Tracing the Linux kernel using Exein Pulsar: a 5 Minute Tutorial
https://ift.tt/A4RtpC6
Submitted February 07, 2023 at 08:29PM by hdtrinh
via reddit https://ift.tt/B1WvhA6
https://ift.tt/A4RtpC6
Submitted February 07, 2023 at 08:29PM by hdtrinh
via reddit https://ift.tt/B1WvhA6
blog.exein.io
Tracing the Linux kernel using Exein Pulsar: a 5 Minute Tutorial | Exein Blog
Cover image
A Detailed Analysis of a New Stealer called Stealerium
https://ift.tt/IqfBdrJ
Submitted February 07, 2023 at 08:27PM by CyberMasterV
via reddit https://ift.tt/Mr7ViHQ
https://ift.tt/IqfBdrJ
Submitted February 07, 2023 at 08:27PM by CyberMasterV
via reddit https://ift.tt/Mr7ViHQ
Security Scorecard
[Whitepaper] A Detailed Analysis Of A New Stealer Called Stealerium
Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console
https://ift.tt/SeULhGb
Submitted February 07, 2023 at 09:44PM by thorn42
via reddit https://ift.tt/EXlrA5o
https://ift.tt/SeULhGb
Submitted February 07, 2023 at 09:44PM by thorn42
via reddit https://ift.tt/EXlrA5o
Datadoghq
Discovering a weakness leading to a partial bypass of the login rate limiting in the AWS Console
In this post, we discuss a weakness we discovered in the AWS Console authentication flow that allowed an attacker to partially bypass the login rate limit.
GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: A comprehensive open-source regex database for secret detection.
https://ift.tt/6IWtvPk
Submitted February 07, 2023 at 09:54PM by mazen160
via reddit https://ift.tt/sIVtCpQ
https://ift.tt/6IWtvPk
Submitted February 07, 2023 at 09:54PM by mazen160
via reddit https://ift.tt/sIVtCpQ
GitHub
GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords…
Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more. - GitHub - mazen160/secrets-patterns-db: Secrets Patterns DB: The largest open-so...
Post-Exploitation: Abusing the KeePass Plugin Cache
https://ift.tt/KJV0v2H
Submitted February 07, 2023 at 11:57PM by guedou
via reddit https://ift.tt/M4eDGlU
https://ift.tt/KJV0v2H
Submitted February 07, 2023 at 11:57PM by guedou
via reddit https://ift.tt/M4eDGlU
Quarkslab
Post-Exploitation: Abusing the KeePass Plugin Cache
🔑 Introducing Matano Identity Data Lake for Open Source Cloud-Native SIEM!
https://ift.tt/0uIX5UH
Submitted February 08, 2023 at 01:11AM by shaeqahmed
via reddit https://ift.tt/EH61jAG
https://ift.tt/0uIX5UH
Submitted February 08, 2023 at 01:11AM by shaeqahmed
via reddit https://ift.tt/EH61jAG
www.matano.dev
Matano adds Identity Data Lake | Matano
We're adding support for pulling logs and enrichment data from identity and auth sources to your Matano data lake. This means you can query failed/successful sign-in attempts, view audit logs, and query user information from popular SaaS sources directly…
Recovery noscript for ESXiArgs ransomware
https://ift.tt/qAp2ojD
Submitted February 08, 2023 at 06:06AM by YogiBerra88888
via reddit https://ift.tt/aLZX2q3
https://ift.tt/qAp2ojD
Submitted February 08, 2023 at 06:06AM by YogiBerra88888
via reddit https://ift.tt/aLZX2q3
GitHub
GitHub - cisagov/ESXiArgs-Recover: A tool to recover from ESXiArgs ransomware
A tool to recover from ESXiArgs ransomware. Contribute to cisagov/ESXiArgs-Recover development by creating an account on GitHub.
