A step-by-step introduction to the use of ROP gadgets to bypass DEP
https://ift.tt/tYdPFON
Submitted January 23, 2023 at 08:34PM by CyberMasterV
via reddit https://ift.tt/9jTGaYs
https://ift.tt/tYdPFON
Submitted January 23, 2023 at 08:34PM by CyberMasterV
via reddit https://ift.tt/9jTGaYs
2FA Day FTW
https://2fa.day
Submitted January 23, 2023 at 10:12PM by intosec
via reddit https://ift.tt/hG0QZdx
https://2fa.day
Submitted January 23, 2023 at 10:12PM by intosec
via reddit https://ift.tt/hG0QZdx
2FA Day
2nd of FebruAry is 2FA Day
2FA Day on 2nd of FebruAry promotes two-factor authentication to enhance online security. It raises awareness about the importance of an extra security layer.
Pwning the all Google phone with a non-Google bug | The GitHub Blog
https://ift.tt/hU3u5qy
Submitted January 24, 2023 at 02:37AM by smaury
via reddit https://ift.tt/ukeamV1
https://ift.tt/hU3u5qy
Submitted January 24, 2023 at 02:37AM by smaury
via reddit https://ift.tt/ukeamV1
The GitHub Blog
Pwning the all Google phone with a non-Google bug | The GitHub Blog
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit…
Mastodon server for hacking community
https://h4x0r.army
Submitted January 24, 2023 at 05:09AM by n4bb
via reddit https://ift.tt/FuUbhQr
https://h4x0r.army
Submitted January 24, 2023 at 05:09AM by n4bb
via reddit https://ift.tt/FuUbhQr
Mastodon hosted on h4x0r.army
h4x0r army
Community for hackers, pentesters, programmers, activists, philosophers, cyberpunks, artists, infosec, privacy professionals, and those genuinely curious about technology.
Reverse-engineering the conditional jump circuitry in the 8086 processor
https://ift.tt/q6D1jLB
Submitted January 24, 2023 at 11:47AM by Gallus
via reddit https://ift.tt/Qvdq6c8
https://ift.tt/q6D1jLB
Submitted January 24, 2023 at 11:47AM by Gallus
via reddit https://ift.tt/Qvdq6c8
Righto
Reverse-engineering the conditional jump circuitry in the 8086 processor
Intel introduced the 8086 microprocessor in 1978 and it had a huge influence on computing. I'm reverse-engineering the 8086 by examining t...
Bitwarden design flaw: Server side iterations
https://ift.tt/0lt6AgJ
Submitted January 24, 2023 at 11:46AM by Gallus
via reddit https://ift.tt/0SKfCtD
https://ift.tt/0lt6AgJ
Submitted January 24, 2023 at 11:46AM by Gallus
via reddit https://ift.tt/0SKfCtD
Almost Secure
Bitwarden design flaw: Server side iterations
Bitwarden is a hot candidate for a LastPass replacement. Looking into how they encrypt data, it doesn’t do things that much better however.
Tampering User Attributes In AWS Cognito User Pools
https://ift.tt/ROXlLvz
Submitted January 24, 2023 at 03:18PM by nibblesec
via reddit https://ift.tt/2gRX89M
https://ift.tt/ROXlLvz
Submitted January 24, 2023 at 03:18PM by nibblesec
via reddit https://ift.tt/2gRX89M
Doyensec
Tampering User Attributes In AWS Cognito User Pools · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
A website to get latest security advisories from multiple sources
https://cyberowl.org
Submitted January 24, 2023 at 05:12PM by karimhabush
via reddit https://ift.tt/0EQvsjl
https://cyberowl.org
Submitted January 24, 2023 at 05:12PM by karimhabush
via reddit https://ift.tt/0EQvsjl
cyberowl.org
Cyberowl | CyberOwl
Stay informed on the latest cyber threats - a one-stop destination for all the latest alerts and updates from multiple sources.
Gato (Github Attack TOolkit), a tool to enumerate, attack, and defend GitHub Actions self-hosted runners
https://ift.tt/gTJVbKY
Submitted January 24, 2023 at 08:46PM by exploding_nun
via reddit https://ift.tt/xubI1RC
https://ift.tt/gTJVbKY
Submitted January 24, 2023 at 08:46PM by exploding_nun
via reddit https://ift.tt/xubI1RC
GitHub
GitHub - praetorian-inc/gato: GitHub Self-Hosted Runner Enumeration and Attack Tool
GitHub Self-Hosted Runner Enumeration and Attack Tool - GitHub - praetorian-inc/gato: GitHub Self-Hosted Runner Enumeration and Attack Tool
Operator’s Guide to the Meterpreter BOFLoader
https://ift.tt/0yEMkY6
Submitted January 24, 2023 at 09:50PM by n00py
via reddit https://ift.tt/qAoSjct
https://ift.tt/0yEMkY6
Submitted January 24, 2023 at 09:50PM by n00py
via reddit https://ift.tt/qAoSjct
TrustedSec
Operator's Guide to the Meterpreter BOFLoader - TrustedSec
TrustedSec's blog is an expert source of information on information security trends and best practices for strategic risk management.
CVE-2023-0210 – Linux Kernel Unauthenticated Remote Heap Overflow Within KSMBD
https://ift.tt/sFdiL2Y
Submitted January 24, 2023 at 09:13PM by MiguelHzBz
via reddit https://ift.tt/rHSsuU9
https://ift.tt/sFdiL2Y
Submitted January 24, 2023 at 09:13PM by MiguelHzBz
via reddit https://ift.tt/rHSsuU9
Sysdig
CVE-2023-0210 – Sysdig
Recently, a vulnerability was discovered, which allowed for unauthenticated remote code execution in the kernel context.
