Hacking the MBTA CharlieCard from 2008 to Present
https://ift.tt/6NCjZ1E
Submitted December 14, 2022 at 06:18PM by _zio_pane
via reddit https://ift.tt/7vuTBZK
https://ift.tt/6NCjZ1E
Submitted December 14, 2022 at 06:18PM by _zio_pane
via reddit https://ift.tt/7vuTBZK
Medium
Operation Charlie: Hacking the MBTA CharlieCard from 2008 to Present
June 2023 Update — Hardwear.io Conference Talk:
Technical Review: A Deep Analysis of the Dirty Pipe Vulnerability
https://ift.tt/I41MN0i
Submitted December 14, 2022 at 07:52PM by gfdgfbal
via reddit https://ift.tt/ySgTPmv
https://ift.tt/I41MN0i
Submitted December 14, 2022 at 07:52PM by gfdgfbal
via reddit https://ift.tt/ySgTPmv
Aquasec
Technical Review: A Deep Analysis of the Dirty Pipe Vulnerability
Aqua discusses how Tracee monitors for the Dirty Pipe vulnerability and how in-kernel technology like eBPF monitors writes that result from it
Unusual Cache Poisoning between Akamai and S3 buckets
https://ift.tt/2C7ltb3
Submitted December 14, 2022 at 08:59PM by albinowax
via reddit https://ift.tt/rpXSIoi
https://ift.tt/2C7ltb3
Submitted December 14, 2022 at 08:59PM by albinowax
via reddit https://ift.tt/rpXSIoi
A nice step-by-step framework for improving tenant isolation in the cloud — written by a global group of cloud security researchers
http://peach.wiz.io
Submitted December 14, 2022 at 09:51PM by Hot_Elevator_5750
via reddit https://ift.tt/invoYPL
http://peach.wiz.io
Submitted December 14, 2022 at 09:51PM by Hot_Elevator_5750
via reddit https://ift.tt/invoYPL
Peach Framework
PEACH - Tenant Isolation Framework for Cloud Apps
Mitigate the risk of isolation escape with a new framework for modeling and improving tenant isolation in cloud SaaS and PaaS.
FRESH from Black Hat EU: Dirty Vanity, the windows-fork based injection method is public
https://ift.tt/QjkzMSK
Submitted December 14, 2022 at 04:31PM by LezG00
via reddit https://ift.tt/ymOaSg1
https://ift.tt/QjkzMSK
Submitted December 14, 2022 at 04:31PM by LezG00
via reddit https://ift.tt/ymOaSg1
GitHub
GitHub - deepinstinct/Dirty-Vanity: A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www…
A POC for the new injection technique, abusing windows fork API to evade EDRs. https://www.blackhat.com/eu-22/briefings/schedule/index.html#dirty-vanity-a-new-approach-to-code-injection--edr-bypass...
How NOT to patch Integer Overflow in JavaScript - Technical analysis of over 50 community submissions
https://ift.tt/r2gMP96
Submitted December 15, 2022 at 09:07AM by pi3ch
via reddit https://ift.tt/iJY7sFp
https://ift.tt/r2gMP96
Submitted December 15, 2022 at 09:07AM by pi3ch
via reddit https://ift.tt/iJY7sFp
Discuss
Write up for Start Here.js: How To and Not To Prevent Integer Overflow in JavaScript
Tl;dr : This article is analysis of over 50 submissions for a JavaScript integer overflow challenge. Many submissions did not address the root cause. A range check on the input as well as arithmetic output using a right data type can eliminate the vulnerability.…
BSidesSF 2023 Call For Presentations, Workshops, and Villages
https://ift.tt/RexzOwS
Submitted December 15, 2022 at 11:12AM by reedloden
via reddit https://ift.tt/c1E5P0n
https://ift.tt/RexzOwS
Submitted December 15, 2022 at 11:12AM by reedloden
via reddit https://ift.tt/c1E5P0n
BSidesSF
BSidesSF 2023 Call For Participation
Talks/WorkshopsThe BSidesSF 2023 CFP is now closed. Check back for updated deadlines for accepted presenters. January 24, 2023 – Notifications on talk/workshop acceptance/rejection start bei...
PyPI malware creators starting to employ Anti-Debug techniques
https://ift.tt/ZFV5E7M
Submitted December 15, 2022 at 01:22PM by SRMish3
via reddit https://ift.tt/Thg60eY
https://ift.tt/ZFV5E7M
Submitted December 15, 2022 at 01:22PM by SRMish3
via reddit https://ift.tt/Thg60eY
JFrog
Python Malware Starting to Employ Anti-Debug Techniques
First time anti-debug techniques are discovered in PyPI malware. Read how these techniques are implemented, including analysis and tips from JFrog Security Research.
Take down of DDoS services under Operation Power OFF
https://ift.tt/DB4UhTX
Submitted December 15, 2022 at 03:47PM by CyberChoicesUK
via reddit https://ift.tt/sOq3zan
https://ift.tt/DB4UhTX
Submitted December 15, 2022 at 03:47PM by CyberChoicesUK
via reddit https://ift.tt/sOq3zan
www.nationalcrimeagency.gov.uk
DDoS-for-hire services taken out in international operation
An international operation targeting tools and services used to commit serious cyber attacks has seen the takedown of 48 of the world’s most popular ‘booter’ sites.
Unauthenticated Buffer Overflows in multiple Zyxel routers still haunting users - Metasploit exploit code published, thousands of devices potentially affected!
https://ift.tt/g3C5Vj7
Submitted December 15, 2022 at 06:22PM by 0x9000
via reddit https://ift.tt/xqlaRS9
https://ift.tt/g3C5Vj7
Submitted December 15, 2022 at 06:22PM by 0x9000
via reddit https://ift.tt/xqlaRS9
SEC Consult
The enemy from within: Unauthenticated Buffer Overflows in Zyxel routers still haunting users
Earlier this year, the SEC Consult Vulnerability Lab published a technical security advisory on different critical vulnerabilities in Zyxel devices, resulting from insecure coding practices and insecure configuration. Those also included a highly critical…
Salt Labs | Missing Bricks: Finding Security Holes in LEGO APIs
https://ift.tt/zfZYuUW
Submitted December 15, 2022 at 07:23PM by ynvb
via reddit https://ift.tt/xZHibBk
https://ift.tt/zfZYuUW
Submitted December 15, 2022 at 07:23PM by ynvb
via reddit https://ift.tt/xZHibBk
salt.security
Salt Labs | Missing Bricks: Finding Security Holes in LEGO APIs
We chose to investigate the services provided by LEGO, perhaps the most famous toy manufacturer in the world – because we contend this example sheds light on the reality of quick adoption of APIs and the risks that can come with that fast pace.
SHA-1 is out. NIST recommends switching to the SHA-2 and SHA-3 groups of hash algorithms as soon as possible, with an official deadline of Dec. 31, 2030.
https://ift.tt/5DrToaG
Submitted December 15, 2022 at 08:36PM by nist
via reddit https://ift.tt/0WOfJHI
https://ift.tt/5DrToaG
Submitted December 15, 2022 at 08:36PM by nist
via reddit https://ift.tt/0WOfJHI
NIST
NIST Retires SHA-1 Cryptographic Algorithm
The venerable cryptographic hash function has vulnerabilities that make its further use inadvisable.
How Elon Musk Says He Catches Leakers at His Companies
https://ift.tt/AFR3EYv
Submitted December 15, 2022 at 09:34PM by moxofoxo
via reddit https://ift.tt/1EsQdAk
https://ift.tt/AFR3EYv
Submitted December 15, 2022 at 09:34PM by moxofoxo
via reddit https://ift.tt/1EsQdAk
The Intercept
How Elon Musk Says He Catches Leakers at His Companies
Musk has boasted of entrapping a Tesla leaker by watermarking emails, and he is threatening any dissidents still at Twitter.
A vulnerability in the UMPD (User-Mode Printer Drivers) allows local users to trigger a use-after-free vulnerability. The vulnerability works from Windows 8 and above, and is fairly easy to exploit on older Windows machines.
https://ift.tt/rpEUcBT
Submitted December 15, 2022 at 08:57PM by SSDisclosure
via reddit https://ift.tt/m9IULtG
https://ift.tt/rpEUcBT
Submitted December 15, 2022 at 08:57PM by SSDisclosure
via reddit https://ift.tt/m9IULtG
SSD Secure Disclosure
Win32k User-Mode Printer Drivers StartDoc UAF - SSD Secure Disclosure
Summary A vulnerability in the UMPD (User-Mode Printer Drivers) allows local users to trigger a use-after-free vulnerability. The vulnerability works from Windows 8 and above, and is fairly easy to exploit on older Windows machines. Credit An independent…
Critical Vulnerability Found in Sovrin, a Popular Decentralized Identity System
https://ift.tt/ksLtEl3
Submitted December 16, 2022 at 11:44AM by jat0369
via reddit https://ift.tt/40yMx3N
https://ift.tt/ksLtEl3
Submitted December 16, 2022 at 11:44AM by jat0369
via reddit https://ift.tt/40yMx3N
Cyberark
Decentralized Identity Attack Surface – Part 2
Introduction This is the second part of our Decentralized Identity (DID) blog series. In case you’re not familiar with DID concepts, we highly encourage you to start with the first part. This time...
Foxit PDF Reader - Use after Free - Remote Code Execution Exploit
https://ift.tt/Y8vnzJR
Submitted December 16, 2022 at 11:42AM by hacksysteam
via reddit https://ift.tt/QtnxiXz
https://ift.tt/Y8vnzJR
Submitted December 16, 2022 at 11:42AM by hacksysteam
via reddit https://ift.tt/QtnxiXz
HackSys Inc
Build: an open source IDE for authoring, testing, and verifying production-ready security tests.
https://ift.tt/p3LWMwf
Submitted December 16, 2022 at 07:45PM by DH_Prelude
via reddit https://ift.tt/WF7Lik1
https://ift.tt/p3LWMwf
Submitted December 16, 2022 at 07:45PM by DH_Prelude
via reddit https://ift.tt/WF7Lik1
GitHub
GitHub - preludeorg/build: Author, test and deploy security tests
Author, test and deploy security tests. Contribute to preludeorg/build development by creating an account on GitHub.
OSCP guide 2022
https://ift.tt/LC9DUwM
Submitted December 17, 2022 at 08:47AM by sgtdede
via reddit https://ift.tt/dXbUaFq
https://ift.tt/LC9DUwM
Submitted December 17, 2022 at 08:47AM by sgtdede
via reddit https://ift.tt/dXbUaFq
sgtdede.gitbook.io
Guide (EN)
OSCP 2022
Exploiting API Framework Flexibility
https://ift.tt/3mLyXzR
Submitted December 17, 2022 at 04:03PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/SDm46ea
https://ift.tt/3mLyXzR
Submitted December 17, 2022 at 04:03PM by 6W99ocQnb8Zy17
via reddit https://ift.tt/SDm46ea
attack ships on fire
Exploiting API Framework Flexibility
TL;DR The modern frameworks are often very flexible with what they accept, and will happily treat a POST with a JSON body as interchangeable with a URL encoded body, or even with query parameters. Due to this, an unexploitable JSON XSS vector can sometimes…
Gepetto - An IDA plugin which queries OpenAI's davinci-003 language model to speed up reverse-engineering
https://ift.tt/gAMNSHK
Submitted December 18, 2022 at 08:08AM by galaris
via reddit https://ift.tt/IpPxGal
https://ift.tt/gAMNSHK
Submitted December 18, 2022 at 08:08AM by galaris
via reddit https://ift.tt/IpPxGal
GitHub
GitHub - JusticeRage/Gepetto: IDA plugin which queries OpenAI's gpt-3.5-turbo language model to speed up reverse-engineering
IDA plugin which queries OpenAI's gpt-3.5-turbo language model to speed up reverse-engineering - GitHub - JusticeRage/Gepetto: IDA plugin which queries OpenAI's gpt-3.5-turbo langua...
Your Car is Trackable by Law TPMS tracking for 30$
https://ift.tt/0G4vqrl
Submitted December 18, 2022 at 10:20AM by Exact-Practice-8658
via reddit https://ift.tt/MBgF1lG
https://ift.tt/0G4vqrl
Submitted December 18, 2022 at 10:20AM by Exact-Practice-8658
via reddit https://ift.tt/MBgF1lG
Medium
Your Car is Trackable by Law
TPMS Tracking