Using PANDA to search for F.L.I.R.T. signatures during process execution
https://ift.tt/umZ0lUW
Submitted June 05, 2023 at 09:28PM by whisperingmime
via reddit https://ift.tt/qhkvJ6W
https://ift.tt/umZ0lUW
Submitted June 05, 2023 at 09:28PM by whisperingmime
via reddit https://ift.tt/qhkvJ6W
Blog by Joren Vrancken
Using PANDA to search for F.L.I.R.T. signatures during process execution
When a malware analyst gets a new malware sample to analyze, one of the first questions they might have, is what functions are called during the execution of the sample. To solve this problem, we can use any old debugger to walk through the sample manually…
Ripping Off Professional Criminals by Fermenting Onions - Phishing Darknet Users for Bitcoins
https://ift.tt/qRiZhI8
Submitted June 05, 2023 at 10:38PM by Salmiakkilakritsi
via reddit https://ift.tt/KmDoxaR
https://ift.tt/qRiZhI8
Submitted June 05, 2023 at 10:38PM by Salmiakkilakritsi
via reddit https://ift.tt/KmDoxaR
Shufflingbytes
Ripping Off Professional Criminals by Fermenting Onions - Phishing Darknet Users for Bitcoins
Writeup of a tool for creating bitcoin stealing phishing clones of onion services on large scale
RCE via LDAP truncation on hg.mozilla.org
https://ift.tt/KDMNH7p
Submitted June 06, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/cX3PHaG
https://ift.tt/KDMNH7p
Submitted June 06, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/cX3PHaG
0day.click
RCE via LDAP truncation on hg.mozilla.org
Given my interest in SCM and CI systems I was a little keen to see how this is done at Mozilla as part of their bug bounty program. Thanks to freddy I was granted Level 1 access to Mozilla’s SCM at hg.mozilla.org in late 2022. As Mozilla is a pretty transparent…
A vulnerability in Roundcube’s markasjunk plugin allows attackers that send a specially crafted identity email address to cause the plugin to execute arbitrary code.
https://ift.tt/ESyD4fU
Submitted June 06, 2023 at 02:37PM by SSDisclosure
via reddit https://ift.tt/wxT1sMv
https://ift.tt/ESyD4fU
Submitted June 06, 2023 at 02:37PM by SSDisclosure
via reddit https://ift.tt/wxT1sMv
SSD Secure Disclosure
SSD Advisory - Roundcube markasjunk RCE - SSD Secure Disclosure
Summary A vulnerability in Roundcube’s markasjunk plugin allows attackers that send a specially crafted identity email address to cause the plugin to execute arbitrary code. Credit An independent security researcher, Selim Enes Karaduman, working with SSD…
Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API
https://ift.tt/tuUfvmH
Submitted June 06, 2023 at 09:24PM by EatonZ
via reddit https://ift.tt/qwPG03D
https://ift.tt/tuUfvmH
Submitted June 06, 2023 at 09:24PM by EatonZ
via reddit https://ift.tt/qwPG03D
Eaton-Works
Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API
A vulnerable password reset API made it possible to take over any account and gain admin-level access to the platform. In addition, broken/missing access controls made it possible to access all data on the platform.
The Big IAM Challenge: Test Your Cloud Security Skills
https://ift.tt/djDnJMs
Submitted June 07, 2023 at 01:43AM by geekydeveloper
via reddit https://ift.tt/PpvIZDr
https://ift.tt/djDnJMs
Submitted June 07, 2023 at 01:43AM by geekydeveloper
via reddit https://ift.tt/PpvIZDr
Bigiamchallenge
The Big IAM Challenge
Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?
