Vulnerability write-up - "Dangerous assumptions" (6 CVEs in Node.js packages)
https://ift.tt/jO0uhAm
Submitted February 22, 2023 at 10:10PM by ThomasRinsma
via reddit https://ift.tt/nf5xuNs
https://ift.tt/jO0uhAm
Submitted February 22, 2023 at 10:10PM by ThomasRinsma
via reddit https://ift.tt/nf5xuNs
Codean
Vulnerability write-up - "Dangerous assumptions"
d08e8132-1c34-4223-b83d-9b7622e0f9c4
Exploit Airlines to get Free WiFi - Airline Vulnerability
https://ift.tt/CRyj1H0
Submitted February 23, 2023 at 09:46AM by brekfasbaksetz
via reddit https://ift.tt/lBr6OmZ
https://ift.tt/CRyj1H0
Submitted February 23, 2023 at 09:46AM by brekfasbaksetz
via reddit https://ift.tt/lBr6OmZ
AD Offsec Testing Tools Pre-Compiled, up to date, and ready to use
https://ift.tt/lrj2Yk9
Submitted February 23, 2023 at 12:16PM by Pleasant-Drawer729
via reddit https://ift.tt/2DK3ouZ
https://ift.tt/lrj2Yk9
Submitted February 23, 2023 at 12:16PM by Pleasant-Drawer729
via reddit https://ift.tt/2DK3ouZ
GitHub
GitHub - Syslifters/offsec-tools: Compiled tools for internal assessments
Compiled tools for internal assessments. Contribute to Syslifters/offsec-tools development by creating an account on GitHub.
Detecting Server-Side Prototype Pollution
https://ift.tt/YqM9En8
Submitted February 23, 2023 at 04:29PM by dcthatch
via reddit https://ift.tt/fcBkS5N
https://ift.tt/YqM9En8
Submitted February 23, 2023 at 04:29PM by dcthatch
via reddit https://ift.tt/fcBkS5N
www.intruder.io
Detecting Server-Side Prototype Pollution
Prototype pollution bugs have been a feature in many CTFs in recent years, and real-world examples in open-source applications have led to impactful exploits such as remote code execution and denial-of-service. The discovery of these bugs has long relied…
41 imposter HTTP libraries discovered on PyPI
https://ift.tt/4yq59vL
Submitted February 23, 2023 at 06:45PM by ledgit
via reddit https://ift.tt/8vzaGIc
https://ift.tt/4yq59vL
Submitted February 23, 2023 at 06:45PM by ledgit
via reddit https://ift.tt/8vzaGIc
ReversingLabs
Developers beware: Imposter HTTP libraries lurk on PyPI
ReversingLabs researchers discovered more than three dozen malicious packages on the PyPI repository that mimic popular HTTP libraries.
Ronin 2.0–Open Source Ruby toolkit for security research and development
https://ift.tt/LCFkpP6
Submitted February 23, 2023 at 10:00PM by pmz
via reddit https://ift.tt/eCwdgrf
https://ift.tt/LCFkpP6
Submitted February 23, 2023 at 10:00PM by pmz
via reddit https://ift.tt/eCwdgrf
www.i-programmer.info
Ronin 2.0–Open Source Ruby toolkit for security research and development
Programming book reviews, programming tutorials,programming news, C#, Ruby, Python,C, C++, PHP, Visual Basic, Computer book reviews, computer history, programming history, joomla, theory, spreadsheets and more.
520 Malware Packages Published to PyPI in Ongoing Attack
https://ift.tt/3wEXDBo
Submitted February 24, 2023 at 07:01AM by louis11
via reddit https://ift.tt/sa23dtj
https://ift.tt/3wEXDBo
Submitted February 24, 2023 at 07:01AM by louis11
via reddit https://ift.tt/sa23dtj
Phylum
Phylum Discovers Aggressive Attack on PyPI Attempting to Deliver Rust Executable
Phylum discovers ~6,000 malicious packages published to PyPI shipping Rust stage 1 executables in ongoing malware campaign.
OpenEMR - Remote Code Execution in your Healthcare System
https://ift.tt/Bm0HuFK
Submitted February 24, 2023 at 02:50PM by _noraj_
via reddit https://ift.tt/DeCbOGI
https://ift.tt/Bm0HuFK
Submitted February 24, 2023 at 02:50PM by _noraj_
via reddit https://ift.tt/DeCbOGI
Sonarsource
OpenEMR - Remote Code Execution in your Healthcare System
We recently discovered three vulnerabilities that allow arbitrary code execution on OpenEMR. Let’s see what we can learn from them and discuss their patches!
The code that wasn't there: Reading memory on an Android device by accident
https://ift.tt/CAlZn4v
Submitted February 24, 2023 at 02:00PM by albinowax
via reddit https://ift.tt/ZRXAs3u
https://ift.tt/CAlZn4v
Submitted February 24, 2023 at 02:00PM by albinowax
via reddit https://ift.tt/ZRXAs3u
The GitHub Blog
The code that wasn't there: Reading memory on an Android device by accident
CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space…
SSO Gadgets: Escalate (Self-)XSS to ATO
https://ift.tt/8C6lOfB
Submitted February 24, 2023 at 03:43PM by albinowax
via reddit https://ift.tt/JlDMeTX
https://ift.tt/8C6lOfB
Submitted February 24, 2023 at 03:43PM by albinowax
via reddit https://ift.tt/JlDMeTX
security.lauritz-holtmann.de
SSO Gadgets: Escalate (Self-)XSS to ATO
With the rise of Single-Sign-On (SSO) and especially OAuth 2.0 and OpenID Connect (OIDC), the attack surface of web applications has increased significantly. In this post, I will show how to escalate a Cross-Site Scripting (XSS) vulnerability to an Account…
A Review of Attacks Against Language-Based Package Managers
https://ift.tt/z7sWK5J
Submitted February 24, 2023 at 05:51PM by panoptischall
via reddit https://ift.tt/XzqE8o0
https://ift.tt/z7sWK5J
Submitted February 24, 2023 at 05:51PM by panoptischall
via reddit https://ift.tt/XzqE8o0
Yet, another packer/loader with my very own implementation of GetProcAddress and GetModuleHandle to dinamically fetch function addresses, as well as AES payload and function name encryption with a derived SHA256 key
https://ift.tt/s0D89Ux
Submitted February 24, 2023 at 09:49PM by oldboy21
via reddit https://ift.tt/Ybyirxv
https://ift.tt/s0D89Ux
Submitted February 24, 2023 at 09:49PM by oldboy21
via reddit https://ift.tt/Ybyirxv
GitHub
GitHub - oldboy21/CGPL: Yet, Another Packer/Loader
Yet, Another Packer/Loader . Contribute to oldboy21/CGPL development by creating an account on GitHub.
