[CVE-2023-33243] STARFACE: Authentication with Password Hash Possible
https://ift.tt/ACuO1lg
Submitted June 01, 2023 at 05:35PM by RedTeamPentesting
via reddit https://ift.tt/X4J7sN0
https://ift.tt/ACuO1lg
Submitted June 01, 2023 at 05:35PM by RedTeamPentesting
via reddit https://ift.tt/X4J7sN0
www.redteam-pentesting.de
STARFACE: Authentication with Password Hash Possible
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's…
Printerlogic Multiple Vulnerabilities - Published at Full Disclosure
https://ift.tt/9IUv1mp
Submitted June 01, 2023 at 06:54PM by 4SysAdmin
via reddit https://ift.tt/p5TnEXZ
https://ift.tt/9IUv1mp
Submitted June 01, 2023 at 06:54PM by 4SysAdmin
via reddit https://ift.tt/p5TnEXZ
seclists.org
Full Disclosure: Printerlogic multiple vulnerabilities
Reversing Python Pickles
https://ift.tt/JyZvfR8
Submitted June 01, 2023 at 09:24PM by nibblesec
via reddit https://ift.tt/vNYL8GR
https://ift.tt/JyZvfR8
Submitted June 01, 2023 at 09:24PM by nibblesec
via reddit https://ift.tt/vNYL8GR
Doyensec
Reversing Pickles with r2pickledec · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
TyphoonCon Capture The Flag 2023 - specially crafted challenges alongside fantastic prizes
https://ift.tt/gIocu9y
Submitted June 01, 2023 at 08:55PM by Marsy_star
via reddit https://ift.tt/vJYxA5t
https://ift.tt/gIocu9y
Submitted June 01, 2023 at 08:55PM by Marsy_star
via reddit https://ift.tt/vJYxA5t
Typhooncon
TyphoonCon Capture The Flag 2023
WELCOME TO TYPHOONCON CTF!Typhooncon CTF is back for the third year in a row! As part of TyphoonCon 2023, we’ll be hosting an on-site/online competition with specially crafted challenges alongside fantastic prizes
REGISTER NOW
…
REGISTER NOW
…
Gigabyte Bios Update System Insecure and Vulnerable to Supply Chain Attack
https://ift.tt/rgfep7A
Submitted June 02, 2023 at 02:25AM by asdf3
via reddit https://ift.tt/TR19ZDr
https://ift.tt/rgfep7A
Submitted June 02, 2023 at 02:25AM by asdf3
via reddit https://ift.tt/TR19ZDr
Eclypsium | Supply Chain Security for the Modern Enterprise
Supply Chain Risk from Gigabyte App Center Backdoor - Eclypsium | Supply Chain Security for the Modern Enterprise
Recently, the Eclypsium platform began detecting suspected backdoor-like behavior within Gigabyte systems in the wild. These detections were driven by heuristic detection methods, which play an important role in detecting new, previously-unknown supply chain…
Free video course: Hacking DVWS (modern DVWA) with Burp Suite
https://www.youtube.com/playlist?list=PLz_SG4MKcA4m1p-QPvkLaX6gVrCIHwkCj
Submitted June 02, 2023 at 12:03PM by 0rsinium
via reddit https://ift.tt/6qMaUZH
https://www.youtube.com/playlist?list=PLz_SG4MKcA4m1p-QPvkLaX6gVrCIHwkCj
Submitted June 02, 2023 at 12:03PM by 0rsinium
via reddit https://ift.tt/6qMaUZH
Reddit
Free video course: Hacking DVWS (modern DVWA) with Burp Suite : r/netsec
481K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to…
Operation Triangulation: iOS devices targeted with previously unknown malware
https://ift.tt/lUK8dtg
Submitted June 04, 2023 at 08:29PM by execveat
via reddit https://ift.tt/32tVbpP
https://ift.tt/lUK8dtg
Submitted June 04, 2023 at 08:29PM by execveat
via reddit https://ift.tt/32tVbpP
Securelist
Operation Triangulation: iOS devices targeted with previously unknown malware
While monitoring the traffic of our own corporate Wi-Fi network, we noticed suspicious activity that originated from several iOS-based phones. Since it is impossible to inspect modern iOS devices from the inside, we created offline backups of the devices…
Unpacking Shellcode with Ghidra Emulator
https://ift.tt/cHnVosl
Submitted June 04, 2023 at 10:40PM by cy1337
via reddit https://ift.tt/wfvQukN
https://ift.tt/cHnVosl
Submitted June 04, 2023 at 10:40PM by cy1337
via reddit https://ift.tt/wfvQukN
Medium
Unpacking Shellcode with Ghidra Emulator
In this post, I use Ghidra’s emulator to unpack a Metasploit XOR encoded reverse shell to get decompiled output with resolved syscalls.