Hack Dojo - search 3000+ awesome security conference videos + AI summary
https://hackdojo.io
Submitted June 07, 2023 at 02:33AM by hack__dojo
via reddit https://ift.tt/RaxTPiI
https://hackdojo.io
Submitted June 07, 2023 at 02:33AM by hack__dojo
via reddit https://ift.tt/RaxTPiI
Reddit
From the netsec community on Reddit: Hack Dojo - search 3000+ awesome security conference videos + AI summary
Posted by hack__dojo - 46 votes and 5 comments
IRCP: A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers
https://ift.tt/7vcOVyb
Submitted June 07, 2023 at 01:45PM by acidvegas
via reddit https://ift.tt/I9ynFVv
https://ift.tt/7vcOVyb
Submitted June 07, 2023 at 01:45PM by acidvegas
via reddit https://ift.tt/I9ynFVv
GitHub
GitHub - internet-relay-chat/IRCP: A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers…
A robust information gathering tool for large scale reconnaissance on Internet Relay Chat servers 🛰️ - internet-relay-chat/IRCP
2023 Vulnerabilities and Threat Trends
https://ift.tt/M4Sq0eg
Submitted June 07, 2023 at 02:54PM by gfekkas
via reddit https://ift.tt/BURWHgS
https://ift.tt/M4Sq0eg
Submitted June 07, 2023 at 02:54PM by gfekkas
via reddit https://ift.tt/BURWHgS
PRIOn - AI Driven Vulnerablity Analysis & Prioritization
Blog - 2023 Vulnerabilities and Threat Trends - PRIOn
In this detailed blog post, explore our in-depth analysis of H1 2023 vulnerabilities from various vendors, their impact, and the threat actors exploiting them.
Popular AI tool MLflow hit with more LFIs, exploit tool updated
https://ift.tt/sSmtTH6
Submitted June 07, 2023 at 06:48PM by FlyingTriangle
via reddit https://ift.tt/CpmlnPj
https://ift.tt/sSmtTH6
Submitted June 07, 2023 at 06:48PM by FlyingTriangle
via reddit https://ift.tt/CpmlnPj
Protectai
Hacking AI: System Takeover in MLflow Strikes Again (And Again)
2 patch bypasses found for severe MLflow LFI/RFI vulnerability
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses
All patched in MLflow version 2.2.3
Protect AI’s vulnerability scanning and exploit tools updated with bypasses
OPC UA Structure, Messaging, Security Features
https://ift.tt/jyL5IE2
Submitted June 07, 2023 at 06:46PM by derp6996
via reddit https://ift.tt/BrQSWyA
https://ift.tt/jyL5IE2
Submitted June 07, 2023 at 06:46PM by derp6996
via reddit https://ift.tt/BrQSWyA
Claroty
OPC UA Deep Dive (Part 3): Exploring the OPC UA Protocol
Explore the intricacies of the OPC UA protocol in Part 3 of Team82's Deep Dive series. Understand the protocol's layers, messaging types, security features, and more in this comprehensive guide to OPC UA for unified OT communication.
Modded Minecraft Malware "fractureiser" - What We Know
https://ift.tt/bIRSy9k
Submitted June 07, 2023 at 08:18PM by hyperflare
via reddit https://ift.tt/ONsBZVC
https://ift.tt/bIRSy9k
Submitted June 07, 2023 at 08:18PM by hyperflare
via reddit https://ift.tt/ONsBZVC
HackMD
THIS DOC IS OLD, WE HAVE MOVED AGAIN - HackMD
# THIS DOC IS OLD, WE HAVE MOVED AGAIN Old doc, further conversation is happening at github due to l
When hackers hack the hackers
https://ift.tt/b0mKj4p
Submitted June 07, 2023 at 10:15PM by S3cur3Th1sSh1t
via reddit https://ift.tt/JTacMWQ
https://ift.tt/b0mKj4p
Submitted June 07, 2023 at 10:15PM by S3cur3Th1sSh1t
via reddit https://ift.tt/JTacMWQ
www.r-tec.net
When Hackers hack the Hackers
In this post, the malware analysis process, as well as attacker activities and Indicators of Compromise (IoCs) are presented.