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game
https://ift.tt/fxTBtmb
Submitted February 08, 2023 at 03:30PM by stashing_the_smack
via reddit https://ift.tt/bnLPGZ1
https://ift.tt/fxTBtmb
Submitted February 08, 2023 at 03:30PM by stashing_the_smack
via reddit https://ift.tt/bnLPGZ1
Avast Threat Labs
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game - Avast Threat Labs
Avast discovered an exploit for CVE-2021-38003 was used in the wild to attack Dota 2 players. This exploit achieved remote code execution on other players' machines by taking advantage of Dota's usage of an outdated V8 version. In response to Avast's findings…
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation) :: jub0bs.com
https://ift.tt/3j7QKxV
Submitted February 08, 2023 at 07:27PM by jub0bs
via reddit https://ift.tt/2ZdgYsB
https://ift.tt/3j7QKxV
Submitted February 08, 2023 at 07:27PM by jub0bs
via reddit https://ift.tt/2ZdgYsB
Jub0Bs
Fearless CORS: a design philosophy for CORS middleware libraries (and a Go implementation)
TL;DR ¶ In this post, I investigate why developers struggle with CORS and I derive Fearless CORS, a design philosophy for better CORS middleware libraries, which comprises the following twelve principles:
Optimise for readability Strive for a simple and…
Optimise for readability Strive for a simple and…
Rustproofing Linux (Part 1, Leaking Addresses)
https://ift.tt/dDYgN8M
Submitted February 08, 2023 at 08:34PM by Gallus
via reddit https://ift.tt/Jw8l73W
https://ift.tt/dDYgN8M
Submitted February 08, 2023 at 08:34PM by Gallus
via reddit https://ift.tt/Jw8l73W
NCC Group Research Blog
Rustproofing Linux (Part 1/4 Leaking Addresses)
Rust is a programming language guaranteeing memory and thread safety while still being able to access raw memory and hardware. This sounds impossible, and it is, that’s why Rust has an unsafe keywo…
Top 10 web hacking techniques of 2022
https://ift.tt/4hdipNu
Submitted February 08, 2023 at 07:55PM by Fugitif
via reddit https://ift.tt/aVfGgDj
https://ift.tt/4hdipNu
Submitted February 08, 2023 at 07:55PM by Fugitif
via reddit https://ift.tt/aVfGgDj
PortSwigger Research
Top 10 web hacking techniques of 2022
Welcome to the Top 10 Web Hacking Techniques of 2022, the 16th edition of our annual community-powered effort to identify the most important and innovative web security research published in the last
A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
https://ift.tt/luvBPMX
Submitted February 08, 2023 at 09:04PM by gfekkas
via reddit https://ift.tt/xw3qCQS
PRIOn - Vulnerability Prioritization Technology
A Year in Review 2022: 100 vulnerabilities you should prioritize - PRIOn
In this article we present the analysis of one hundred (100) vulnerabilities that you should keep an eye on and prioritize them according to your environment.
OpenSSH Pre-Auth Double Free - CVE-2023-25136 - Writeup and Proof-of-Concept
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
https://ift.tt/qgEOI9j
Submitted February 08, 2023 at 11:03PM by n0llbyte
via reddit https://ift.tt/Ux4bwjR
JFrog
CVE-2023-25136 OpenSSH Pre-Auth Double Free Writeup & PoC
Understanding the OpenSSH CVE-2023-25136 high vulnerability. Read our analysis with Proof-of-Concept, learn what's vulnerable, and discover remediations.
Offphish - Phishing revisited in 2023
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
https://ift.tt/cdzPZ7s
Submitted February 09, 2023 at 03:40PM by 0xcsandker
via reddit https://ift.tt/fkaGbeU
www.securesystems.de
Offphish - Phishing revisited in 2023
This blog post evaluates the state of the art with phishing, which techniques are still relevant and what know-how is worth revisiting. Additionally an overview of various techniques across the three stages of a phishing campaign, an overview of features…
Neo4jection: Secrets, Data, and Cloud Exploits - Attacking Neo4j
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
https://ift.tt/0vWoGyr
Submitted February 09, 2023 at 08:26PM by lowlandsmarch
via reddit https://ift.tt/WhrZC48
Varonis
Neo4jection: Secrets, Data, and Cloud Exploits
With the continuous rise of graph databases, especially Neo4j, we're seeing increased discussions among security researchers about issues found in those databases. However, given our experience with graph databases ― from designing complex and scalable solutions…
Exploit Vector Analysis of Emerging 'ESXiArgs' Ransomware
https://ift.tt/8ekw2IE
Submitted February 10, 2023 at 01:18AM by DrinkMoreCodeMore
via reddit https://ift.tt/Ndsr6me
https://ift.tt/8ekw2IE
Submitted February 10, 2023 at 01:18AM by DrinkMoreCodeMore
via reddit https://ift.tt/Ndsr6me
www.greynoise.io
GreyNoise | Exploit Vector Analysis of Emerging ‘ESXiArgs’ Ransomware (a.k.a. Wow do I hate ESXi Threat Intel [right now])
GreyNoise researchers provide context around the mass confusion that is the state of ransomware campaigns against exposed VMWare ESXi hosts and bad attribution takes.
We had a security incident. Here’s what we know.
/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Submitted February 10, 2023 at 01:59AM by sanitybit
via reddit https://ift.tt/86qcYfm
/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Submitted February 10, 2023 at 01:59AM by sanitybit
via reddit https://ift.tt/86qcYfm
Reddit
r/netsec on Reddit
We had a security incident. Here’s what we know. - No votes and no comments
Avalanche Blockchain Vulnerable to 0day DoS
https://ift.tt/sbtlPzg
Submitted February 10, 2023 at 07:47AM by endless
via reddit https://ift.tt/FgTJj6x
https://ift.tt/sbtlPzg
Submitted February 10, 2023 at 07:47AM by endless
via reddit https://ift.tt/FgTJj6x
Livejournal
0Day Avalanche Blockchain API DoS
Author : https://twitter.com/123456 Avalanche just fucked me out of a sizable bug bounty — so I immediately found another bug to disclose to the public. This is a remote API DoS/crash that should OOM chain P and render a vulnerable node mostly or entirely…
Found SaltStack on a network and don't know how to attack the thing? Check out how a few configuration issues and a new spin on Jinja template injections can undo a network managed by Salt
https://ift.tt/ART3g6U
Submitted February 10, 2023 at 09:50AM by SkylightCyber
via reddit https://ift.tt/wAma1bd
https://ift.tt/ART3g6U
Submitted February 10, 2023 at 09:50AM by SkylightCyber
via reddit https://ift.tt/wAma1bd
Skylightcyber
Skylight Cyber | A-Salt: attacking SaltStack
Found SaltStack on a network and don't know how to attack the thing? Check out how a few configuration issues and a new spin on Jinja template injections can undo a network managed by Salt.
secpat2gf: convert secret patterns to gf compatible.
https://ift.tt/LGwKF2W
Submitted February 10, 2023 at 09:22AM by dwisiswant0
via reddit https://ift.tt/6iYSmnM
https://ift.tt/LGwKF2W
Submitted February 10, 2023 at 09:22AM by dwisiswant0
via reddit https://ift.tt/6iYSmnM
GitHub
GitHub - dwisiswant0/secpat2gf: convert secret patterns to gf compatible.
convert secret patterns to gf compatible. Contribute to dwisiswant0/secpat2gf development by creating an account on GitHub.
Find Writable Shares with Python.
https://ift.tt/iyYDhSm
Submitted February 10, 2023 at 06:47PM by oldboy21
via reddit https://ift.tt/eulwT2W
https://ift.tt/iyYDhSm
Submitted February 10, 2023 at 06:47PM by oldboy21
via reddit https://ift.tt/eulwT2W
GitHub
GitHub - oldboy21/RSMBI: Find Writable Shares
Find Writable Shares. Contribute to oldboy21/RSMBI development by creating an account on GitHub.