RedRays Uncovers Alarming Scope of Breach: Urgent Action Required to Safeguard Critical Systems
https://ift.tt/3V48qeL
Submitted June 05, 2023 at 02:28AM by vah_13
via reddit https://ift.tt/42UfYlG
https://ift.tt/3V48qeL
Submitted June 05, 2023 at 02:28AM by vah_13
via reddit https://ift.tt/42UfYlG
RedRays - Your SAP Security Solution
Press release: RedRays discovered major cybersecurity leak affects 4800 domains
RedRays uncovers major breach: 4,800+ domains affected, including top crypto exchanges, Google accounts, and government entities. 2,000+ impacted enterprise software users and over 100 banks. Urgent action needed to strengthen cybersecurity defenses. RedRays…
kitabisa/teler-waf: Introduces external custom rules & DSL expression support!
https://ift.tt/PbwB8to
Submitted June 05, 2023 at 08:05AM by dwisiswant0
via reddit https://ift.tt/KH0CFxB
https://ift.tt/PbwB8to
Submitted June 05, 2023 at 08:05AM by dwisiswant0
via reddit https://ift.tt/KH0CFxB
GitHub
Introduces external custom rules & DSL expression support! · teler-sh/teler-waf · Discussion #45
I'm thrilled to announce the new release of teler-waf v1 (beta) just hit the streets with highly anticipated and powerful features: the ability to load external custom rules and full support fo...
Storing Passwords - A Journey of Common Pitfalls
https://ift.tt/bL9Iqih
Submitted June 05, 2023 at 07:08PM by RedTeamPentesting
via reddit https://ift.tt/imWQCjs
https://ift.tt/bL9Iqih
Submitted June 05, 2023 at 07:08PM by RedTeamPentesting
via reddit https://ift.tt/imWQCjs
RedTeam Pentesting - Blog
Storing Passwords - A Journey of Common Pitfalls
As pentesters, we regularly see creative ways of handling authentication and almost as often we see the pitfalls that come along with these unconventional ways. For instance, we recently discovered a vulnerability in the web interface of STARFACE PBX …
Using PANDA to search for F.L.I.R.T. signatures during process execution
https://ift.tt/umZ0lUW
Submitted June 05, 2023 at 09:28PM by whisperingmime
via reddit https://ift.tt/qhkvJ6W
https://ift.tt/umZ0lUW
Submitted June 05, 2023 at 09:28PM by whisperingmime
via reddit https://ift.tt/qhkvJ6W
Blog by Joren Vrancken
Using PANDA to search for F.L.I.R.T. signatures during process execution
When a malware analyst gets a new malware sample to analyze, one of the first questions they might have, is what functions are called during the execution of the sample. To solve this problem, we can use any old debugger to walk through the sample manually…
Ripping Off Professional Criminals by Fermenting Onions - Phishing Darknet Users for Bitcoins
https://ift.tt/qRiZhI8
Submitted June 05, 2023 at 10:38PM by Salmiakkilakritsi
via reddit https://ift.tt/KmDoxaR
https://ift.tt/qRiZhI8
Submitted June 05, 2023 at 10:38PM by Salmiakkilakritsi
via reddit https://ift.tt/KmDoxaR
Shufflingbytes
Ripping Off Professional Criminals by Fermenting Onions - Phishing Darknet Users for Bitcoins
Writeup of a tool for creating bitcoin stealing phishing clones of onion services on large scale
RCE via LDAP truncation on hg.mozilla.org
https://ift.tt/KDMNH7p
Submitted June 06, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/cX3PHaG
https://ift.tt/KDMNH7p
Submitted June 06, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/cX3PHaG
0day.click
RCE via LDAP truncation on hg.mozilla.org
Given my interest in SCM and CI systems I was a little keen to see how this is done at Mozilla as part of their bug bounty program. Thanks to freddy I was granted Level 1 access to Mozilla’s SCM at hg.mozilla.org in late 2022. As Mozilla is a pretty transparent…
A vulnerability in Roundcube’s markasjunk plugin allows attackers that send a specially crafted identity email address to cause the plugin to execute arbitrary code.
