Google Lets Anyone See Original Uncropped Images – Proof of Concept
https://ift.tt/fzCShkm
Submitted February 15, 2023 at 08:41AM by moxofoxo
via reddit https://ift.tt/0QdDCtr
https://ift.tt/fzCShkm
Submitted February 15, 2023 at 08:41AM by moxofoxo
via reddit https://ift.tt/0QdDCtr
Google Docs
Google Lets Anyone See Original Uncropped Images – Proof of Concept
Google Lets Anyone See Original Uncropped Images – Proof of Concept Details: https://theintercept.com/2023/02/14/whistleblower-image-crop-document/
cURL audit: How a joke led to significant findings
https://ift.tt/PrWTM4Y
Submitted February 15, 2023 at 10:48AM by Gallus
via reddit https://ift.tt/ugYKaxk
https://ift.tt/PrWTM4Y
Submitted February 15, 2023 at 10:48AM by Gallus
via reddit https://ift.tt/ugYKaxk
Trail of Bits Blog
cURL audit: How a joke led to significant findings
By Maciej Domanski In fall 2022, Trail of Bits audited cURL, a widely-used command-line utility that transfers data between a server and supports various protocols. The project coincided with a Tra…
HAProxy Security Update (CVE-2023-25725) - HTTP content smuggling attack
https://ift.tt/d6ptXHQ
Submitted February 15, 2023 at 10:15AM by Gallus
via reddit https://ift.tt/8ve30Ab
https://ift.tt/d6ptXHQ
Submitted February 15, 2023 at 10:15AM by Gallus
via reddit https://ift.tt/8ve30Ab
Cross-Thread Return Address Predictions
https://ift.tt/xXrvY93
Submitted February 15, 2023 at 02:07PM by Gallus
via reddit https://ift.tt/miH6pZ1
https://ift.tt/xXrvY93
Submitted February 15, 2023 at 02:07PM by Gallus
via reddit https://ift.tt/miH6pZ1
Amd
Cross-Thread Return Address Predictions
Summary AMD internally discovered a potential vulnerability where certain AMD processors may speculatively execute instructions at an incorrect return site after an SMT mode switch that may potentially lead to information disclosure. AMD believes that due…
Server-side prototype pollution: Black-box detection without the DoS
https://ift.tt/ndDGe1w
Submitted February 15, 2023 at 10:12PM by Gallus
via reddit https://ift.tt/D1do06f
https://ift.tt/ndDGe1w
Submitted February 15, 2023 at 10:12PM by Gallus
via reddit https://ift.tt/D1do06f
PortSwigger Research
Server-side prototype pollution: Black-box detection without the DoS
Server-side prototype pollution is hard to detect black-box without causing a DoS. In this post, we introduce a range of safe detection techniques, which we've also implemented in an open source Burp
GitHub - misterch0c/Awesome-Hacking: A collection of various awesome lists for hackers, pentesters and security researchers
https://ift.tt/fLJIVFz
Submitted February 16, 2023 at 12:45AM by Various-Musician-218
via reddit https://ift.tt/JaUOQro
https://ift.tt/fLJIVFz
Submitted February 16, 2023 at 12:45AM by Various-Musician-218
via reddit https://ift.tt/JaUOQro
GitHub
GitHub - misterch0c/Awesome-Hacking: A collection of various awesome lists for hackers, pentesters and security researchers
A collection of various awesome lists for hackers, pentesters and security researchers - GitHub - misterch0c/Awesome-Hacking: A collection of various awesome lists for hackers, pentesters and secur...
Researcher infiltrates phishing syndicate to learn TTP's
https://ift.tt/4xSU8gr
Submitted February 16, 2023 at 09:10PM by CyberArkLabs
via reddit https://ift.tt/BobeNgw
https://ift.tt/4xSU8gr
Submitted February 16, 2023 at 09:10PM by CyberArkLabs
via reddit https://ift.tt/BobeNgw
Cyberark
Phishing as a Service
Introduction Everyone knows what phishing is. It has been around for more than two decades. Now it seems that phishing is more accessible than before. This blog covers how malicious actors can...
