Mosca SAST tool
https://ift.tt/aRWgTfc
Submitted December 30, 2022 at 10:14AM by CoolerVoid
via reddit https://ift.tt/EngzbWT
https://ift.tt/aRWgTfc
Submitted December 30, 2022 at 10:14AM by CoolerVoid
via reddit https://ift.tt/EngzbWT
Reverse Prompt Engineering - Pwning the source prompts of Notion AI & 7 techniques for Reverse Prompt Engineering
https://ift.tt/wP7pMVr
Submitted December 30, 2022 at 11:18AM by Gallus
via reddit https://ift.tt/vJM56r4
https://ift.tt/wP7pMVr
Submitted December 30, 2022 at 11:18AM by Gallus
via reddit https://ift.tt/vJM56r4
L-Space Diaries
Reverse Prompt Engineering for Fun and (no) Profit
Pwning the source prompts of Notion AI, 7 techniques for Reverse Prompt Engineering... and why everyone is *wrong* about prompt injection
Writing Windows Kernel Drivers for Advanced Persistence (Part 1)
https://ift.tt/4s8gmcj
Submitted December 29, 2022 at 08:17PM by v3ded
via reddit https://ift.tt/hb9QRC1
https://ift.tt/4s8gmcj
Submitted December 29, 2022 at 08:17PM by v3ded
via reddit https://ift.tt/hb9QRC1
v3ded.github.io
Red Team Tactics: Writing Windows Kernel Drivers for Advanced Persistence (Part 1)
Introduction This post, as indicated by the noscript, will cover the topic of writing Windows kernel drivers for advanced persistence. Because the subject matte...
BufferPwn: RCE vulnerability in the common network code of several first party Nintendo games since the Nintendo 3DS
https://ift.tt/pQKn9Wc
Submitted December 29, 2022 at 02:43AM by 4ngr0n
via reddit https://ift.tt/Z4nqe1j
https://ift.tt/pQKn9Wc
Submitted December 29, 2022 at 02:43AM by 4ngr0n
via reddit https://ift.tt/Z4nqe1j
GitHub
GitHub - PabloMK7/ENLBufferPwn: Information and PoC about the ENLBufferPwn vulnerability
Information and PoC about the ENLBufferPwn vulnerability - GitHub - PabloMK7/ENLBufferPwn: Information and PoC about the ENLBufferPwn vulnerability
There is no secure software supply-chain.
https://ift.tt/JpxWYLC
Submitted December 30, 2022 at 06:26PM by dlorenc
via reddit https://ift.tt/vwGdiZt
https://ift.tt/JpxWYLC
Submitted December 30, 2022 at 06:26PM by dlorenc
via reddit https://ift.tt/vwGdiZt
On Engineering
There is no secure software supply-chain.
Years ago, entrepreneurs and innovators predicated that “software would eat the world”. And to little surprise, year after year, the world has become more and more reliant on software solutions. Often times, that software is (or indirectly depends on) some…
Chrome Browser Exploitation, Part 3: Analyzing and Exploiting CVE-2018-17463
https://ift.tt/8mKWc1Y
Submitted December 30, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/VUrziFs
https://ift.tt/8mKWc1Y
Submitted December 30, 2022 at 08:25PM by Gallus
via reddit https://ift.tt/VUrziFs
Jack Hacks
Chrome Browser Exploitation, Part 3: Analyzing and Exploiting CVE-2018-17463
Welcome to the third and final installment of the “Chrome Browser Exploitation” series. The main objective of this series has been to provide an introduction to browser internals and delve into the topic of Chrome browser exploitation on Windows in greater…
Windows 2008 Server - Vulnerability Scan
https://ift.tt/MdZQafq
Submitted December 30, 2022 at 09:18PM by Ok-Strain-4392
via reddit https://ift.tt/Edon8Iz
https://ift.tt/MdZQafq
Submitted December 30, 2022 at 09:18PM by Ok-Strain-4392
via reddit https://ift.tt/Edon8Iz
Wikipedia
Microsoft Baseline Security Analyzer
computer security evaluation tool
Architecture Notes - Capture the Flag.
https://ift.tt/A6ZgExP
Submitted December 30, 2022 at 11:20PM by myusuf3
via reddit https://ift.tt/SZy8D5x
https://ift.tt/A6ZgExP
Submitted December 30, 2022 at 11:20PM by myusuf3
via reddit https://ift.tt/SZy8D5x
ctf.architecturenotes.co
Architecture Notes - Capture the Flag.
Join the Architecture Notes CTF and test your system design skills against participants from around the world. Solve challenges in distributed systems, web security, and more. Open to all skill levels.
LuaJIT Sandbox Escape: The Saga Ends
https://ift.tt/bpBIGWH
Submitted December 31, 2022 at 05:50PM by Gallus
via reddit https://ift.tt/w57jqOQ
https://ift.tt/bpBIGWH
Submitted December 31, 2022 at 05:50PM by Gallus
via reddit https://ift.tt/w57jqOQ
0xbigshaq.github.io
LuaJIT Sandbox Escape: The Saga Ends
Happy holidays 🕎/🎅 and (almost) happy new year!
This week I presented my LuaJIT journey at the DEFCON-Groups meetup(@dc9723):
Yesterday I shared my LuaJIT journey at @dc9723 group. Thanks for everyone who attended :DCurrently working on the last blogpost…
This week I presented my LuaJIT journey at the DEFCON-Groups meetup(@dc9723):
Yesterday I shared my LuaJIT journey at @dc9723 group. Thanks for everyone who attended :DCurrently working on the last blogpost…
Offensive C#
https://ift.tt/M6U5NYV
Submitted January 01, 2023 at 01:11PM by nikkithegr8
via reddit https://ift.tt/ISj08vO
https://ift.tt/M6U5NYV
Submitted January 01, 2023 at 01:11PM by nikkithegr8
via reddit https://ift.tt/ISj08vO
Teachable
Offensive C#
Compromised PyTorch-nightly dependency chain
https://ift.tt/N57rPX6
Submitted January 01, 2023 at 02:31PM by z84
via reddit https://ift.tt/lqiOySj
https://ift.tt/N57rPX6
Submitted January 01, 2023 at 02:31PM by z84
via reddit https://ift.tt/lqiOySj
pytorch.org
An open source machine learning framework that accelerates the path from research prototyping to production deployment.
GitHub - jafarlihi/modreveal: Utility to find hidden Linux kernel modules
https://ift.tt/JToxZzW
Submitted January 01, 2023 at 09:00PM by jafarlihi
via reddit https://ift.tt/2MLx38D
https://ift.tt/JToxZzW
Submitted January 01, 2023 at 09:00PM by jafarlihi
via reddit https://ift.tt/2MLx38D
GitHub
GitHub - jafarlihi/modreveal: Utility to find hidden Linux kernel modules
Utility to find hidden Linux kernel modules. Contribute to jafarlihi/modreveal development by creating an account on GitHub.
GitHub - kitabisa/teler-waf: teler-waf is a Go HTTP middleware that provide teler IDS functionality with teler IDS to protect against web-based attacks and improve the security of Go-based web applications. It is highly configurable and easy to integrate into existing Go applications.
https://ift.tt/ByWet0O
Submitted January 02, 2023 at 10:55AM by dwisiswant0
via reddit https://ift.tt/UOi3NbY
https://ift.tt/ByWet0O
Submitted January 02, 2023 at 10:55AM by dwisiswant0
via reddit https://ift.tt/UOi3NbY
GitHub
GitHub - kitabisa/teler-waf: teler-waf is a Go HTTP middleware that provide teler IDS functionality to protect against web-based…
teler-waf is a Go HTTP middleware that provide teler IDS functionality to protect against web-based attacks and improve the security of Go-based web applications. It is highly configurable and easy...
Python developers, uninstall this malicious package right now
https://ift.tt/LmgJWr5
Submitted January 02, 2023 at 10:07PM by DevOpsMuffin39
via reddit https://ift.tt/aKpZqFR
https://ift.tt/LmgJWr5
Submitted January 02, 2023 at 10:07PM by DevOpsMuffin39
via reddit https://ift.tt/aKpZqFR
Neowin
Python developers, uninstall this malicious package right now
Python developers who spent some time coding over the holiday break may want to check out an advisory regarding a malicious PyTorch package that was being fetched from PyPI last week.
Cloud Metadata - AWS IAM Credential Abuse
https://ift.tt/GmaY2nC
Submitted January 03, 2023 at 01:51AM by SNEAKYMONK3Y
via reddit https://ift.tt/qQebJnV
https://ift.tt/GmaY2nC
Submitted January 03, 2023 at 01:51AM by SNEAKYMONK3Y
via reddit https://ift.tt/qQebJnV
you sneakymonkey!
Cloud Metadata - AWS IAM Credential Abuse
Attackers are already fully aware of what cloud misconfigurations are and how to take advantage. Why would an attacker run 169.254.169[.]254/latest/meta-data/iam/security-credentials/ ?
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
https://ift.tt/HJYoIBD
Submitted January 03, 2023 at 03:53PM by samwcurry
via reddit https://ift.tt/oHyQrRE
https://ift.tt/HJYoIBD
Submitted January 03, 2023 at 03:53PM by samwcurry
via reddit https://ift.tt/oHyQrRE
Sam Curry | Web Application Security Researcher
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
During the fall of 2022, a few friends and I took a road trip from Chicago, IL to Washington, DC to attend a cybersecurity conference and (try) to take a break from our usual computer work. While we were visiting the University of Maryland, we came across…
SSRF vulnerabilities caused by SNI proxy misconfigurations
https://ift.tt/lFgSUGy
Submitted January 03, 2023 at 07:07PM by Gallus
via reddit https://ift.tt/KfcbRYm
https://ift.tt/lFgSUGy
Submitted January 03, 2023 at 07:07PM by Gallus
via reddit https://ift.tt/KfcbRYm
Invicti
SSRF vulnerabilities caused by SNI proxy misconfigurations | Invicti
Misconfigurations in reverse proxies that use SNI to select backend servers can lead to SSRF vulnerabilities. Invicti security researcher Aleksei Tiurin explores the security implications of SNI proxy misconfigurations.
SimpleX Chat – the 1st messenger without user profile IDs (not even random numbers) – v4.4 released with disappearing messages and connection verification!
https://ift.tt/jWuvpnq
Submitted January 03, 2023 at 11:31PM by epoberezkin
via reddit https://ift.tt/rRqoZM8
https://ift.tt/jWuvpnq
Submitted January 03, 2023 at 11:31PM by epoberezkin
via reddit https://ift.tt/rRqoZM8
simplex.chat
SimpleX Chat v4.4 released – with disappearing messages, live messages, connection security verification and French language!
of-CORS: a framework for hacking internal apps with open CORS via bug bounty
https://ift.tt/bVhkxpA
Submitted January 03, 2023 at 11:28PM by wifihack
via reddit https://ift.tt/SwkyGgU
https://ift.tt/bVhkxpA
Submitted January 03, 2023 at 11:28PM by wifihack
via reddit https://ift.tt/SwkyGgU
Truffle Security
Bypass firewalls with of-CORs and typo-squatting - Truffle Security
Of-CORS, an appsec framework to exploit internal open CORS apps without violating bug bounty rules.
Nuclear Pond: Scanning for Vulnerabilities at Scale for Less Than a Cup of Coffee
https://ift.tt/YgM6WsR
Submitted January 04, 2023 at 12:08AM by crustysecurity
via reddit https://ift.tt/FJbu0wK
https://ift.tt/YgM6WsR
Submitted January 04, 2023 at 12:08AM by crustysecurity
via reddit https://ift.tt/FJbu0wK
DevSecOps Docs
Nuclear Pond
Perform internet wide scans for far less than a cup of coffee.
PBS FRONTLINE investigates Pegasus, the powerful spyware sold to governments around the world by the Israeli company NSO Group.
https://ift.tt/LvQZB8o
Submitted January 04, 2023 at 08:57AM by identifytarget
via reddit https://ift.tt/1tAmfnK
https://ift.tt/LvQZB8o
Submitted January 04, 2023 at 08:57AM by identifytarget
via reddit https://ift.tt/1tAmfnK
FRONTLINE
Global Spyware Scandal: Exposing Pegasus
In a two-part documentary, FRONTLINE and Forbidden Films explore how the powerful spyware Pegasus, sold to governments around the world by the Israeli company NSO Group, was used on journalists,