Wrote a hands-on blog series for anyone trying to get a start as a SOC analyst -- feedback welcome!
https://ift.tt/JGAI5if
Submitted February 25, 2023 at 09:26AM by skybound5
via reddit https://ift.tt/7Ani2hd
https://ift.tt/JGAI5if
Submitted February 25, 2023 at 09:26AM by skybound5
via reddit https://ift.tt/7Ani2hd
Eric’s Substack
So you want to be a SOC Analyst? Intro
A blog series for someone wanting to get a start as a SOC Analyst
Awesome Security Newsletters
https://ift.tt/r3ciYsD
Submitted February 26, 2023 at 09:29AM by mymalema
via reddit https://ift.tt/HFSVPKy
https://ift.tt/r3ciYsD
Submitted February 26, 2023 at 09:29AM by mymalema
via reddit https://ift.tt/HFSVPKy
GitHub
GitHub - TalEliyahu/awesome-security-newsletters: Periodic cyber security newsletters that capture the latest news, summaries of…
Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attac...
open-appsec provides ML-based API Security add-on for Kong API Gateways
https://ift.tt/bE1wpCr
Submitted February 26, 2023 at 03:30PM by Hen2022
via reddit https://ift.tt/CTXHhAE
https://ift.tt/bE1wpCr
Submitted February 26, 2023 at 03:30PM by Hen2022
via reddit https://ift.tt/CTXHhAE
open-appsec
open-appsec provides ML-based API Security add-on for Kong API Gateways
open-appsec provides Kong users effective and integrated API Security including preemptive protection against zero-day attacks.
Scripts for playing with WinDbg JS API (hugsy/windbg_js_noscripts)
https://ift.tt/WZo6rz3
Submitted February 27, 2023 at 06:57AM by Gallus
via reddit https://ift.tt/wdD2oji
https://ift.tt/WZo6rz3
Submitted February 27, 2023 at 06:57AM by Gallus
via reddit https://ift.tt/wdD2oji
GitHub
GitHub - hugsy/windbg_js_noscripts: Toy noscripts for playing with WinDbg JS API
Toy noscripts for playing with WinDbg JS API. Contribute to hugsy/windbg_js_noscripts development by creating an account on GitHub.
RIG Exploit Kit: In-Depth Analysis
https://ift.tt/Ll56PJd
Submitted February 27, 2023 at 09:05PM by wtfse
via reddit https://ift.tt/oRvbymI
https://ift.tt/Ll56PJd
Submitted February 27, 2023 at 09:05PM by wtfse
via reddit https://ift.tt/oRvbymI
ParamAngler - tool for testing specific payload on each parameter
https://ift.tt/8QEtpX6
Submitted February 28, 2023 at 01:17AM by spajky_yt
via reddit https://ift.tt/S1VIJNn
https://ift.tt/8QEtpX6
Submitted February 28, 2023 at 01:17AM by spajky_yt
via reddit https://ift.tt/S1VIJNn
GitHub
GitHub - spyx/ParamAngler
Contribute to spyx/ParamAngler development by creating an account on GitHub.
Lastpass Quietly indicates that Enterprise Users' K2s were accessed
https://ift.tt/s6EpGyF
Submitted February 28, 2023 at 01:12AM by csanders_
via reddit https://ift.tt/6McgLTz
https://ift.tt/s6EpGyF
Submitted February 28, 2023 at 01:12AM by csanders_
via reddit https://ift.tt/6McgLTz
Lastpass
Security Bulletin: Recommended Actions for LastPass Business Administrators
Your organization’s security is vital to our mutual success, so we’ve created this guide to help you respond to the recent LastPass security incident in a way that meets your security posture and environment’s needs.
It’s All Bad News: An update on how the Lastpass breach affects Lastpass SSO
https://ift.tt/uhptTmf
Submitted February 28, 2023 at 04:30AM by csanders_
via reddit https://ift.tt/zomdyug
https://ift.tt/uhptTmf
Submitted February 28, 2023 at 04:30AM by csanders_
via reddit https://ift.tt/zomdyug
Medium
It’s All Bad News: An update on how the Lastpass breach affects Lastpass SSO
Every week, almost without fail, I come across one thing that confuses, entertains, or most commonly infuriates me. I’ve decided to keep a…
SPIP Remote Code Execution (pre-auth)
https://ift.tt/aZ23R6X
Submitted February 28, 2023 at 03:29AM by EasyAd9596
via reddit https://ift.tt/mpj8GsQ
https://ift.tt/aZ23R6X
Submitted February 28, 2023 at 03:29AM by EasyAd9596
via reddit https://ift.tt/mpj8GsQ