[BugTales] REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB
https://ift.tt/j0DPtKa
Submitted February 16, 2023 at 10:01PM by poltess0
via reddit https://ift.tt/wxlfjPq
https://ift.tt/j0DPtKa
Submitted February 16, 2023 at 10:01PM by poltess0
via reddit https://ift.tt/wxlfjPq
labs.taszk.io
[BugTales] REUnziP: Re-Exploiting Huawei Recovery With FaultyUSB
Huawei Recovery Update Zip ToC-ToU Vulnerability
Secure Boot to Heads: A brief history of #Linux Boot Integrity
https://ift.tt/3hJjucx
Submitted February 16, 2023 at 09:56PM by maltfield
via reddit https://ift.tt/xSvupWd
https://ift.tt/3hJjucx
Submitted February 16, 2023 at 09:56PM by maltfield
via reddit https://ift.tt/xSvupWd
Michael Altfield's Tech Blog
Trusted Boot (Anti-Evil-Maid, Heads, and PureBoot) - Michael Altfield's Tech Blog
This post will help to provide historical context and demystify what's under the hood of Heads, PureBoot, and other tools to provide Trusted Boot. I will not be presenting anything new in this article; I merely hope to provide a historical timeline and a…
No More Access Denied - I Am the TrustedInstaller
https://ift.tt/gkMqKpu
Submitted February 17, 2023 at 12:07AM by achilles4828
via reddit https://ift.tt/w6Roj1s
https://ift.tt/gkMqKpu
Submitted February 17, 2023 at 12:07AM by achilles4828
via reddit https://ift.tt/w6Roj1s
FourCore
No more Access Denied - I am TrustedInstaller - FourCore
TrustedInstaller is a Service Account which is used to protect important Windows files and folders from unautorized modification. We take a look at how to obtain TrustedInstaller privileges to delete Windows Defender directory
Outdated Default AWS IAM Policy Language Versions | CloudQuery
https://ift.tt/L2jKyAC
Submitted February 17, 2023 at 03:51AM by jsonpile
via reddit https://ift.tt/5flPX1N
https://ift.tt/L2jKyAC
Submitted February 17, 2023 at 03:51AM by jsonpile
via reddit https://ift.tt/5flPX1N
CloudQuery
Outdated Default AWS IAM Policy Language Versions | CloudQuery
Amazon Web Services (AWS) has 2 different policy versions for writing JSON IAM policies. This lesser known nuance creates issues with policy variables and newer features. This blog focuses on identifying IAM policies still using the outdated IAM language…
Guide For Beginners: Syslog Configuration on Cisco Devices
https://ift.tt/igNQkRh
Submitted February 17, 2023 at 12:35PM by DenofBlerds
via reddit https://ift.tt/a4FTO0x
https://ift.tt/igNQkRh
Submitted February 17, 2023 at 12:35PM by DenofBlerds
via reddit https://ift.tt/a4FTO0x
Cyber Coastal
Cybersecurity Guide For Beginners: Syslog Configuration on Cisco Devices - Cyber Coastal
https://youtu.be/bDIIj3J7JcMSyslog is an open-source protocol used to collect log messages from many different sources, including operating systems, applications, routers, switches, and other network devices. It is used to manage network events, detect security…
CVE-2023-20032: ClamAV Remote Code Execution (CVSS 9.8)
https://ift.tt/6MWhVxJ
Submitted February 17, 2023 at 02:30PM by qwerty0x41
via reddit https://ift.tt/64iWpLO
https://ift.tt/6MWhVxJ
Submitted February 17, 2023 at 02:30PM by qwerty0x41
via reddit https://ift.tt/64iWpLO
Cisco
Cisco Security Advisory: ClamAV HFS+ Partition Scanning Buffer Overflow Vulnerability Affecting Cisco Products: February 2023
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated…
A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated…
Reinforcement learning for red/blue team automation
https://ift.tt/80KGPqj
Submitted February 17, 2023 at 03:17PM by limmen
via reddit https://ift.tt/Gd4TF0S
https://ift.tt/80KGPqj
Submitted February 17, 2023 at 03:17PM by limmen
via reddit https://ift.tt/Gd4TF0S
GitHub
GitHub - Limmen/awesome-rl-for-cybersecurity: A curated list of resources dedicated to reinforcement learning applied to cyber…
A curated list of resources dedicated to reinforcement learning applied to cyber security. - GitHub - Limmen/awesome-rl-for-cybersecurity: A curated list of resources dedicated to reinforcement le...
