Evading MDATP for Full Endpoint Compromising
https://ift.tt/UMpH2Zr
Submitted May 08, 2023 at 01:57AM by florilsk
via reddit https://ift.tt/n2VKY3J
https://ift.tt/UMpH2Zr
Submitted May 08, 2023 at 01:57AM by florilsk
via reddit https://ift.tt/n2VKY3J
ETWHash - "He who listens, shall receive" - Nettitude Labs
https://ift.tt/lWC3Vye
Submitted May 08, 2023 at 12:40PM by lefterispanos
via reddit https://ift.tt/ozaPDc8
https://ift.tt/lWC3Vye
Submitted May 08, 2023 at 12:40PM by lefterispanos
via reddit https://ift.tt/ozaPDc8
LRQA
ETWHash -
ETWHash is a small C# tool used during Red Team engagements, that can consume ETW SMB events and extract NetNTLMv2 hashes for cracking offline, unlike currently documented methods.
Building a Red Team Infrastructure in 2023
https://ift.tt/j8J9HCE
Submitted May 08, 2023 at 02:48PM by co1nc1dence
via reddit https://ift.tt/6CoObNa
https://ift.tt/j8J9HCE
Submitted May 08, 2023 at 02:48PM by co1nc1dence
via reddit https://ift.tt/6CoObNa
www.securesystems.de
Building a Red Team Infrastructure in 2023
In this blog post an overview of the different components of a red team infrastructure is given. This includes explanations how these work, as well as the comparison of different solutions and their characteristics.
Backhand v0.12.0: Now supporting custom Squashfs images
https://ift.tt/AI8ZSqv
Submitted May 08, 2023 at 04:59PM by arch_rust
via reddit https://ift.tt/yGQevMt
https://ift.tt/AI8ZSqv
Submitted May 08, 2023 at 04:59PM by arch_rust
via reddit https://ift.tt/yGQevMt
GitHub
Release v0.12.0 · wcampbell0x2a/backhand
Thanks @rbran for the contributions!
backhand
Kind has been extended to take an CompressionAction to have a custom compression and decompression
algorithm. This defaults to the DefaultCompressor i...
backhand
Kind has been extended to take an CompressionAction to have a custom compression and decompression
algorithm. This defaults to the DefaultCompressor i...
PRFs, PRPs and other fantastic things
https://ift.tt/zSmp7qQ
Submitted May 08, 2023 at 08:32PM by feross
via reddit https://ift.tt/yCVgZDf
https://ift.tt/zSmp7qQ
Submitted May 08, 2023 at 08:32PM by feross
via reddit https://ift.tt/yCVgZDf
A Few Thoughts on Cryptographic Engineering
PRFs, PRPs and other fantastic things
A few weeks ago I ran into a conversation on Twitter about the weaknesses of applied cryptography textbooks, and how they tend to spend way too much time lecturing people about Feistel networks and…
GitHub - almandin/ntdsdotsqlite: A small utility to translate NTDS.dit files to SQLite format.
https://ift.tt/oTWZDil
Submitted May 08, 2023 at 11:17PM by almandin_jv
via reddit https://ift.tt/Gyzs0QF
https://ift.tt/oTWZDil
Submitted May 08, 2023 at 11:17PM by almandin_jv
via reddit https://ift.tt/Gyzs0QF
GitHub
GitHub - almandin/ntdsdotsqlite: A small utility to translate NTDS.dit files to SQLite format.
