Precious Gemstones: The New Generation of Kerberos Attacks
https://ift.tt/g4OoTv8
Submitted December 13, 2022 at 11:47AM by 0xdea
via reddit https://ift.tt/fG62uxn
https://ift.tt/g4OoTv8
Submitted December 13, 2022 at 11:47AM by 0xdea
via reddit https://ift.tt/fG62uxn
Unit 42
Precious Gemstones: The New Generation of Kerberos Attacks
Unit 42 researchers show new methods to improve detection of a next-gen line of Kerberos attacks, which allow attackers to modify Kerberos tickets to maintain privileged access.
An Open Source tool for Fixing the Accidental Public GitHub Repo
https://ift.tt/PN97OuX
Submitted December 13, 2022 at 01:31PM by amirshk
via reddit https://ift.tt/W6Tzetm
https://ift.tt/PN97OuX
Submitted December 13, 2022 at 01:31PM by amirshk
via reddit https://ift.tt/W6Tzetm
Medium
Exposed Repository: Fixing the Accidental Public GitHub Repo
TL;DR The open-source GitHub App https://github.com/PerimeterX/gitapp_alert_on_public
Pass The eWPT Exam on Your First Attempt Using Free Resources!
https://ift.tt/fJ3dV0Z
Submitted December 13, 2022 at 02:11PM by grumpzsux
via reddit https://ift.tt/MOqA8Du
https://ift.tt/fJ3dV0Z
Submitted December 13, 2022 at 02:11PM by grumpzsux
via reddit https://ift.tt/MOqA8Du
Wannabe Bug Bounty Hunter.
Pass the eWPT Exam in 2023 Using Free Resources
Pass the eWPT Exam by eLearnSecurity in 2023 using only free resources, on your first attempt. Use the same resources I used to be successful.
Exploiting CVE-2022-42703 - Bringing back the stack attack
https://ift.tt/BaGFQVl
Submitted December 13, 2022 at 09:35AM by boutnaru
via reddit https://ift.tt/LMedT5D
https://ift.tt/BaGFQVl
Submitted December 13, 2022 at 09:35AM by boutnaru
via reddit https://ift.tt/LMedT5D
Blogspot
Exploiting CVE-2022-42703 - Bringing back the stack attack
Seth Jenkins, Project Zero This blog post details an exploit for CVE-2022-42703 (P0 issue 2351 - Fixed 5 September 2022), a bug Jann Horn ...
A Server Side Request Forgery protection library for Golang
https://ift.tt/x0sLc4p
Submitted December 13, 2022 at 07:22PM by nibblesec
via reddit https://ift.tt/FgWa0VE
https://ift.tt/x0sLc4p
Submitted December 13, 2022 at 07:22PM by nibblesec
via reddit https://ift.tt/FgWa0VE
Doyensec
safeurl for Go · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Critical Citrix ADC Bug Exploited in the Wild
https://ift.tt/XQN5jGS
Submitted December 13, 2022 at 07:07PM by YogiBerra88888
via reddit https://ift.tt/NITJpLE
https://ift.tt/XQN5jGS
Submitted December 13, 2022 at 07:07PM by YogiBerra88888
via reddit https://ift.tt/NITJpLE
Citrix Blogs
Released: Citrix ADC and Citrix Gateway (security bulletin CTX474995) security update | Citrix Blogs
Learn about security updates for versions 12.1 (including FIPS and NDcPP) and 13.0 before 13.0-58.32 of Citrix ADC and Citrix Gateway and get fixes for both (security bulletin CTX474995).
A Deep Dive into BianLian Ransomware [PDF]
https://ift.tt/2ePO0bz
Submitted December 13, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/JochqWx
https://ift.tt/2ePO0bz
Submitted December 13, 2022 at 08:30PM by CyberMasterV
via reddit https://ift.tt/JochqWx
SecurityScorecard
Resources
Explore cybersecurity white papers, data sheets, webinars, videos, informative blogs, and more with SecurityScorecard.
