Pre-Auth RCE with CodeQL in Under 20 Minutes
https://ift.tt/FoGYOzv
Submitted December 03, 2022 at 06:19PM by Gallus
via reddit https://ift.tt/gj1CAKU
https://ift.tt/FoGYOzv
Submitted December 03, 2022 at 06:19PM by Gallus
via reddit https://ift.tt/gj1CAKU
Frycos Security Diary
Pre-Auth RCE with CodeQL in Under 20 Minutes
This write-up won’t be an intense discussion on security code review techniques this time. We’ll simply let do all the hard work by a third party: CodeQL.
[KIS-2022-06] Drupal H5P Module <= 2.0.0 (isValidPackage) Zip Slip Vulnerability
https://ift.tt/vbXEA8L
Submitted December 03, 2022 at 08:12PM by eg1x
via reddit https://ift.tt/uoPx2Gp
https://ift.tt/vbXEA8L
Submitted December 03, 2022 at 08:12PM by eg1x
via reddit https://ift.tt/uoPx2Gp
GitHub Actions - Artifact Poisoning Vulnerability
https://ift.tt/JGHP6lW
Submitted December 04, 2022 at 09:39PM by dotanoam
via reddit https://ift.tt/8O3nhNa
https://ift.tt/JGHP6lW
Submitted December 04, 2022 at 09:39PM by dotanoam
via reddit https://ift.tt/8O3nhNa
Legitsecurity
Novel Pipeline Vulnerability Discovered; Rust Found Vulnerable
New software supply chain vulnerabilities use artifact poisoning and attack the software development pipelines on projects using GitHub Actions.
OWASP Top 10 CI/CD Security Risks project released
https://ift.tt/oliaeAh
Submitted December 05, 2022 at 01:56AM by Hefty_Knowledge_7449
via reddit https://ift.tt/KeLNiyp
https://ift.tt/oliaeAh
Submitted December 05, 2022 at 01:56AM by Hefty_Knowledge_7449
via reddit https://ift.tt/KeLNiyp
owasp.org
OWASP Top 10 CI/CD Security Risks | OWASP Foundation
OWASP Top 10 CI/CD Security Risks on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to improve the security of software.
“In startups, your junior dev is more of a threat to security than North Korea.” Appreciate a security expert who knows startups shouldn't waste resources overdoing security when they still don't have product-market fit.
https://ift.tt/NXIF5ku
Submitted December 05, 2022 at 06:24AM by maddening_conversati
via reddit https://ift.tt/gVZhw5j
https://ift.tt/NXIF5ku
Submitted December 05, 2022 at 06:24AM by maddening_conversati
via reddit https://ift.tt/gVZhw5j
Dev Interrupted
Why Startups Suck at Security w/ Vanta's Head of Engineering, Matt Spitz
When your startup is struggling to find its product-market fit, security is the last thing on your mind - and according to security expert Matt Spitz, that’s perfectly fine! Matt is Vanta's Head of Engineering and he joins this week's episode of Dev Interrupted…
Slides: Demystifying Practical DoS Attacks
https://ift.tt/FYV3MSe
Submitted December 05, 2022 at 12:18PM by mazen160
via reddit https://ift.tt/1H5ET7y
https://ift.tt/FYV3MSe
Submitted December 05, 2022 at 12:18PM by mazen160
via reddit https://ift.tt/1H5ET7y
Mazin Ahmed
DoS Attacks are Dead: Demystifying Practical DoS Attacks
DoS Attacks are Dead: Demystifying Practical DoS Attacks.
Release of EMBA firmware analyzer in version 1.2.0 - aka London Calling
https://ift.tt/RgaUdDv
Submitted December 05, 2022 at 06:57PM by _m-1-k-3_
via reddit https://ift.tt/VwDRepW
https://ift.tt/RgaUdDv
Submitted December 05, 2022 at 06:57PM by _m-1-k-3_
via reddit https://ift.tt/VwDRepW
GitHub
Release EMBA v1.2.0 - London Calling · e-m-b-a/emba
Beside bug fixes this release introduces many new features. You are invited to celebrate the new EMBA version with us.