A small utility to translate NTDS.dit files to SQLite format. - almandin/ntdsdotsqlite
Vulnerability Analysis with Ghidra Scripting
https://ift.tt/oReVUfW
Submitted May 09, 2023 at 03:50AM by cy1337
via reddit https://ift.tt/AVR9rLB
https://ift.tt/oReVUfW
Submitted May 09, 2023 at 03:50AM by cy1337
via reddit https://ift.tt/AVR9rLB
Medium
Vulnerability Analysis with Ghidra Scripting
As some of you may have seen, I posted a challenge to use Ghidra to identify a vulnerability in a WarGames themed game. There has been a…
Guardians of the Network: Exploring the World of Intrusion Detection and Prevention Systems
https://ift.tt/XfB0hJY
Submitted May 09, 2023 at 10:56AM by Smooth-Obligation181
via reddit https://ift.tt/qpbH5Ut
https://ift.tt/XfB0hJY
Submitted May 09, 2023 at 10:56AM by Smooth-Obligation181
via reddit https://ift.tt/qpbH5Ut
Codelivly
Guardians of the Network: Exploring the World of Intrusion Detection and Prevention Systems - Codelivly
In today's increasingly digital world, the need for robust cybersecurity measures has never been gre
Backdooring Electron Apps
https://ift.tt/K3wHXaj
Submitted May 09, 2023 at 12:54PM by nv1t
via reddit https://ift.tt/YfQqGng
https://ift.tt/K3wHXaj
Submitted May 09, 2023 at 12:54PM by nv1t
via reddit https://ift.tt/YfQqGng
Inside Out Insights
Backdooring Electron Applications – Inside Out Insights
Recently, we discussed various methods of persistence on corporate devices and a colleague of mine mentioned a tool he had written. We we...
MSI's firmware, Intel Boot Guard private keys leaked
https://ift.tt/G4NpZEd
Submitted May 09, 2023 at 02:07PM by marklarledu
via reddit https://ift.tt/Rq8odwG
https://ift.tt/G4NpZEd
Submitted May 09, 2023 at 02:07PM by marklarledu
via reddit https://ift.tt/Rq8odwG
Help Net Security
MSI’s firmware, Intel Boot Guard private keys leaked
The cybercriminals who breached MSI last month have apparently leaked the company's private code signing keys on their dark web site.
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF...
https://ift.tt/o3kMvwE
Submitted May 09, 2023 at 02:52PM by poltess0
via reddit https://ift.tt/UXS4An9
https://ift.tt/o3kMvwE
Submitted May 09, 2023 at 02:52PM by poltess0
via reddit https://ift.tt/UXS4An9
Jub0Bs
A smorgasbord of a bug chain: postMessage, JSONP, WAF bypass, DOM-based XSS, CORS, CSRF...
TL;DR ¶ A few months ago, while hunting on a public bug-bounty programme, I found a nice little bug chain that involved
an insecure message event listener, a shoddy JSONP endpoint, a WAF bypass, DOM-based XSS on an out-of-scope subdomain, a permissive CORS…
an insecure message event listener, a shoddy JSONP endpoint, a WAF bypass, DOM-based XSS on an out-of-scope subdomain, a permissive CORS…
Introducing resocks - An Encrypted Back-Connect SOCKS Proxy for Network Pivoting
https://ift.tt/fQrwHAa
Submitted May 09, 2023 at 09:13PM by RedTeamPentesting
via reddit https://ift.tt/To3D5tq
https://ift.tt/fQrwHAa
Submitted May 09, 2023 at 09:13PM by RedTeamPentesting
via reddit https://ift.tt/To3D5tq
RedTeam Pentesting - Blog
Introducing resocks - An Encrypted Back-Connect SOCKS Proxy for Network Pivoting
Compromising a host in a company’s perimeter often creates the opportunity to pivot into an internal network. From there on, each additional compromised system may grant us access into further subnets. Pivoting like this is second nature to …
Using AI to find software vulnerabilities in XNU
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
https://ift.tt/c3gi5FB
Submitted May 09, 2023 at 11:17PM by TimGMichaud
via reddit https://ift.tt/XnCs21S
Inulledmyself
Using AI to find software vulnerabilities in XNU
Note : This work took place in May-Aug of 2022. It just took me this long to finally finish writing this (Too busy playing with my SRD 😅) L...
An analysis of partial/intermittent encryption, along with our newest OSS ransomware recovery tool...WHITE PHOENIX.