AWS ECR Public Vulnerability
https://ift.tt/9voLzjP
Submitted December 13, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/V937Wt4
https://ift.tt/9voLzjP
Submitted December 13, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/V937Wt4
blog.lightspin.io
AWS ECR Public Vulnerability
Let's go over a critical AWS Elastic Container Registry Public (ECR Public) vulnerability that allowed external actors to delete, update, and create ECR Public images, layers, and tags in registries and repositories that belong to other AWS Accounts, by abusing…
Sandworm.JS - dynamically analyses over 2M javanoscript packages to offer zero day, real time protection against malicious noscripts.
https://sandworm.dev
Submitted December 14, 2022 at 12:32AM by sculabobone
via reddit https://ift.tt/T0bQuHW
https://sandworm.dev
Submitted December 14, 2022 at 12:32AM by sculabobone
via reddit https://ift.tt/T0bQuHW
Reddit
r/netsec - Sandworm.JS - dynamically analyses over 2M javanoscript packages to offer zero day, real time protection against malicious…
73 votes and 4 comments so far on Reddit
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK.
https://ift.tt/1EvINpU
Submitted December 14, 2022 at 03:45AM by FipoKa
via reddit https://ift.tt/Zw5ltkj
https://ift.tt/1EvINpU
Submitted December 14, 2022 at 03:45AM by FipoKa
via reddit https://ift.tt/Zw5ltkj
GitHub
GitHub - ax/apk.sh: apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding…
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK. - GitHub - ax/apk.sh: apk.sh makes reverse engineering...
breaking chatgpt's "woke filter"
https://ift.tt/TB0OxVz
Submitted December 14, 2022 at 07:42AM by endless
via reddit https://ift.tt/HvmEqIc
https://ift.tt/TB0OxVz
Submitted December 14, 2022 at 07:42AM by endless
via reddit https://ift.tt/HvmEqIc
Livejournal
breaking chatgpt's woke filter
so i had to crack my way into public information, controversial topics and statistics on chatgpt. if you haven't noticed, there's a woke filter. while chatgpt claims to be programmatically incapable of political correctness, that is not the case at all. but…
Vulnerabilities found on Arcadyan Routers
https://ift.tt/GyPC4JS
Submitted December 14, 2022 at 08:37AM by asherdl02
via reddit https://ift.tt/OYLatGz
https://ift.tt/GyPC4JS
Submitted December 14, 2022 at 08:37AM by asherdl02
via reddit https://ift.tt/OYLatGz
Gist
Vulnerabilities found on Arcadyan Routers - Asher Davila L.
Vulnerabilities found on Arcadyan Routers - Asher Davila L. - Arcadyan Vulnerabilities.md
Coercer: A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
https://ift.tt/bZzH1tg
Submitted December 14, 2022 at 01:29PM by boutnaru
via reddit https://ift.tt/kjEHq1p
https://ift.tt/bZzH1tg
Submitted December 14, 2022 at 01:29PM by boutnaru
via reddit https://ift.tt/kjEHq1p
GitHub
GitHub - p0dalirius/Coercer: A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through…
A python noscript to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods. - GitHub - p0dalirius/Coercer: A python noscript to automatically coerce a Windows...