Spread the word and secure the Internet of Things with EMBA!
Since versio...
Spread the word and secure the Internet of Things with EMBA!
Since versio...
A Detailed Analysis of The Last Version of REvil Ransomware [PDF]
https://ift.tt/aBqiN7P
Submitted December 05, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/YgfD59K
https://ift.tt/aBqiN7P
Submitted December 05, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/YgfD59K
Security Scorecard
A Detailed Analysis Of The Last Version Of R Evil Ransomware
Default NETGEAR Router Configuration Allows Attacks from WAN
https://ift.tt/O4eptul
Submitted December 05, 2022 at 10:52PM by dinobyt3s
via reddit https://ift.tt/RQkB5ws
https://ift.tt/O4eptul
Submitted December 05, 2022 at 10:52PM by dinobyt3s
via reddit https://ift.tt/RQkB5ws
Medium
NETGEAR Router Network Misconfiguration
Last Minute Patch Thwarts Pwn2Own Entries
Hijacking GitHub Repositories by Deleting and Restoring Them
https://ift.tt/UwgFvjO
Submitted December 05, 2022 at 10:30PM by whisperingmime
via reddit https://ift.tt/5QHWuoO
https://ift.tt/UwgFvjO
Submitted December 05, 2022 at 10:30PM by whisperingmime
via reddit https://ift.tt/5QHWuoO
Blog by Joren Vrancken
Hijacking GitHub Repositories by Deleting and Restoring Them
Recently, we encountered an obscure security measure while researching GitHub repositories: the popular repository namespace retirement. This security measure was implemented by GitHub to protect (popular) repositories against repo jacking (i.e. hijacking…
[Help] I'm looking for a downloadable list of all CVEs including vulnerability
https://ift.tt/3E4PVUC
Submitted December 06, 2022 at 04:00AM by much_thanks
via reddit https://ift.tt/F8mfKxQ
https://ift.tt/3E4PVUC
Submitted December 06, 2022 at 04:00AM by much_thanks
via reddit https://ift.tt/F8mfKxQ
cve.mitre.org
CVE -
Download CVE List
Download CVE List
The mission of the CVE® Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities.
Moobot Uses a Fake Vulnerability
https://ift.tt/3DKiMT2
Submitted December 06, 2022 at 07:52PM by chicksdigthelongrun
via reddit https://ift.tt/uaT9YZi
https://ift.tt/3DKiMT2
Submitted December 06, 2022 at 07:52PM by chicksdigthelongrun
via reddit https://ift.tt/uaT9YZi
VulnCheck
Moobot Uses a Fake Vulnerability - Blog - VulnCheck
An investigation into CVE-2022-28958 finds the vulnerability doesn't actually exist.
The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022
https://ift.tt/vzwsCtW
Submitted December 06, 2022 at 08:21PM by Gallus
via reddit https://ift.tt/Dqv9NcF
https://ift.tt/vzwsCtW
Submitted December 06, 2022 at 08:21PM by Gallus
via reddit https://ift.tt/Dqv9NcF
STAR Labs
The Last Breath of Our Netgear RAX30 Bugs - A Tragic Tale before Pwn2Own Toronto 2022
Background Some time ago, we were playing with some Netgear routers and we learned so much from this target.
