MeshyJSON: A TP-Link tdpServer JSON Stack Overflow
https://ift.tt/UowW4V3
Submitted December 19, 2022 at 06:22PM by ArbitraryWrite
via reddit https://ift.tt/FBiNEjM
https://ift.tt/UowW4V3
Submitted December 19, 2022 at 06:22PM by ArbitraryWrite
via reddit https://ift.tt/FBiNEjM
NCC Group Research
MeshyJSON: A TP-Link tdpServer JSON Stack Overflow
This blog post describes a vulnerability found and exploited in November 2022 by NCC Group. The target was the TP-Link AX1800 WiFi 6 Router (Archer AX21).
Why build an HTTP client into a database? So you can ingest web data directly!
https://ift.tt/zDf58WC
Submitted December 19, 2022 at 09:10PM by stevecio
via reddit https://ift.tt/5CY2PRt
https://ift.tt/zDf58WC
Submitted December 19, 2022 at 09:10PM by stevecio
via reddit https://ift.tt/5CY2PRt
Steampipe
Why build an HTTP client into a database? So you can ingest web data directly! | Steampipe Blog
When there isn't a Steampipe plugin to meet your need, the Net plugin's net_http_request table can save the day.
clif - is a command-line application fuzzer in Rust
https://ift.tt/sPnKZYm
Submitted December 19, 2022 at 10:41PM by andy-codes
via reddit https://ift.tt/cUI8CHJ
https://ift.tt/sPnKZYm
Submitted December 19, 2022 at 10:41PM by andy-codes
via reddit https://ift.tt/cUI8CHJ
andy.codes
Andy's Terminal - clif: simple command-line application fuzze
EDR evasion with hardware breakpoints
https://ift.tt/OufPCEv
Submitted December 20, 2022 at 02:39AM by Fun_Preference1113
via reddit https://ift.tt/PazyvXh
https://ift.tt/OufPCEv
Submitted December 20, 2022 at 02:39AM by Fun_Preference1113
via reddit https://ift.tt/PazyvXh
Cymulate
EDR Evasion with Hardware Breakpoints: The Blindside Technique
Cymulate researchers have discovered a new vulnerability and created a proof of concept. The technique based on it allows attackers to circumvent many EDR vendors.
Beware of this CI/CD vulnerability: GitHub Environment Injection (Google & Apache found vulnerable)
https://ift.tt/Va83JSG
Submitted December 20, 2022 at 03:52AM by roy_6472
via reddit https://ift.tt/IW1rJzo
https://ift.tt/Va83JSG
Submitted December 20, 2022 at 03:52AM by roy_6472
via reddit https://ift.tt/IW1rJzo
Legitsecurity
Google & Apache Found Vulnerable to GitHub Environment Injection
Learn how Legit Security discovered a vulnerable GitHub actions workflow that affected Google, Apache and potentially many more. Get details on the vulnerability and what you can do to mitigate it.
Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg
https://ift.tt/IqrKgzL
Submitted December 20, 2022 at 04:11AM by Void_Sec
via reddit https://ift.tt/LtjqCTz
https://ift.tt/IqrKgzL
Submitted December 20, 2022 at 04:11AM by Void_Sec
via reddit https://ift.tt/LtjqCTz
Exodus Intelligence
Linux Kernel: Exploiting a Netfilter Use-after-Free in kmalloc-cg - Exodus Intelligence
By Sergi Martinez Overview It’s been a while since our last technical blogpost, so here’s one right on time for the Christmas holidays. We describe a method to exploit a use-after-free in the Linux kernel when objects are allocated in a specific slab cache…
Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot
https://ift.tt/6pjZFxH
Submitted December 20, 2022 at 08:28AM by wrongbaud
via reddit https://ift.tt/tScD0Zd
https://ift.tt/6pjZFxH
Submitted December 20, 2022 at 08:28AM by wrongbaud
via reddit https://ift.tt/tScD0Zd
Voidstar Security Research Blog
Intro to Embedded RE: UART Discovery and Firmware Extraction via UBoot
Extracting firmware via UART and UBoot
Writeup about an authentication bypass and privilege escalation in the Passwordstate password manager
https://ift.tt/7fPEZsM
Submitted December 20, 2022 at 01:17PM by parzel
via reddit https://ift.tt/OG3BWVU
https://ift.tt/7fPEZsM
Submitted December 20, 2022 at 01:17PM by parzel
via reddit https://ift.tt/OG3BWVU
Modzero
Better Make Sure Your Password Manager Is Secure | mod%log
We examined the password management solution Passwordstate of Click Studios and identified multiple high severity vulnerabilities (CVE-2022-3875, CVE-2022-3876, CVE-2022-3877).