Pending motion for investigation in federal case over prosecutors planting trojan malware in emailed discovery documents!
https://ift.tt/mxGWbkN
Submitted June 08, 2023 at 12:38AM by dmg15
via reddit https://ift.tt/IMOWeUg
https://ift.tt/mxGWbkN
Submitted June 08, 2023 at 12:38AM by dmg15
via reddit https://ift.tt/IMOWeUg
SignatureGate - Bypassing AV/EDRs by exploiting 10 years old CVE
https://ift.tt/3sVMvp0
Submitted June 07, 2023 at 11:59PM by florilsk
via reddit https://ift.tt/j38CxEH
https://ift.tt/3sVMvp0
Submitted June 07, 2023 at 11:59PM by florilsk
via reddit https://ift.tt/j38CxEH
GitHub
GitHub - florylsk/SignatureGate: Weaponized HellsGate/SigFlip
Weaponized HellsGate/SigFlip. Contribute to florylsk/SignatureGate development by creating an account on GitHub.
Patching Windows Event Tracing in memory to be stealthier (POC)
https://ift.tt/V2sdYwI
Submitted June 08, 2023 at 06:49PM by thehunter699
via reddit https://ift.tt/uOXnTdR
https://ift.tt/V2sdYwI
Submitted June 08, 2023 at 06:49PM by thehunter699
via reddit https://ift.tt/uOXnTdR
GitHub
GitHub - nullsection/SharpETW-Patch
Contribute to nullsection/SharpETW-Patch development by creating an account on GitHub.
Legacy authentication: The curious case of BAV2ROPC
https://ift.tt/oGYUH5N
Submitted June 08, 2023 at 08:26PM by tvjust
via reddit https://ift.tt/F7XJ9xG
https://ift.tt/oGYUH5N
Submitted June 08, 2023 at 08:26PM by tvjust
via reddit https://ift.tt/F7XJ9xG
Red Canary
Legacy authentication: The curious case of BAV2ROPC
A mysterious user agent string in some Microsoft 365 audit logs offers clues for how to detect logins from legacy authentication protocols.
MSSQL linked servers: abusing ADSI for password retrieval - BlackArrow
https://ift.tt/mZJNSK9
Submitted June 08, 2023 at 10:17PM by apanonimo
via reddit https://ift.tt/qKvuGPm
https://ift.tt/mZJNSK9
Submitted June 08, 2023 at 10:17PM by apanonimo
via reddit https://ift.tt/qKvuGPm
Tarlogic Security
MSSQL linked servers: abusing ADSI for password retrieval
New technique to gather passwords from MSSQL by abusing linked servers through the ADSI provider
Detecting and mitigating a multi-stage AiTM phishing and BEC campaign
https://ift.tt/SuvZeb7
Submitted June 08, 2023 at 10:03PM by SCI_Rusher
via reddit https://ift.tt/ya29Qkz
https://ift.tt/SuvZeb7
Submitted June 08, 2023 at 10:03PM by SCI_Rusher
via reddit https://ift.tt/ya29Qkz
Microsoft Security Blog
Detecting and mitigating a multi-stage AiTM phishing and BEC campaign | Microsoft Security Blog
A multi-stage adversary-in-the-middle (AiTM) and business email compromise (BEC) attack targets banking and financial services organizations.
The new version 4.0 of the Common Vulnerability Scoring System (CVSS) has just entered public preview phase. Please have a look and send us your comments by July 31st, see the presentation for details about how to provide feedback.
https://ift.tt/jzi9fkA
Submitted June 09, 2023 at 01:07AM by forgetful_12345
via reddit https://ift.tt/3Em5huY
https://ift.tt/jzi9fkA
Submitted June 09, 2023 at 01:07AM by forgetful_12345
via reddit https://ift.tt/3Em5huY
FIRST — Forum of Incident Response and Security Teams
Common Vulnerability Scoring System
acme.sh runs arbitrary commands from a remote server
https://ift.tt/DuYmOvf
Submitted June 09, 2023 at 12:59PM by tubularobot
via reddit https://ift.tt/QUGVAte
https://ift.tt/DuYmOvf
Submitted June 09, 2023 at 12:59PM by tubularobot
via reddit https://ift.tt/QUGVAte
GitHub
acme.sh runs arbitrary commands from a remote server · Issue #4659 · acmesh-official/acme.sh
Hello, You may already be aware of this, but HiCA is injecting arbitrary code/commands into the certificate obtaining process and acme.sh is running them on the client machine. I am not sure if thi...