However, Netgear recently patched several vulnerabilities in their RAX30 router firmware, including the two vulnerabilities in the DHCP interface…
However, Netgear recently patched several vulnerabilities in their RAX30 router firmware, including the two vulnerabilities in the DHCP interface…
An open source SMS gateway for pentest projects
https://ift.tt/vNmDwKb
Submitted December 07, 2022 at 02:55AM by aunga
via reddit https://ift.tt/gDWXiYF
https://ift.tt/vNmDwKb
Submitted December 07, 2022 at 02:55AM by aunga
via reddit https://ift.tt/gDWXiYF
Pentagrid AG
An open source SMS gateway for pentest projects
We publish an open source Python-based server for sending and especially receiving SMS using multiple GSM modems and SIM cards, which helps us in pentesting projects, but also for alerting system moni
RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass
https://ift.tt/iJLpbhS
Submitted December 07, 2022 at 08:01AM by Gallus
via reddit https://ift.tt/FHgo8bO
https://ift.tt/iJLpbhS
Submitted December 07, 2022 at 08:01AM by Gallus
via reddit https://ift.tt/FHgo8bO
h1pmnh.github.io
Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass
Writeup of a collaborated bug on Bugcrowd where I was able to bypass Akamai WAF to exploit RCE on Spring Boot error page using SpEL
PyPI-distributed malicious package campagin tying into GitHub accounts and embedded into repos to disguise its intention - FULL ANALYSIS
https://ift.tt/vZe3R0u
Submitted December 07, 2022 at 09:05PM by dalmoz
via reddit https://ift.tt/7tMuU3J
https://ift.tt/vZe3R0u
Submitted December 07, 2022 at 09:05PM by dalmoz
via reddit https://ift.tt/7tMuU3J
Apiiro | Secure your development and delivery to the cloud
Apiiro’s AI engine detected a software supply chain attack in PyPI
The Apiiro AI engine discovered a malicious Python package that is currently presented on the python PyPI package management portal.
Firewalls under the hood - UFW
https://ift.tt/iFPdK6S
Submitted December 08, 2022 at 04:02AM by doitsukara
via reddit https://ift.tt/5DTfyxH
https://ift.tt/iFPdK6S
Submitted December 08, 2022 at 04:02AM by doitsukara
via reddit https://ift.tt/5DTfyxH
blog.kanbach.org
Firewalls under the hood - UFW
IT-Security and stuff - Firewalls under the hood - UFW
GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a TRUE call stack spoofer
https://ift.tt/l3mOZoa
Submitted December 08, 2022 at 03:24PM by R3dCr0wn
via reddit https://ift.tt/gvCJrlj
https://ift.tt/l3mOZoa
Submitted December 08, 2022 at 03:24PM by R3dCr0wn
via reddit https://ift.tt/gvCJrlj
GitHub
GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a fully dynamic call stack spoofer
PoC Implementation of a fully dynamic call stack spoofer - GitHub - klezVirus/SilentMoonwalk: PoC Implementation of a fully dynamic call stack spoofer
Shoggoth
https://ift.tt/iM4gyEA
Submitted December 08, 2022 at 06:30PM by DarkGrejuva
via reddit https://ift.tt/SXavVkh
https://ift.tt/iM4gyEA
Submitted December 08, 2022 at 06:30PM by DarkGrejuva
via reddit https://ift.tt/SXavVkh
GitHub
GitHub - frkngksl/Shoggoth: Shoggoth: Asmjit Based Polymorphic Encryptor
Shoggoth: Asmjit Based Polymorphic Encryptor. Contribute to frkngksl/Shoggoth development by creating an account on GitHub.
cli google search client written by chatgpt ai - bypasses captcha and rate limiting
https://ift.tt/IyY3E5e
Submitted December 08, 2022 at 07:59PM by endless
via reddit https://ift.tt/pgSm7qt
https://ift.tt/IyY3E5e
Submitted December 08, 2022 at 07:59PM by endless
via reddit https://ift.tt/pgSm7qt
GitHub
GitHub - visualbasic6/search: a cli google client written by ai (chatgpt) that bypasses captcha and rate limiting by using the…
a cli google client written by ai (chatgpt) that bypasses captcha and rate limiting by using the google alert's "preview" feature - GitHub - visualbasic6/search: a cli goo...
How to secure your Open Source Project – A quick guide for developers
https://ift.tt/JuLsBlx
Submitted December 08, 2022 at 09:18PM by TupleType1
via reddit https://ift.tt/XJgksaR
https://ift.tt/JuLsBlx
Submitted December 08, 2022 at 09:18PM by TupleType1
via reddit https://ift.tt/XJgksaR
Cider Security Site
“How to secure your Open Source Project - A quick guide for developers”.
Check out our latest blog post: “How to secure your Open Source Project - A quick guide for developers”. This post provides valuable guidance on how to ensure the security of your open source project. We will be sharing some practical tips and best practices…