2022 InfoSec Black Friday Deals
https://ift.tt/jMeAgR2
Submitted November 24, 2022 at 01:31PM by Fugitif
via reddit https://ift.tt/2WfXqp0
https://ift.tt/jMeAgR2
Submitted November 24, 2022 at 01:31PM by Fugitif
via reddit https://ift.tt/2WfXqp0
GitHub
GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
All the deals for InfoSec related software/tools this Black Friday - GitHub - 0x90n/InfoSec-Black-Friday: All the deals for InfoSec related software/tools this Black Friday
Sigstore The Easy Way
https://ift.tt/2xOFRqN
Submitted November 24, 2022 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/2i8VaS0
https://ift.tt/2xOFRqN
Submitted November 24, 2022 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/2i8VaS0
Rewanthtammana
Sigstore The Easy Way
Software signing just got easier. Sigstore The Easy Way guide is the most straightforward way to geting started with software signing & securing software supply chains.
Containers: Rootful, Rootless, Privileged and Super Privileged
https://ift.tt/K61PaUt
Submitted November 25, 2022 at 09:12PM by fcano1
via reddit https://ift.tt/zTpGZwL
https://ift.tt/K61PaUt
Submitted November 25, 2022 at 09:12PM by fcano1
via reddit https://ift.tt/zTpGZwL
Exploiting CORS Misconfigurations
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
attack ships on fire
Exploiting CORS Misconfigurations
TL;DR If you can find an unrestricted CORS endpoint, that also responds to the HTTP override headers, then potentially you can use it to access endpoints that aren’t enabled for CORS, bypass CSRF protections, and also deliver an XST (which will give you access…
So, you want to get into bug bounties?
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
Shubham Shah
So, you want to get into bug bounties?
I've been doing bug bounties for over 10 years now and over time, I have grown fonder of the life changing effects it has had for me. From job prospects, to being able to financially support those around me and myself. I believe that if you're passionate…
Exploiting an N-day vBulletin PHP Object Injection Vulnerability
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
Hacking Smartwatches for Spear Phishing – Red Team Ops – Cybervelia
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
Heap_detective is an open-source static analysis tool that finds pitfalls in heap memory usage in C and C++.
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
GitHub
GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
The simple way to detect heap memory pitfalls in C++ and C. Beta. - GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
ransomwhere: a ransomware sample to test out your ransomware response strategy.
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
GitHub
GitHub - hazcod/ransomwhere: A PoC ransomware sample to test out your ransomware response strategy.
A PoC ransomware sample to test out your ransomware response strategy. - hazcod/ransomwhere
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
blog.zapb.de
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
The firmware of microcontrollers usually contains valuable data such as intellectual property and, in some cases, even cryptographic material.
In order to protect the confidentiality of these assets,
In order to protect the confidentiality of these assets,
subzuf – a smart DNS response-guided subdomain fuzzer
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
GitHub
GitHub - elceef/subzuf: a smart DNS response-guided subdomain fuzzer
a smart DNS response-guided subdomain fuzzer. Contribute to elceef/subzuf development by creating an account on GitHub.
Beating Plagiarism Checkers with a Custom Font
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
Medium
Beating Plagiarism Checkers for Science
TLDR; a custom font can be used to avoid a plagiarism checker while still being human readable.
The Art of Bypassing Kerberoast Detections with Orpheus
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
TrustedSec
The Art of Bypassing Kerberoast Detections with Orpheus
Subdomain Enumeration with DNSSEC
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
Systemsecurity
Subdomain Enumeration with DNSSEC
DNSSEC uses resource records like NSEC or NSEC3, which can be leveraged for subdomain enumeration. Different techniques for zone enumeration and countermeasures like White Lies and Black Lies are described in this blog post.
Xiongmai IoT Exploitation
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Looting Microsoft Configuration Manager
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
Withsecure
Looting Microsoft Configuration Manager
Configuration Manager often contain information that could be used by an attacker to find new attack paths or credentials that allow lateral movement.
Need for speed: static analysis version
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
SGX.Fail - Overview of SGX Attacks
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
Reddit
From the netsec community on Reddit: SGX.Fail - Overview of SGX Attacks
Posted by Gallus - 13 votes and 0 comments
Building Policy Gate for DevSecOps using Open Policy Agent
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
Medium
Building Policy Gate for DevSecOps using Open Policy Agent
In our last blog, we detailed our approach to building a continuous application security pipeline with the objective of providing…
Multiversity by @wefuzz_io, a collection of amazing resources for Hackers and Developers to learn, develop, showcase and contribute to the future of Web3 Security
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
multiversity.wefuzz.io
👾 WeFuzz Multiversity | Multiversity
New details on commercial spyware vendor Variston
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
Google
New details on commercial spyware vendor Variston
The Threat Analysis Group shares new information on the commercial spyware vendor Variston.