GitHub - kitabisa/teler-waf: teler-waf is a Go HTTP middleware that provide teler IDS functionality with teler IDS to protect against web-based attacks and improve the security of Go-based web applications. It is highly configurable and easy to integrate into existing Go applications.
https://ift.tt/ByWet0O
Submitted January 02, 2023 at 10:55AM by dwisiswant0
via reddit https://ift.tt/UOi3NbY
https://ift.tt/ByWet0O
Submitted January 02, 2023 at 10:55AM by dwisiswant0
via reddit https://ift.tt/UOi3NbY
GitHub
GitHub - kitabisa/teler-waf: teler-waf is a Go HTTP middleware that provide teler IDS functionality to protect against web-based…
teler-waf is a Go HTTP middleware that provide teler IDS functionality to protect against web-based attacks and improve the security of Go-based web applications. It is highly configurable and easy...
Python developers, uninstall this malicious package right now
https://ift.tt/LmgJWr5
Submitted January 02, 2023 at 10:07PM by DevOpsMuffin39
via reddit https://ift.tt/aKpZqFR
https://ift.tt/LmgJWr5
Submitted January 02, 2023 at 10:07PM by DevOpsMuffin39
via reddit https://ift.tt/aKpZqFR
Neowin
Python developers, uninstall this malicious package right now
Python developers who spent some time coding over the holiday break may want to check out an advisory regarding a malicious PyTorch package that was being fetched from PyPI last week.
Cloud Metadata - AWS IAM Credential Abuse
https://ift.tt/GmaY2nC
Submitted January 03, 2023 at 01:51AM by SNEAKYMONK3Y
via reddit https://ift.tt/qQebJnV
https://ift.tt/GmaY2nC
Submitted January 03, 2023 at 01:51AM by SNEAKYMONK3Y
via reddit https://ift.tt/qQebJnV
you sneakymonkey!
Cloud Metadata - AWS IAM Credential Abuse
Attackers are already fully aware of what cloud misconfigurations are and how to take advantage. Why would an attacker run 169.254.169[.]254/latest/meta-data/iam/security-credentials/ ?
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
https://ift.tt/HJYoIBD
Submitted January 03, 2023 at 03:53PM by samwcurry
via reddit https://ift.tt/oHyQrRE
https://ift.tt/HJYoIBD
Submitted January 03, 2023 at 03:53PM by samwcurry
via reddit https://ift.tt/oHyQrRE
Sam Curry | Web Application Security Researcher
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More
During the fall of 2022, a few friends and I took a road trip from Chicago, IL to Washington, DC to attend a cybersecurity conference and (try) to take a break from our usual computer work. While we were visiting the University of Maryland, we came across…
SSRF vulnerabilities caused by SNI proxy misconfigurations
https://ift.tt/lFgSUGy
Submitted January 03, 2023 at 07:07PM by Gallus
via reddit https://ift.tt/KfcbRYm
https://ift.tt/lFgSUGy
Submitted January 03, 2023 at 07:07PM by Gallus
via reddit https://ift.tt/KfcbRYm
Invicti
SSRF vulnerabilities caused by SNI proxy misconfigurations | Invicti
Misconfigurations in reverse proxies that use SNI to select backend servers can lead to SSRF vulnerabilities. Invicti security researcher Aleksei Tiurin explores the security implications of SNI proxy misconfigurations.
SimpleX Chat – the 1st messenger without user profile IDs (not even random numbers) – v4.4 released with disappearing messages and connection verification!
https://ift.tt/jWuvpnq
Submitted January 03, 2023 at 11:31PM by epoberezkin
via reddit https://ift.tt/rRqoZM8
https://ift.tt/jWuvpnq
Submitted January 03, 2023 at 11:31PM by epoberezkin
via reddit https://ift.tt/rRqoZM8
simplex.chat
SimpleX Chat v4.4 released – with disappearing messages, live messages, connection security verification and French language!
of-CORS: a framework for hacking internal apps with open CORS via bug bounty
https://ift.tt/bVhkxpA
Submitted January 03, 2023 at 11:28PM by wifihack
via reddit https://ift.tt/SwkyGgU
https://ift.tt/bVhkxpA
Submitted January 03, 2023 at 11:28PM by wifihack
via reddit https://ift.tt/SwkyGgU
Truffle Security
Bypass firewalls with of-CORs and typo-squatting - Truffle Security
Of-CORS, an appsec framework to exploit internal open CORS apps without violating bug bounty rules.