https://ift.tt/ESyD4fU
Submitted June 06, 2023 at 02:37PM by SSDisclosure
via reddit https://ift.tt/wxT1sMv
https://ift.tt/ESyD4fU
Submitted June 06, 2023 at 02:37PM by SSDisclosure
via reddit https://ift.tt/wxT1sMv
SSD Secure Disclosure
SSD Advisory - Roundcube markasjunk RCE - SSD Secure Disclosure
Summary A vulnerability in Roundcube’s markasjunk plugin allows attackers that send a specially crafted identity email address to cause the plugin to execute arbitrary code. Credit An independent security researcher, Selim Enes Karaduman, working with SSD…
Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API
https://ift.tt/tuUfvmH
Submitted June 06, 2023 at 09:24PM by EatonZ
via reddit https://ift.tt/qwPG03D
https://ift.tt/tuUfvmH
Submitted June 06, 2023 at 09:24PM by EatonZ
via reddit https://ift.tt/qwPG03D
Eaton-Works
Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API
A vulnerable password reset API made it possible to take over any account and gain admin-level access to the platform. In addition, broken/missing access controls made it possible to access all data on the platform.
The Big IAM Challenge: Test Your Cloud Security Skills
https://ift.tt/djDnJMs
Submitted June 07, 2023 at 01:43AM by geekydeveloper
via reddit https://ift.tt/PpvIZDr
https://ift.tt/djDnJMs
Submitted June 07, 2023 at 01:43AM by geekydeveloper
via reddit https://ift.tt/PpvIZDr
Bigiamchallenge
The Big IAM Challenge
Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?
Hack Dojo - search 3000+ awesome security conference videos + AI summary
https://hackdojo.io
Submitted June 07, 2023 at 02:33AM by hack__dojo
via reddit https://ift.tt/RaxTPiI
https://hackdojo.io
Submitted June 07, 2023 at 02:33AM by hack__dojo
via reddit https://ift.tt/RaxTPiI
Reddit
From the netsec community on Reddit: Hack Dojo - search 3000+ awesome security conference videos + AI summary
Posted by hack__dojo - 46 votes and 5 comments
IRCP: A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers
https://ift.tt/7vcOVyb
Submitted June 07, 2023 at 01:45PM by acidvegas
via reddit https://ift.tt/I9ynFVv
https://ift.tt/7vcOVyb
Submitted June 07, 2023 at 01:45PM by acidvegas
via reddit https://ift.tt/I9ynFVv
GitHub
GitHub - internet-relay-chat/IRCP: A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers…
A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers 🛰️ - internet-relay-chat/IRCP
2023 Vulnerabilities and Threat Trends
https://ift.tt/M4Sq0eg
Submitted June 07, 2023 at 02:54PM by gfekkas
via reddit https://ift.tt/BURWHgS
https://ift.tt/M4Sq0eg
Submitted June 07, 2023 at 02:54PM by gfekkas
via reddit https://ift.tt/BURWHgS
PRIOn - AI Driven Vulnerablity Analysis & Prioritization
Blog - 2023 Vulnerabilities and Threat Trends - PRIOn
In this detailed blog post, explore our in-depth analysis of H1 2023 vulnerabilities from various vendors, their impact, and the threat actors exploiting them.
Popular AI tool MLflow hit with more LFIs, exploit tool updated
https://ift.tt/sSmtTH6
Submitted June 07, 2023 at 06:48PM by FlyingTriangle
via reddit https://ift.tt/CpmlnPj
https://ift.tt/sSmtTH6
Submitted June 07, 2023 at 06:48PM by FlyingTriangle
via reddit https://ift.tt/CpmlnPj
Protectai
Hacking AI: System Takeover in MLflow Strikes Again (And Again)
2 patch bypasses found for severe MLflow LFI/RFI vulnerability
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses