I created a GitHub repo for learning application security from scratch. It's perfect for beginners and includes a comprehensive list of reference links. But it's not complete yet! Contributors are welcome to add more details.
https://ift.tt/rdzjB1t
Submitted May 06, 2023 at 11:56PM by Ano_F
via reddit https://ift.tt/hlg8raq
https://ift.tt/rdzjB1t
Submitted May 06, 2023 at 11:56PM by Ano_F
via reddit https://ift.tt/hlg8raq
GitHub
GitHub - Anof-cyber/Application-Security: Resources for Application Security including Web, API, Android, iOS and Thick Client
Resources for Application Security including Web, API, Android, iOS and Thick Client - Anof-cyber/Application-Security
Dependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot
https://ift.tt/7Qin9mG
Submitted May 07, 2023 at 01:08AM by giraffesecurity
via reddit https://ift.tt/TV64zcy
https://ift.tt/7Qin9mG
Submitted May 07, 2023 at 01:08AM by giraffesecurity
via reddit https://ift.tt/TV64zcy
Breaking down Reverse shell commands
https://ift.tt/rCApuhj
Submitted May 07, 2023 at 10:04PM by adityatelange
via reddit https://ift.tt/bjpW9AS
https://ift.tt/rCApuhj
Submitted May 07, 2023 at 10:04PM by adityatelange
via reddit https://ift.tt/bjpW9AS
Aditya Telange
Breaking down Reverse shell commands
In pentesting assessments and CTFs we always need reverse shells to execute commands on target machine once we have exploited a system and have a command injection at some point in our engagement.
For that we have an awesome project: revshells.com or reverse…
For that we have an awesome project: revshells.com or reverse…
Evading MDATP for Full Endpoint Compromising
https://ift.tt/UMpH2Zr
Submitted May 08, 2023 at 01:57AM by florilsk
via reddit https://ift.tt/n2VKY3J
https://ift.tt/UMpH2Zr
Submitted May 08, 2023 at 01:57AM by florilsk
via reddit https://ift.tt/n2VKY3J
ETWHash - "He who listens, shall receive" - Nettitude Labs
https://ift.tt/lWC3Vye
Submitted May 08, 2023 at 12:40PM by lefterispanos
via reddit https://ift.tt/ozaPDc8
https://ift.tt/lWC3Vye
Submitted May 08, 2023 at 12:40PM by lefterispanos
via reddit https://ift.tt/ozaPDc8
LRQA
ETWHash -
ETWHash is a small C# tool used during Red Team engagements, that can consume ETW SMB events and extract NetNTLMv2 hashes for cracking offline, unlike currently documented methods.
Building a Red Team Infrastructure in 2023
https://ift.tt/j8J9HCE
Submitted May 08, 2023 at 02:48PM by co1nc1dence
via reddit https://ift.tt/6CoObNa
https://ift.tt/j8J9HCE
Submitted May 08, 2023 at 02:48PM by co1nc1dence
via reddit https://ift.tt/6CoObNa
www.securesystems.de
Building a Red Team Infrastructure in 2023
In this blog post an overview of the different components of a red team infrastructure is given. This includes explanations how these work, as well as the comparison of different solutions and their characteristics.
Backhand v0.12.0: Now supporting custom Squashfs images
https://ift.tt/AI8ZSqv
Submitted May 08, 2023 at 04:59PM by arch_rust
via reddit https://ift.tt/yGQevMt
https://ift.tt/AI8ZSqv
Submitted May 08, 2023 at 04:59PM by arch_rust
via reddit https://ift.tt/yGQevMt
GitHub
Release v0.12.0 · wcampbell0x2a/backhand
Thanks @rbran for the contributions!
backhand
Kind has been extended to take an CompressionAction to have a custom compression and decompression
algorithm. This defaults to the DefaultCompressor i...
backhand
Kind has been extended to take an CompressionAction to have a custom compression and decompression
algorithm. This defaults to the DefaultCompressor i...
PRFs, PRPs and other fantastic things
https://ift.tt/zSmp7qQ
Submitted May 08, 2023 at 08:32PM by feross
via reddit https://ift.tt/yCVgZDf
https://ift.tt/zSmp7qQ
Submitted May 08, 2023 at 08:32PM by feross
via reddit https://ift.tt/yCVgZDf
A Few Thoughts on Cryptographic Engineering
PRFs, PRPs and other fantastic things
A few weeks ago I ran into a conversation on Twitter about the weaknesses of applied cryptography textbooks, and how they tend to spend way too much time lecturing people about Feistel networks and…
GitHub - almandin/ntdsdotsqlite: A small utility to translate NTDS.dit files to SQLite format.
https://ift.tt/oTWZDil
Submitted May 08, 2023 at 11:17PM by almandin_jv
via reddit https://ift.tt/Gyzs0QF
https://ift.tt/oTWZDil
Submitted May 08, 2023 at 11:17PM by almandin_jv
via reddit https://ift.tt/Gyzs0QF
GitHub
GitHub - almandin/ntdsdotsqlite: A small utility to translate NTDS.dit files to SQLite format.
A small utility to translate NTDS.dit files to SQLite format. - almandin/ntdsdotsqlite
Vulnerability Analysis with Ghidra Scripting
https://ift.tt/oReVUfW
Submitted May 09, 2023 at 03:50AM by cy1337
via reddit https://ift.tt/AVR9rLB
https://ift.tt/oReVUfW
Submitted May 09, 2023 at 03:50AM by cy1337
via reddit https://ift.tt/AVR9rLB
Medium
Vulnerability Analysis with Ghidra Scripting
As some of you may have seen, I posted a challenge to use Ghidra to identify a vulnerability in a WarGames themed game. There has been a…
Guardians of the Network: Exploring the World of Intrusion Detection and Prevention Systems
https://ift.tt/XfB0hJY
Submitted May 09, 2023 at 10:56AM by Smooth-Obligation181
via reddit https://ift.tt/qpbH5Ut
https://ift.tt/XfB0hJY
Submitted May 09, 2023 at 10:56AM by Smooth-Obligation181
via reddit https://ift.tt/qpbH5Ut
Codelivly
Guardians of the Network: Exploring the World of Intrusion Detection and Prevention Systems - Codelivly
In today's increasingly digital world, the need for robust cybersecurity measures has never been gre
Backdooring Electron Apps
https://ift.tt/K3wHXaj
Submitted May 09, 2023 at 12:54PM by nv1t
via reddit https://ift.tt/YfQqGng
https://ift.tt/K3wHXaj
Submitted May 09, 2023 at 12:54PM by nv1t
via reddit https://ift.tt/YfQqGng
Inside Out Insights
Backdooring Electron Applications – Inside Out Insights
Recently, we discussed various methods of persistence on corporate devices and a colleague of mine mentioned a tool he had written. We we...
MSI's firmware, Intel Boot Guard private keys leaked
https://ift.tt/G4NpZEd
Submitted May 09, 2023 at 02:07PM by marklarledu
via reddit https://ift.tt/Rq8odwG
https://ift.tt/G4NpZEd
Submitted May 09, 2023 at 02:07PM by marklarledu
via reddit https://ift.tt/Rq8odwG
Help Net Security
MSI’s firmware, Intel Boot Guard private keys leaked
The cybercriminals who breached MSI last month have apparently leaked the company's private code signing keys on their dark web site.
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF...
https://ift.tt/o3kMvwE
Submitted May 09, 2023 at 02:52PM by poltess0
via reddit https://ift.tt/UXS4An9
https://ift.tt/o3kMvwE
Submitted May 09, 2023 at 02:52PM by poltess0
via reddit https://ift.tt/UXS4An9
Jub0Bs
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF...
TL;DR ¶ A few months ago, while hunting on a public bug-bounty programme, I found a nice little bug chain that involved
an insecure message event listener, a shoddy JSONP endpoint, a WAF bypass, DOM-based XSS on an out-of-scope subdomain, a permissive CORS…
an insecure message event listener, a shoddy JSONP endpoint, a WAF bypass, DOM-based XSS on an out-of-scope subdomain, a permissive CORS…
Introducing resocks - An Encrypted Back-Connect SOCKS Proxy for Network Pivoting
https://ift.tt/fQrwHAa
Submitted May 09, 2023 at 09:13PM by RedTeamPentesting
via reddit https://ift.tt/To3D5tq
https://ift.tt/fQrwHAa
Submitted May 09, 2023 at 09:13PM by RedTeamPentesting
via reddit https://ift.tt/To3D5tq
RedTeam Pentesting - Blog
Introducing resocks - An Encrypted Back-Connect SOCKS Proxy for Network Pivoting
Compromising a host in a company’s perimeter often creates the opportunity to pivot into an internal network. From there on, each additional compromised system may grant us access into further subnets. Pivoting like this is second nature to …
Using AI to find software vulnerabilities in XNU
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
Inulledmyself
Using AI to find software vulnerabilities in XNU
Note : This work took place in May-Aug of 2022. It just took me this long to finally finish writing this (Too busy playing with my SRD 😅) L...
An analysis of partial/intermittent encryption, along with our newest OSS ransomware recovery tool...WHITE PHOENIX.
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
Cyberark
White Phoenix: Beating Intermittent Encryption
Recently, a new trend has emerged in the world of ransomware: intermittent encryption, the partial encryption of targeted files. Many ransomware groups, such as BlackCat and Play, have adopted...
An AWS IAM Wishlist
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
www.zeuscloud.io
An AWS IAM Wishlist
A wishlist of AWS IAM feature requests
Escaping Parallels Desktop with Plist Injection
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
pwn.win
Escaping Parallels Desktop with Plist Injection
This post details two bugs I found, a plist injection (CVE-2023-27328) and a race condition (CVE-2023-27327), which could be used to escape from a guest Parallels Desktop virtual machine. In this post I’ll break down the findings.
PwnAssistant - Controlling /home's via a Home Assistant RCE
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
Elttam
PwnAssistant - Controlling /home's via a Home Assistant RCE
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Latest Developments in Unblob (Firmware Extraction Tool)
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
ONEKEY
Latest Developments in Unblob (2)
Revolutionize firmware extraction with UNBLOB! Discover the latest developments & advancements in this cutting-edge project. Don't miss latest blog post!