Ghidra Golf: A Reverse Engineering CTF
https://ift.tt/kqCJSeZ
Submitted February 17, 2023 at 05:17PM by DLLCoolJ
via reddit https://ift.tt/Bxs2OEL
https://ift.tt/kqCJSeZ
Submitted February 17, 2023 at 05:17PM by DLLCoolJ
via reddit https://ift.tt/Bxs2OEL
GitHub
Ghidra Golf
OUSD R&E Sponsored Automated Reverse Engineering CTF - Ghidra Golf
Introducing Proxy Enriched Sequence Diagrams (PESD). New Burp Plugin.
https://ift.tt/c6Y0Oti
Submitted February 17, 2023 at 05:03PM by nibblesec
via reddit https://ift.tt/BuewIcL
https://ift.tt/c6Y0Oti
Submitted February 17, 2023 at 05:03PM by nibblesec
via reddit https://ift.tt/BuewIcL
Doyensec
Introducing Proxy Enriched Sequence Diagrams (PESD) · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
How we Hacked Apple Twice in one day for Fun (and Profit)
https://ift.tt/t18n6ZB
Submitted February 17, 2023 at 08:14PM by pectoral
via reddit https://ift.tt/gQ2lw6J
https://ift.tt/t18n6ZB
Submitted February 17, 2023 at 08:14PM by pectoral
via reddit https://ift.tt/gQ2lw6J
Medium
Hacking Apple: Two Successful Exploits and Positive Thoughts on their Bug Bounty Program
Hacking Apple is no easy feat. With some of the most talented security professionals working on protecting their systems, it’s hard to…
ICS and OT Vulnerabilities Analysis for 2022
https://ift.tt/1z8l52w
Submitted February 17, 2023 at 09:09PM by derp6996
via reddit https://ift.tt/3ZNMK1H
https://ift.tt/1z8l52w
Submitted February 17, 2023 at 09:09PM by derp6996
via reddit https://ift.tt/3ZNMK1H
Claroty
Report: State of XIoT Security: 2H 2022
Uncover the latest trends in the State of XIoT Security Report for 2H 2022. Discover the changing landscape of vulnerabilities in OT, IoT, and IoMT.
chvancooten/NimPlant: A light-weight first-stage C2 implant written in Nim.
https://ift.tt/tpmMDKW
Submitted February 18, 2023 at 08:33AM by Vegetable_Treat_5017
via reddit https://ift.tt/2cFd1G9
https://ift.tt/tpmMDKW
Submitted February 18, 2023 at 08:33AM by Vegetable_Treat_5017
via reddit https://ift.tt/2cFd1G9
GitHub
GitHub - chvancooten/NimPlant: A light-weight first-stage C2 implant written in Nim.
A light-weight first-stage C2 implant written in Nim. - GitHub - chvancooten/NimPlant: A light-weight first-stage C2 implant written in Nim.
Azure B2C Crypto Misuse and Account Compromise
https://ift.tt/rECKWDX
Submitted February 18, 2023 at 07:03PM by dlorenc
via reddit https://ift.tt/Y5lbgEs
https://ift.tt/rECKWDX
Submitted February 18, 2023 at 07:03PM by dlorenc
via reddit https://ift.tt/Y5lbgEs
Praetorian
Azure B2C Crypto Misuse and Account Compromise -
Microsoft’s Azure B2C service misused cryptography, which allowed an attacker to craft an OAuth refresh token to access a victim account.
Small utility to chunk up a large BloodHound JSON file into smaller files for faster importing.
https://ift.tt/KxLyd86
Submitted February 19, 2023 at 04:08AM by ustayready
via reddit https://ift.tt/C0uD57s
https://ift.tt/KxLyd86
Submitted February 19, 2023 at 04:08AM by ustayready
via reddit https://ift.tt/C0uD57s
GitHub
GitHub - ustayready/ShredHound: Small utility to chunk up a large BloodHound JSON file into smaller files for importing.
Small utility to chunk up a large BloodHound JSON file into smaller files for importing. - GitHub - ustayready/ShredHound: Small utility to chunk up a large BloodHound JSON file into smaller files ...