GitHub - FourCoreLabs/LolDriverScan: Scan vulnerable drivers on Windows System
https://ift.tt/FCNWS3t
Submitted July 15, 2023 at 08:46PM by achilles4828
via reddit https://ift.tt/fne974p
https://ift.tt/FCNWS3t
Submitted July 15, 2023 at 08:46PM by achilles4828
via reddit https://ift.tt/fne974p
GitHub
GitHub - FourCoreLabs/LolDriverScan: Scan vulnerable drivers on Windows with loldrivers.io
Scan vulnerable drivers on Windows with loldrivers.io - FourCoreLabs/LolDriverScan
Satellites lack standard security mechanisms found in mobile phones and laptops - Help Net Security
https://ift.tt/bJrXWVG
Submitted July 16, 2023 at 10:34AM by i-_-am-_-batman
via reddit https://ift.tt/mNqU6eD
https://ift.tt/bJrXWVG
Submitted July 16, 2023 at 10:34AM by i-_-am-_-batman
via reddit https://ift.tt/mNqU6eD
Help Net Security
Satellites lack standard security mechanisms found in mobile phones and laptops
Researchers assessed satellite security mechanisms from an IT perspective and found a lack of modern security implementation.
GitHub - ZephrFish/PotFileUtils
https://ift.tt/0Nwto8v
Submitted July 16, 2023 at 05:38PM by ZephrX112
via reddit https://ift.tt/2RiwAnN
https://ift.tt/0Nwto8v
Submitted July 16, 2023 at 05:38PM by ZephrX112
via reddit https://ift.tt/2RiwAnN
GitHub
GitHub - ZephrFish/PotUtils
Contribute to ZephrFish/PotUtils development by creating an account on GitHub.
Vault Range - The Measure and Resilience of Weaponized Exploit Methods for Linux
https://ift.tt/3EZ8tGL
Submitted July 16, 2023 at 06:55PM by hardenedvault
via reddit https://ift.tt/1dASBvD
https://ift.tt/3EZ8tGL
Submitted July 16, 2023 at 06:55PM by hardenedvault
via reddit https://ift.tt/1dASBvD
hardenedvault.net
Vault Range - The Measure and Resilience of Weaponized Exploit Methods for Linux
Disclaimer VED (Vault Exploit Defense) test image contains only the VED kernel module, and does not contain any security baselines, access control policies and situational hardening solution.
PSC Automation: Using Python to Interact With PortShellCrypter.
https://ift.tt/4ZOUhRt
Submitted July 16, 2023 at 08:20PM by fullspectrumdev
via reddit https://ift.tt/6OTH4dk
https://ift.tt/4ZOUhRt
Submitted July 16, 2023 at 08:20PM by fullspectrumdev
via reddit https://ift.tt/6OTH4dk
Full Spectrum Things
PSC Automation: Using Python to Interact With PortShellCrypter.
PortShellCrypter offers up a noscripting socket, and a simple utility (pscsh) that allows executing shell noscripts on the remote end.
pscsh basically enables you to write a shell noscript, and have it be executed remotely, by sending it line by line to the remote…
pscsh basically enables you to write a shell noscript, and have it be executed remotely, by sending it line by line to the remote…
Beyond the Marketing: Assessing Anti-Bot Platforms through a Hacker's Lens
https://ift.tt/xhf6dHB
Submitted July 16, 2023 at 08:11PM by R380073D
via reddit https://ift.tt/yhNLkBf
https://ift.tt/xhf6dHB
Submitted July 16, 2023 at 08:11PM by R380073D
via reddit https://ift.tt/yhNLkBf
How We Found Another GitHub Actions Environment Injection Vulnerability in a Google Project
https://ift.tt/Jx9ZDwE
Submitted July 17, 2023 at 01:45AM by roy_6472
via reddit https://ift.tt/20gPXdy
https://ift.tt/Jx9ZDwE
Submitted July 17, 2023 at 01:45AM by roy_6472
via reddit https://ift.tt/20gPXdy
Legitsecurity
How We Found Another GitHub Actions Environment Injection Vulnerability in a Google Project
Legit Security | This blog shows another case of GitHub Actions environment injection vulnerability in a Google repository.
Prominent Threat Actor Accidentally Infects Own Computer with Info-Stealer
https://ift.tt/kNuKhcM
Submitted July 17, 2023 at 04:21PM by Malwarebeasts
via reddit https://ift.tt/knHuvRj
https://ift.tt/kNuKhcM
Submitted July 17, 2023 at 04:21PM by Malwarebeasts
via reddit https://ift.tt/knHuvRj
Hudsonrock
Prominent Threat Actor Accidentally Infects Own Computer with Info-Stealer
Threat actor “La_Citrix” is known for hacking companies — he accidentally infected his own computer and likely ended up selling it without noticing.