Nuclear Pond: Scanning for Vulnerabilities at Scale for Less Than a Cup of Coffee
https://ift.tt/YgM6WsR
Submitted January 04, 2023 at 12:08AM by crustysecurity
via reddit https://ift.tt/FJbu0wK
https://ift.tt/YgM6WsR
Submitted January 04, 2023 at 12:08AM by crustysecurity
via reddit https://ift.tt/FJbu0wK
DevSecOps Docs
Nuclear Pond
Perform internet wide scans for far less than a cup of coffee.
PBS FRONTLINE investigates Pegasus, the powerful spyware sold to governments around the world by the Israeli company NSO Group.
https://ift.tt/LvQZB8o
Submitted January 04, 2023 at 08:57AM by identifytarget
via reddit https://ift.tt/1tAmfnK
https://ift.tt/LvQZB8o
Submitted January 04, 2023 at 08:57AM by identifytarget
via reddit https://ift.tt/1tAmfnK
FRONTLINE
Global Spyware Scandal: Exposing Pegasus
In a two-part documentary, FRONTLINE and Forbidden Films explore how the powerful spyware Pegasus, sold to governments around the world by the Israeli company NSO Group, was used on journalists,
Top 10 web hacking techniques of 2022 - nominations open
https://ift.tt/gQ29cqy
Submitted January 04, 2023 at 07:35PM by Fugitif
via reddit https://ift.tt/HA8YREn
https://ift.tt/gQ29cqy
Submitted January 04, 2023 at 07:35PM by Fugitif
via reddit https://ift.tt/HA8YREn
PortSwigger Research
Top 10 web hacking techniques of 2022 - nominations open
Update: Voting is now closed, and the panel vote is in progress. Nominations are now open for the top 10 new web hacking techniques of 2022! Every year, security researchers share their latest f
CyberArk Labs’ 2022 Threat Research in Review
https://ift.tt/GpDzknt
Submitted January 04, 2023 at 08:34PM by CyberArkLabs
via reddit https://ift.tt/CwV8tZo
https://ift.tt/GpDzknt
Submitted January 04, 2023 at 08:34PM by CyberArkLabs
via reddit https://ift.tt/CwV8tZo
Cyberark
CyberArk Labs’ 2022 Threat Research in Review
Cyber defenders need timely, accurate threat intelligence to protect their organizations. This is what drives our CyberArk Labs team to produce innovative research, expose new attack methods and...
BusKill (open-source laptop kill cord) Warrant Canary for 2023 🕵️
https://ift.tt/T4ALOUH
Submitted January 04, 2023 at 10:21PM by maltfield
via reddit https://ift.tt/cLwG507
https://ift.tt/T4ALOUH
Submitted January 04, 2023 at 10:21PM by maltfield
via reddit https://ift.tt/cLwG507
BusKill
BusKill Canary #5 - BusKill
This post contains the cryptographically-signed BusKill warrant canary #005 for January 2023 to June 2023.
a quick post about rbac-police
https://ift.tt/1ieqDva
Submitted January 04, 2023 at 11:32PM by punksecurity_simon
via reddit https://ift.tt/m6uPDwN
https://ift.tt/1ieqDva
Submitted January 04, 2023 at 11:32PM by punksecurity_simon
via reddit https://ift.tt/m6uPDwN
punksecurity.co.uk
Auditing Kubernetes with rbac-police
Kubernetes pods can be abused to take over the entire Kubernetes cluster. rbac-police shows you which.
