Exploiting CORS Misconfigurations
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
https://ift.tt/DdZtKfn
Submitted November 26, 2022 at 02:09PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/NQL5XFR
attack ships on fire
Exploiting CORS Misconfigurations
TL;DR If you can find an unrestricted CORS endpoint, that also responds to the HTTP override headers, then potentially you can use it to access endpoints that aren’t enabled for CORS, bypass CSRF protections, and also deliver an XST (which will give you access…
So, you want to get into bug bounties?
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
https://ift.tt/1FgJcEo
Submitted November 26, 2022 at 03:01PM by Mempodipper
via reddit https://ift.tt/JUi4Rem
Shubham Shah
So, you want to get into bug bounties?
I've been doing bug bounties for over 10 years now and over time, I have grown fonder of the life changing effects it has had for me. From job prospects, to being able to financially support those around me and myself. I believe that if you're passionate…
Exploiting an N-day vBulletin PHP Object Injection Vulnerability
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
https://ift.tt/0bJFYQ7
Submitted November 26, 2022 at 10:51PM by eg1x
via reddit https://ift.tt/RxEBYnh
Hacking Smartwatches for Spear Phishing – Red Team Ops – Cybervelia
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
https://ift.tt/ok0a9uR
Submitted November 28, 2022 at 12:21AM by Necessary-Reality-80
via reddit https://ift.tt/gtce1RV
Heap_detective is an open-source static analysis tool that finds pitfalls in heap memory usage in C and C++.
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
https://ift.tt/O3Fa721
Submitted November 28, 2022 at 08:02AM by CoolerVoid
via reddit https://ift.tt/9BHvPNF
GitHub
GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
The simple way to detect heap memory pitfalls in C++ and C. Beta. - GitHub - CoolerVoid/heap_detective: The simple way to detect heap memory pitfalls in C++ and C. Beta.
ransomwhere: a ransomware sample to test out your ransomware response strategy.
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
https://ift.tt/c1o67Ey
Submitted November 28, 2022 at 03:11PM by nindustries
via reddit https://ift.tt/yzC1QrP
GitHub
GitHub - hazcod/ransomwhere: A PoC ransomware sample to test out your ransomware response strategy.
A PoC ransomware sample to test out your ransomware response strategy. - hazcod/ransomwhere
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
https://ift.tt/sTWhvmj
Submitted November 28, 2022 at 08:43PM by Gallus
via reddit https://ift.tt/czlvK3U
blog.zapb.de
Exception(al) Failure - Breaking the STM32F1 Read-Out Protection
The firmware of microcontrollers usually contains valuable data such as intellectual property and, in some cases, even cryptographic material.
In order to protect the confidentiality of these assets,
In order to protect the confidentiality of these assets,
subzuf – a smart DNS response-guided subdomain fuzzer
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
https://ift.tt/6GsbK48
Submitted November 29, 2022 at 12:33AM by feecle
via reddit https://ift.tt/H7AUCpe
GitHub
GitHub - elceef/subzuf: a smart DNS response-guided subdomain fuzzer
a smart DNS response-guided subdomain fuzzer. Contribute to elceef/subzuf development by creating an account on GitHub.
Beating Plagiarism Checkers with a Custom Font
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
https://ift.tt/VFPwE7A
Submitted November 29, 2022 at 05:24AM by Exact-Practice-8658
via reddit https://ift.tt/3WLvq7P
Medium
Beating Plagiarism Checkers for Science
TLDR; a custom font can be used to avoid a plagiarism checker while still being human readable.
The Art of Bypassing Kerberoast Detections with Orpheus
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
https://ift.tt/seRg69H
Submitted November 29, 2022 at 07:14AM by sanitybit
via reddit https://ift.tt/jypN8wV
TrustedSec
The Art of Bypassing Kerberoast Detections with Orpheus
Subdomain Enumeration with DNSSEC
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
https://ift.tt/LOp8X6N
Submitted November 29, 2022 at 06:22PM by doitsukara
via reddit https://ift.tt/iBaw9yl
Systemsecurity
Subdomain Enumeration with DNSSEC
DNSSEC uses resource records like NSEC or NSEC3, which can be leveraged for subdomain enumeration. Different techniques for zone enumeration and countermeasures like White Lies and Black Lies are described in this blog post.
Xiongmai IoT Exploitation
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
https://ift.tt/3txnMOV
Submitted November 30, 2022 at 01:50AM by chicksdigthelongrun
via reddit https://ift.tt/E3C5Mpb
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Looting Microsoft Configuration Manager
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
https://ift.tt/f7bKoRH
Submitted November 30, 2022 at 03:04AM by 1njected
via reddit https://ift.tt/YiuX8wg
Withsecure
Looting Microsoft Configuration Manager
Configuration Manager often contain information that could be used by an attacker to find new attack paths or credentials that allow lateral movement.
Need for speed: static analysis version
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
https://ift.tt/yEB4gfX
Submitted November 30, 2022 at 03:42AM by pabloest
via reddit https://ift.tt/jWgoNTy
semgrep.dev
Semgrep App Security Platform | AI-assisted SAST, SCA and Secrets Detection
An extensible developer-friendly application security platform that scans source code to surface true and actionable security issues with AI-assisted SAST, SCA, and Secrets Detection solutions.
SGX.Fail - Overview of SGX Attacks
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
https://sgx.fail/
Submitted November 30, 2022 at 07:59AM by Gallus
via reddit https://ift.tt/fptIBWk
Reddit
From the netsec community on Reddit: SGX.Fail - Overview of SGX Attacks
Posted by Gallus - 13 votes and 0 comments
Building Policy Gate for DevSecOps using Open Policy Agent
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
https://ift.tt/YtzdUmy
Submitted November 30, 2022 at 03:54PM by nicksthehacker_
via reddit https://ift.tt/9eGjxf8
Medium
Building Policy Gate for DevSecOps using Open Policy Agent
In our last blog, we detailed our approach to building a continuous application security pipeline with the objective of providing…
Multiversity by @wefuzz_io, a collection of amazing resources for Hackers and Developers to learn, develop, showcase and contribute to the future of Web3 Security
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
https://ift.tt/025dgAQ
Submitted November 30, 2022 at 11:49PM by ant4g0nist
via reddit https://ift.tt/xUD2d3z
multiversity.wefuzz.io
👾 WeFuzz Multiversity | Multiversity
New details on commercial spyware vendor Variston
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
https://ift.tt/0mFW4Cg
Submitted November 30, 2022 at 11:36PM by YogiBerra88888
via reddit https://ift.tt/KkmLOeC
Google
New details on commercial spyware vendor Variston
The Threat Analysis Group shares new information on the commercial spyware vendor Variston.
Black Hat USA 2022 Conference Recordings
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
https://www.youtube.com/playlist?list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq
Submitted December 01, 2022 at 05:46AM by sanitybit
via reddit https://ift.tt/mYk64vI
YouTube
Black Hat USA 2022
Share your videos with friends, family, and the world
RFC 8628 lets you phish people even if they're using WebAuthn
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
https://ift.tt/cpNIYLj
Submitted December 01, 2022 at 05:44AM by sanitybit
via reddit https://ift.tt/T2z6uwx
Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328) - SUID-root program installed by default on Ubuntu
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
https://ift.tt/OvQHKgX
Submitted December 01, 2022 at 07:23AM by Gallus
via reddit https://ift.tt/07bJkwg
seclists.org
oss-sec: Race condition in snap-confine's must_mkdir_and_open_with_perms() (CVE-2022-3328)