https://ift.tt/S5lbqcF
https://ift.tt/6mStIco
Submitted November 12, 2022 at 07:11AM by aleixrodriala
via reddit https://ift.tt/S5lbqcF
GitHub
GitHub - aleixrodriala/wa-tunnel: Tunneling Internet traffic over Whatsapp
Tunneling Internet traffic over Whatsapp. Contribute to aleixrodriala/wa-tunnel development by creating an account on GitHub.
The exploit recon 'msg_msg' and its mitigation in VED
https://ift.tt/9j7ifVt
Submitted November 13, 2022 at 04:32PM by hardenedvault
via reddit https://ift.tt/MFapBKu
https://ift.tt/9j7ifVt
Submitted November 13, 2022 at 04:32PM by hardenedvault
via reddit https://ift.tt/MFapBKu
hardenedvault.net
The exploit recon 'msg_msg' and its mitigation in VED
Why msg_msg? The size of structure is control by userspace Firstly, the length of the msg_msg struct can be indirectly controlled from userspace, which means that msg can overlap the cache of the specified types.
Phishing with Google Calendar and Evilginx2 to Deliver a Malicious Zoom Link
https://ift.tt/vgYUQj9
Submitted November 13, 2022 at 07:59PM by Dr_Mantis_Tobbogon
via reddit https://ift.tt/hkwiWzO
https://ift.tt/vgYUQj9
Submitted November 13, 2022 at 07:59PM by Dr_Mantis_Tobbogon
via reddit https://ift.tt/hkwiWzO
Starlink User Terminal Modchip
https://ift.tt/K8ce7hj
Submitted November 14, 2022 at 08:45AM by Gallus
via reddit https://ift.tt/IxGuqtJ
https://ift.tt/K8ce7hj
Submitted November 14, 2022 at 08:45AM by Gallus
via reddit https://ift.tt/IxGuqtJ
GitHub
GitHub - KULeuven-COSIC/Starlink-FI
Contribute to KULeuven-COSIC/Starlink-FI development by creating an account on GitHub.
Threat and Vulnerability Hunting with Application Server Error Logs
https://ift.tt/uPO57DT
Submitted November 14, 2022 at 02:42PM by SnooDucks7926
via reddit https://ift.tt/35MCbuE
https://ift.tt/uPO57DT
Submitted November 14, 2022 at 02:42PM by SnooDucks7926
via reddit https://ift.tt/35MCbuE
Wix Engineering
Threat and Vulnerability Hunting with Application Server Error Logs
Introduction When doing application security at scale, you have to make peace with the fact that some issues may as well find their way into production. While we work hard to make sure this almost never happens, we understand that it’s just a fact of life…
A Technical Analysis of Royal Ransomware [PDF]
https://ift.tt/37DTGs8
Submitted November 14, 2022 at 08:34PM by CyberMasterV
via reddit https://ift.tt/GnVET7m
https://ift.tt/37DTGs8
Submitted November 14, 2022 at 08:34PM by CyberMasterV
via reddit https://ift.tt/GnVET7m
Security Scorecard
A Technical Analysis Of The Royal Ransomware
This malware encrypts files with the AES algorithm, either fully or partially. The extension of the affected files changes to “.royal”. Find out more in this technical analysis of the Royal Ransomware from SecurityScorecard’s Senior Malware Analyst, Vlad…