OSV-Scanner: A vulnerability scanner written in Go which uses the data provided by OSV.dev
https://ift.tt/ly82KCe
Submitted December 20, 2022 at 02:21PM by Titokhan
via reddit https://ift.tt/l8HBtYU
https://ift.tt/ly82KCe
Submitted December 20, 2022 at 02:21PM by Titokhan
via reddit https://ift.tt/l8HBtYU
GitHub
GitHub - google/osv-scanner: Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Vulnerability scanner written in Go which uses the data provided by https://osv.dev - GitHub - google/osv-scanner: Vulnerability scanner written in Go which uses the data provided by https://osv.dev
Bypass iOS backup's TCC protection
https://ift.tt/Fn31eqd
Submitted December 20, 2022 at 11:28PM by surrealisticpillow12
via reddit https://ift.tt/bP5iuhU
https://ift.tt/Fn31eqd
Submitted December 20, 2022 at 11:28PM by surrealisticpillow12
via reddit https://ift.tt/bP5iuhU
theevilbit.github.io
CVE-2022-32929 - Bypass iOS backup's TCC protection
Intro Normally, when a users backup their iOS device, the backup is saved into ~/Library/Application Support/MobileSync/Backup directory. The MobileSync directory is properly protected by TCC, as the backup can contain photos, contact information, everything…
Using Leaking Sentinel Value to Bypass the Latest Chrome v8 HardenProtect
https://ift.tt/c7vTymG
Submitted December 20, 2022 at 11:24PM by surrealisticpillow12
via reddit https://ift.tt/JsM0GKv
https://ift.tt/c7vTymG
Submitted December 20, 2022 at 11:24PM by surrealisticpillow12
via reddit https://ift.tt/JsM0GKv
Medium
Using Leaking Sentinel Value to Bypass the Latest Chrome v8 HardenProtect
A technical analysis where we use sentinel value to bypass the Latest Chrome v8 HardenProtect
Validating Okta Access Tokens in Python with PyJWT
https://ift.tt/o3egBH5
Submitted December 21, 2022 at 02:03AM by csanders_
via reddit https://ift.tt/cmrVxK6
https://ift.tt/o3egBH5
Submitted December 21, 2022 at 02:03AM by csanders_
via reddit https://ift.tt/cmrVxK6
Medium
Validating Okta Access Tokens in Python with PyJWT
Every week, almost without fail, I come across one thing that confuses, entertains, or most commonly infuriates me. I’ve decided to keep a…
New Chaes campaign uses Windows Management Instrumentation Command-Line Utility
https://ift.tt/R3FXlf9
Submitted December 21, 2022 at 05:07AM by PENGUINPLOW
via reddit https://ift.tt/x1RFSEw
https://ift.tt/R3FXlf9
Submitted December 21, 2022 at 05:07AM by PENGUINPLOW
via reddit https://ift.tt/x1RFSEw
sidechannel.blog
New Chaes campaign uses Windows Management Instrumentation Command-Line Utility | SideChannel – Tempest
Exploring the depths of Istio: A researcher's guide to analyzing a caching vulnerability
https://ift.tt/smxYTeD
Submitted December 21, 2022 at 11:28AM by jat0369
via reddit https://ift.tt/g9u4G2J
https://ift.tt/smxYTeD
Submitted December 21, 2022 at 11:28AM by jat0369
via reddit https://ift.tt/g9u4G2J
Cyberark
What I Learned from Analyzing a Caching Vulnerability in Istio
TL;DR Istio is an open-source service mash that can layer over applications. Studying CVE-2021-34824 in Istio will allow us to dive into some concepts of Istio and service meshes in general. We...
Cisco BroadWorks CommPilot Application Software Authenticated Remote Code Execution (CVE-2022-20958)
https://ift.tt/CQtm93e
Submitted December 21, 2022 at 04:41PM by smaury
via reddit https://ift.tt/lT2CBH5
https://ift.tt/CQtm93e
Submitted December 21, 2022 at 04:41PM by smaury
via reddit https://ift.tt/lT2CBH5
Shielder
Shielder - Cisco BroadWorks CommPilot Application Software Authenticated Remote Code Execution (CVE-2022-20958)
CVE-2022-20958: Cisco BroadWorks CommPilot Application allows authenticated users to upload configuration files on the platform. The lack of file validation and a broken access control on the vulnerable upload serverlet allows any authenticated user to upload…
Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)
https://ift.tt/OAzwT6u
Submitted December 21, 2022 at 04:40PM by smaury
via reddit https://ift.tt/L59OyzW
https://ift.tt/OAzwT6u
Submitted December 21, 2022 at 04:40PM by smaury
via reddit https://ift.tt/L59OyzW
Shielder
Shielder - Cisco BroadWorks CommPilot Application Software Unauthenticated Server-Side Request Forgery (CVE-2022-20951)
CVE-2022-20951: Cisco BroadWorks CommPilot Application exposes a servlet that allows the application to be used as an HTTP proxy server. The lack of validation of the the target URL and the lack of authentication protection allows an unauthenticated attacker…
DirtyCred Remastered: UAF to LPE (CVE-2022-2602)
https://ift.tt/YbP6cLo
Submitted December 21, 2022 at 07:45PM by Void_Sec
via reddit https://ift.tt/dtVc6i1
https://ift.tt/YbP6cLo
Submitted December 21, 2022 at 07:45PM by Void_Sec
via reddit https://ift.tt/dtVc6i1
LukeGix
DirtyCred Remastered
DirtyCred Remastered: how to turn an UAF into Privilege Escalation
A journey into IoT - Unknown Chinese alarm - Part 4 - Internal communications
https://ift.tt/ot28baN
Submitted December 21, 2022 at 08:32PM by 0xdea
via reddit https://ift.tt/mGDvXC2
https://ift.tt/ot28baN
Submitted December 21, 2022 at 08:32PM by 0xdea
via reddit https://ift.tt/mGDvXC2
hn security
A journey into IoT - Unknown Chinese alarm - Part 4 - Internal communications - hn security
Disclaimer: as many other security researchers […]
Deconstructing and Exploiting CVE-2020-6418
https://ift.tt/zvYZpHL
Submitted December 21, 2022 at 07:56PM by surrealisticpillow12
via reddit https://ift.tt/I0Ri9OG
https://ift.tt/zvYZpHL
Submitted December 21, 2022 at 07:56PM by surrealisticpillow12
via reddit https://ift.tt/I0Ri9OG
STAR Labs
Deconstructing and Exploiting CVE-2020-6418
As part of my internship at STAR Labs, I conducted n-day analysis of CVE-2020-6418. This vulnerability lies in the V8 engine of Google Chrome, namely its optimizing compiler Turbofan. Specifically, the vulnerable version is in Google Chrome’s V8 prior to…
Puckungfu: A NETGEAR WAN Command Injection
https://ift.tt/8pYDvB4
Submitted December 22, 2022 at 05:02PM by ArbitraryWrite
via reddit https://ift.tt/paMGtRe
https://ift.tt/8pYDvB4
Submitted December 22, 2022 at 05:02PM by ArbitraryWrite
via reddit https://ift.tt/paMGtRe
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
GLPI Exploitation Timeline
https://ift.tt/gNnY2aJ
Submitted December 22, 2022 at 07:15PM by chicksdigthelongrun
via reddit https://ift.tt/L7S3jqX
https://ift.tt/gNnY2aJ
Submitted December 22, 2022 at 07:15PM by chicksdigthelongrun
via reddit https://ift.tt/L7S3jqX
GLPI Exploitation Timeline - Blog - VulnCheck
Taking a look at the timeline leading up to exploitation of CVE-2022-35914 and the current state of attacks in the wild.