GitHub - Free Python scanner for CVE-2022-47966
https://ift.tt/GJmQ1as
Submitted January 24, 2023 at 11:09PM by vonahisec
via reddit https://ift.tt/aBUMkhn
https://ift.tt/GJmQ1as
Submitted January 24, 2023 at 11:09PM by vonahisec
via reddit https://ift.tt/aBUMkhn
GitHub
GitHub - vonahisec/CVE-2022-47966-Scan
Contribute to vonahisec/CVE-2022-47966-Scan development by creating an account on GitHub.
Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI
https://ift.tt/eX1biC5
Submitted January 25, 2023 at 10:00AM by Mempodipper
via reddit https://ift.tt/O9g0jQZ
https://ift.tt/eX1biC5
Submitted January 25, 2023 at 10:00AM by Mempodipper
via reddit https://ift.tt/O9g0jQZ
Assetnote
Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI
Application security issues found by Assetnote
Active Directory: Using LDAP Queries for Stealthy Enumeration
https://ift.tt/vfOCFhT
Submitted January 25, 2023 at 02:01PM by andreashappe
via reddit https://ift.tt/UNnwcTx
https://ift.tt/vfOCFhT
Submitted January 25, 2023 at 02:01PM by andreashappe
via reddit https://ift.tt/UNnwcTx
snikt.net
Active Directory: Using LDAP Queries for Stealthy Enumeration -
Andreas Happe sometimes blogs about development, life or security.
DMARC Identifier Alignment: relax, don't do it, when you want to go to it - From subdomain takeover to phishing mails
https://ift.tt/cGhLpum
Submitted January 25, 2023 at 04:56PM by ljulolsen
via reddit https://ift.tt/D72K1wO
https://ift.tt/cGhLpum
Submitted January 25, 2023 at 04:56PM by ljulolsen
via reddit https://ift.tt/D72K1wO
Jeffrey Bencteux
DMARC Identifier Alignment: relax, don't do it, when you want to go to it
From subdomain takeover to phishing mails
TL;DR; if you have a subdomain takeover for a given domain, and default DMARC alignment settings, you can create emails that passes SPF and DMARC for phishing purposes. DKIM, however, cannot be passed for the domain…
TL;DR; if you have a subdomain takeover for a given domain, and default DMARC alignment settings, you can create emails that passes SPF and DMARC for phishing purposes. DKIM, however, cannot be passed for the domain…
PyCript is a Burp Suite extension to bypass client-side encryption that supports both manual and automated testing such as Scanners, Intruder, or SQLMAP. Custom encryption logic can be written in NodeJS to support any encryption within BurpSuite
https://ift.tt/qLV3SyC
Submitted January 25, 2023 at 10:40PM by Ano_F
via reddit https://ift.tt/GF5L1xh
https://ift.tt/qLV3SyC
Submitted January 25, 2023 at 10:40PM by Ano_F
via reddit https://ift.tt/GF5L1xh
GitHub
GitHub - Anof-cyber/PyCript: Burp Suite extension for bypassing client-side encryption using custom logic for manual and automation…
Burp Suite extension for bypassing client-side encryption using custom logic for manual and automation testing. - GitHub - Anof-cyber/PyCript: Burp Suite extension for bypassing client-side encrypt...
Whacking a phishing admin panel for fun and profit
https://ift.tt/RpX7QeP
Submitted January 26, 2023 at 10:32AM by thehunter699
via reddit https://ift.tt/Ia3shPl
https://ift.tt/RpX7QeP
Submitted January 26, 2023 at 10:32AM by thehunter699
via reddit https://ift.tt/Ia3shPl
Medium
Destroying the Scammers Portal — SBI Scam
Greetings to all readers,
Digital False Flag Operations: A How-To Guide. Pinning your malicious digital operations to the opposition
https://ift.tt/elin5VJ
Submitted January 26, 2023 at 02:48PM by Robbedoes_
via reddit https://ift.tt/JTpI2lz
https://ift.tt/elin5VJ
Submitted January 26, 2023 at 02:48PM by Robbedoes_
via reddit https://ift.tt/JTpI2lz
Medium
Digital False Flag Operations: A How-To Guide
Pinning your malicious cyber operations to the opposition
Help! is this a false positive? this file was flagged by defender, it is from a mod downloaded from moddb
https://ift.tt/q42frwd
Submitted January 26, 2023 at 06:29PM by UncannyBishop
via reddit https://ift.tt/LyGbfiN
https://ift.tt/q42frwd
Submitted January 26, 2023 at 06:29PM by UncannyBishop
via reddit https://ift.tt/LyGbfiN
Ransacking your password reset tokens
https://ift.tt/QJFvrU4
Submitted January 26, 2023 at 06:26PM by mckirk_
via reddit https://ift.tt/FChn13t
https://ift.tt/QJFvrU4
Submitted January 26, 2023 at 06:26PM by mckirk_
via reddit https://ift.tt/FChn13t
positive.security
Ransacking your password reset tokens | Positive Security
We demonstrate how the popular "Ransack" library (Ruby on Rails) can be abused to exfiltrate sensitive data via character by character brute-force, allowing for a full application compromise in some cases. An internet wide search identifies several hundred…
Software Supply Chain Security Debt is Increasing: Here's How To Pay If Off
https://ift.tt/6m8U9Mj
Submitted January 26, 2023 at 07:37PM by dlorenc
via reddit https://ift.tt/tl0mBE6
https://ift.tt/6m8U9Mj
Submitted January 26, 2023 at 07:37PM by dlorenc
via reddit https://ift.tt/tl0mBE6
DevOps.com
Software Supply Chain Security Debt is Increasing: Here’s How To Pay It Off
Risks in the software supply chain contribute to increased security debt, but there are ways organizations can pay it off.