Hacking the MBTA CharlieCard from 2008 to Present
https://ift.tt/6NCjZ1E
Submitted December 14, 2022 at 06:18PM by _zio_pane
via reddit https://ift.tt/7vuTBZK
https://ift.tt/6NCjZ1E
Submitted December 14, 2022 at 06:18PM by _zio_pane
via reddit https://ift.tt/7vuTBZK
Medium
Operation Charlie: Hacking the MBTA CharlieCard from 2008 to Present
June 2023 Update — Hardwear.io Conference Talk:
Technical Review: A Deep Analysis of the Dirty Pipe Vulnerability
https://ift.tt/I41MN0i
Submitted December 14, 2022 at 07:52PM by gfdgfbal
via reddit https://ift.tt/ySgTPmv
https://ift.tt/I41MN0i
Submitted December 14, 2022 at 07:52PM by gfdgfbal
via reddit https://ift.tt/ySgTPmv
Aquasec
Technical Review: A Deep Analysis of the Dirty Pipe Vulnerability
Aqua discusses how Tracee monitors for the Dirty Pipe vulnerability and how in-kernel technology like eBPF monitors writes that result from it
Unusual Cache Poisoning between Akamai and S3 buckets
https://ift.tt/2C7ltb3
Submitted December 14, 2022 at 08:59PM by albinowax
via reddit https://ift.tt/rpXSIoi
https://ift.tt/2C7ltb3
Submitted December 14, 2022 at 08:59PM by albinowax
via reddit https://ift.tt/rpXSIoi
A nice step-by-step framework for improving tenant isolation in the cloud — written by a global group of cloud security researchers
http://peach.wiz.io
Submitted December 14, 2022 at 09:51PM by Hot_Elevator_5750
via reddit https://ift.tt/invoYPL
http://peach.wiz.io
Submitted December 14, 2022 at 09:51PM by Hot_Elevator_5750
via reddit https://ift.tt/invoYPL
Peach Framework
PEACH - Tenant Isolation Framework for Cloud Apps
Mitigate the risk of isolation escape with a new framework for modeling and improving tenant isolation in cloud SaaS and PaaS.
FRESH from Black Hat EU: Dirty Vanity, the windows-fork based injection method is public
https://ift.tt/QjkzMSK
Submitted December 14, 2022 at 04:31PM by LezG00
via reddit https://ift.tt/ymOaSg1
https://ift.tt/QjkzMSK
Submitted December 14, 2022 at 04:31PM by LezG00
via reddit https://ift.tt/ymOaSg1
GitHub
GitHub - deepinstinct/Dirty-Vanity: A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www…
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass...
How NOT to patch Integer Overflow in JavaScript - Technical analysis of over 50 community submissions
https://ift.tt/r2gMP96
Submitted December 15, 2022 at 09:07AM by pi3ch
via reddit https://ift.tt/iJY7sFp
https://ift.tt/r2gMP96
Submitted December 15, 2022 at 09:07AM by pi3ch
via reddit https://ift.tt/iJY7sFp
Discuss
Write up for Start Here.js: How To and Not To Prevent Integer Overflow in JavaScript
Tl;dr : This article is analysis of over 50 submissions for a JavaScript integer overflow challenge. Many submissions did not address the root cause. A range check on the input as well as arithmetic output using a right data type can eliminate the vulnerability.…
BSidesSF 2023 Call For Presentations, Workshops, and Villages
https://ift.tt/RexzOwS
Submitted December 15, 2022 at 11:12AM by reedloden
via reddit https://ift.tt/c1E5P0n
https://ift.tt/RexzOwS
Submitted December 15, 2022 at 11:12AM by reedloden
via reddit https://ift.tt/c1E5P0n
BSidesSF
BSidesSF 2023 Call For Participation
Talks/WorkshopsThe BSidesSF 2023 CFP is now closed. Check back for updated deadlines for accepted presenters. January 24, 2023 – Notifications on talk/workshop acceptance/rejection start bei...
PyPI malware creators starting to employ Anti-Debug techniques
https://ift.tt/ZFV5E7M
Submitted December 15, 2022 at 01:22PM by SRMish3
via reddit https://ift.tt/Thg60eY
https://ift.tt/ZFV5E7M
Submitted December 15, 2022 at 01:22PM by SRMish3
via reddit https://ift.tt/Thg60eY
JFrog
Python Malware Starting to Employ Anti-Debug Techniques
First time anti-debug techniques are discovered in PyPI malware. Read how these techniques are implemented, including analysis and tips from JFrog Security Research.