In-depth Analysis of the PyTorch Dependency Confusion Administered Malware
https://ift.tt/Ftw4oNx
Submitted January 05, 2023 at 02:17AM by gfdgfbal
via reddit https://ift.tt/qvSjXoA
https://ift.tt/Ftw4oNx
Submitted January 05, 2023 at 02:17AM by gfdgfbal
via reddit https://ift.tt/qvSjXoA
Aqua
In-depth Analysis of the PyTorch Dependency Confusion Administered Malware
PyTorch-nightly dependency chain was compromised. In this blog, we will provide an explanation of this attack and how to safeguard against similar attacks.
Escaping from bhyve
https://ift.tt/2BoJNK7
Submitted January 05, 2023 at 04:25AM by Gallus
via reddit https://ift.tt/iH3d2Yk
https://ift.tt/2BoJNK7
Submitted January 05, 2023 at 04:25AM by Gallus
via reddit https://ift.tt/iH3d2Yk
Synacktiv
Escaping from bhyve
Bhyve is a hypervisor for FreeBSD.
Fun and Games with Intel AMT
https://ift.tt/6h0S4pL
Submitted January 05, 2023 at 03:58AM by lightgrains
via reddit https://ift.tt/Zos7Guy
https://ift.tt/6h0S4pL
Submitted January 05, 2023 at 03:58AM by lightgrains
via reddit https://ift.tt/Zos7Guy
StarkeBlog
Fun and Games with Intel AMT
What is this?
Casper-fs is a Custom Hidden Linux Kernel Module generator. Each module works in the file system to protect and hide secret files.
https://ift.tt/JB7YOlj
Submitted January 05, 2023 at 07:26AM by CoolerVoid
via reddit https://ift.tt/aTdwJ7v
https://ift.tt/JB7YOlj
Submitted January 05, 2023 at 07:26AM by CoolerVoid
via reddit https://ift.tt/aTdwJ7v
YWallet Audit Results
https://ift.tt/rcqZ7nz
Submitted January 05, 2023 at 07:17AM by Gallus
via reddit https://ift.tt/2TqFGCl
https://ift.tt/rcqZ7nz
Submitted January 05, 2023 at 07:17AM by Gallus
via reddit https://ift.tt/2TqFGCl
Zecsec
YWallet Audit Results Published
In October of last year, I reviewed YWallet for security and privacy issues. This was the first audit I performed for the Zcash Ecosystem Security grant.
Today, the final report is being made available to the Zcash community at the link below.
The audit found…
Today, the final report is being made available to the Zcash community at the link below.
The audit found…
Prototype Pollution in Python
https://ift.tt/lsrOXLb
Submitted January 05, 2023 at 07:16AM by Gallus
via reddit https://ift.tt/UPTp7NR
https://ift.tt/lsrOXLb
Submitted January 05, 2023 at 07:16AM by Gallus
via reddit https://ift.tt/UPTp7NR
Abdulrah33m's Blog - Just another security researcher motivated by "why"s
Prototype Pollution in Python - Abdulrah33m's Blog
> TL;DR The main objective of this research is to prove the possibility of having a variation of Prototype Pollution in other programming languages, including those that are class-based by showing Class Pollution in Python. > Background Prototype Pollution…
Padding oracle attack: demonstration
https://ift.tt/qWhMi9s
Submitted January 05, 2023 at 10:26AM by yurichev
via reddit https://ift.tt/VoXhad9
https://ift.tt/qWhMi9s
Submitted January 05, 2023 at 10:26AM by yurichev
via reddit https://ift.tt/VoXhad9
Padding oracle attack: demonstration
https://ift.tt/qWhMi9s
Submitted January 05, 2023 at 11:41AM by yurichev
via reddit https://ift.tt/FdjRnUK
https://ift.tt/qWhMi9s
Submitted January 05, 2023 at 11:41AM by yurichev
via reddit https://ift.tt/FdjRnUK
Reddit
r/netsec on Reddit: Padding oracle attack: demonstration
Posted by u/yurichev - 30 votes and 2 comments