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
https://ift.tt/DxMJ4tA
Submitted May 10, 2023 at 03:18AM by jat0369
via reddit https://ift.tt/jQNT18v
Cyberark
White Phoenix: Beating Intermittent Encryption
Recently, a new trend has emerged in the world of ransomware: intermittent encryption, the partial encryption of targeted files. Many ransomware groups, such as BlackCat and Play, have adopted...
An AWS IAM Wishlist
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
https://ift.tt/7xKoyME
Submitted May 10, 2023 at 03:08AM by VariousAd5147
via reddit https://ift.tt/TgxWYmH
www.zeuscloud.io
An AWS IAM Wishlist
A wishlist of AWS IAM feature requests
Escaping Parallels Desktop with Plist Injection
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
https://ift.tt/juDxrnp
Submitted May 10, 2023 at 04:09AM by DOTheLOGA
via reddit https://ift.tt/YfROl6u
pwn.win
Escaping Parallels Desktop with Plist Injection
This post details two bugs I found, a plist injection (CVE-2023-27328) and a race condition (CVE-2023-27327), which could be used to escape from a guest Parallels Desktop virtual machine. In this post I’ll break down the findings.
PwnAssistant - Controlling /home's via a Home Assistant RCE
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
https://ift.tt/60ezV9W
Submitted May 10, 2023 at 06:54AM by ffyns
via reddit https://ift.tt/l2Egx4A
Elttam
PwnAssistant - Controlling /home's via a Home Assistant RCE
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Latest Developments in Unblob (Firmware Extraction Tool)
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
https://ift.tt/2a69FgD
Submitted May 10, 2023 at 12:24PM by g_e_r_h_a_r_d
via reddit https://ift.tt/zVZi4l6
ONEKEY
Latest Developments in Unblob (2)
Revolutionize firmware extraction with UNBLOB! Discover the latest developments & advancements in this cutting-edge project. Don't miss latest blog post!
Stockfish, a very popular chess engine, has a buffer overflow vulnerability due to unsanatized input
https://ift.tt/BA9inDf
Submitted May 10, 2023 at 05:24PM by Diesl
via reddit https://ift.tt/A65kTaB
https://ift.tt/BA9inDf
Submitted May 10, 2023 at 05:24PM by Diesl
via reddit https://ift.tt/A65kTaB
GitHub
Increase MAX_MOVES to prevent buffer overflow and stack corruption by ZealanL · Pull Request #4558 · official-stockfish/Stockfish
SF's move buffer ExtMove moveList[MAX_MOVES] assumes a maximum move count of 256, but there are many "impossible" positions in which more than 256 moves are generated.
When running on...
When running on...
ChatGPT-Assisted Implant Development, Part 1.
https://ift.tt/azqV8YO
Submitted May 10, 2023 at 09:09PM by fullspectrumdev
via reddit https://ift.tt/1QnqVGO
https://ift.tt/azqV8YO
Submitted May 10, 2023 at 09:09PM by fullspectrumdev
via reddit https://ift.tt/1QnqVGO
Full Spectrum Things
ChatGPT-Assisted Implant Development, Part 1.
This is a rambling post series, as an introduction to some other, forthcoming posts on the same topic. It is mostly a braindump of sorts as I go through the design process and try get GPT to do some element of my job for me.
So recently I have been
So recently I have been
Security Audit of BlindAI Core, an open source ML deployment solution with Intel SGX enclave
https://ift.tt/wLxS40f
Submitted May 10, 2023 at 11:11PM by Wooden_Rip_2341
via reddit https://ift.tt/o1GBdXu
https://ift.tt/wLxS40f
Submitted May 10, 2023 at 11:11PM by Wooden_Rip_2341
via reddit https://ift.tt/o1GBdXu
Mithril Security Blog
BlindAI Passes an Independent Security Audit by Quarkslab
We take security and open-source data privacy seriously at Mithril Security. So we're very proud that our historical confidential computing solution, BlindAI, was successfully audited by Quarkslab!