promptmap - automatically tests prompt injection attacks on ChatGPT instances
https://ift.tt/0qRkmis
Submitted July 16, 2023 at 05:23PM by utku1337
via reddit https://ift.tt/g0WVwQr
https://ift.tt/0qRkmis
Submitted July 16, 2023 at 05:23PM by utku1337
via reddit https://ift.tt/g0WVwQr
GitHub
GitHub - utkusen/promptmap: automatically tests prompt injection attacks on ChatGPT instances
automatically tests prompt injection attacks on ChatGPT instances - utkusen/promptmap
A technical analysis of the Quasar-forked RAT called VoidRAT
https://ift.tt/3BlH0TE
Submitted July 17, 2023 at 07:25PM by CyberMasterV
via reddit https://ift.tt/KTGiIBc
https://ift.tt/3BlH0TE
Submitted July 17, 2023 at 07:25PM by CyberMasterV
via reddit https://ift.tt/KTGiIBc
Security Scorecard
A Technical Analysis of Void Rat | SecurityScorecard
VoidRAT is based on the open-source RAT called Quasar. The malware steals information from web browsers and applications such as FileZilla and WinSCP. It also implements a keylogger functionality that saves and exfiltrates the pressed keys.
Email hack prompts call for Microsoft to make security logs free
https://ift.tt/Z38MbYL
Submitted July 17, 2023 at 09:38PM by mikevvei
via reddit https://ift.tt/We1xF3o
https://ift.tt/Z38MbYL
Submitted July 17, 2023 at 09:38PM by mikevvei
via reddit https://ift.tt/We1xF3o
SC Media
Email hack prompts call for Microsoft to make security logs free
An attack against multiple organizations using the company’s cloud email services, including U.S. government agencies, was “invisible” to many of the victims because they hadn’t paid extra to access security logs. One senator likened the extra costs to “selling…
Uncovering drIBAN fraud operations 3 | Cleafy Lab
https://ift.tt/YagcGrm
Submitted July 18, 2023 at 06:32PM by f3d_0x0
via reddit https://ift.tt/Nh6P0DY
https://ift.tt/YagcGrm
Submitted July 18, 2023 at 06:32PM by f3d_0x0
via reddit https://ift.tt/Nh6P0DY
Cleafy
Uncovering drIBAN fraud operations 3 | Cleafy Labs
The threat intelligence team of Cleafy analyzed undercovering drIBAN fraud operations. Read here the final episode of the series of technical analysis.
Streamlining Websocket Pentesting with wsrepl
https://ift.tt/qykgmOe
Submitted July 18, 2023 at 06:05PM by nibblesec
via reddit https://ift.tt/eVQF82b
https://ift.tt/qykgmOe
Submitted July 18, 2023 at 06:05PM by nibblesec
via reddit https://ift.tt/eVQF82b
Doyensec
Streamlining Websocket Pentesting with wsrepl · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Critical Vulnerabilities in Citrix ADC and Citrix Gateway: Patch now!
https://ift.tt/LAgSmEz
Submitted July 18, 2023 at 10:33PM by Sir_Major_Kitten
via reddit https://ift.tt/tnh6sPW
https://ift.tt/LAgSmEz
Submitted July 18, 2023 at 10:33PM by Sir_Major_Kitten
via reddit https://ift.tt/tnh6sPW
[CVE-2023-38357] RWS WorldServer: Session Token Enumeration
https://ift.tt/SM89X7w
Submitted July 19, 2023 at 02:33PM by RedTeamPentesting
via reddit https://ift.tt/IoGQzbD
https://ift.tt/SM89X7w
Submitted July 19, 2023 at 02:33PM by RedTeamPentesting
via reddit https://ift.tt/IoGQzbD
www.redteam-pentesting.de
RedTeam Pentesting GmbH - Session Token Enumeration in RWS WorldServer
Session tokens in RWS WorldServer have a low entropy and can be enumerated, leading to unauthorised access to user sessions.
Extending Burp Suite for fun and profit - The Montoya way - Part 3
https://ift.tt/AnK4lVq
Submitted July 19, 2023 at 08:27PM by 0xdea
via reddit https://ift.tt/58qH7AT
https://ift.tt/AnK4lVq
Submitted July 19, 2023 at 08:27PM by 0xdea
via reddit https://ift.tt/58qH7AT
hn security
Extending Burp Suite for fun and profit - The Montoya way - Part 3 - hn security
Setting up the environment + Hello […]
Browse millions of secrets leaked in GitHub/NPM via Forager
https://ift.tt/ShLQA4H
Submitted July 19, 2023 at 11:14PM by Phorcez
via reddit https://ift.tt/htr7Zlc
https://ift.tt/ShLQA4H
Submitted July 19, 2023 at 11:14PM by Phorcez
via reddit https://ift.tt/htr7Zlc
Trufflesecurity
Introducing Forager: Browse Millions of Leaked API keys Found With TruffleHog ◆ Truffle Security Co.
Trufflehog is an open-source secret scanning engine that detects sensitive credentials such as passwords and API keys – secrets that are inadvertently exposed by individuals and organizations. Two years ago, Trufflehog v3 was released, a complete rewrite…
Using MiTMProxy as a noscriptable pre-proxy for BurpSuite
https://ift.tt/UnmWX6s
Submitted July 20, 2023 at 01:23AM by mikeVVcm
via reddit https://ift.tt/XfoBQ2z
https://ift.tt/UnmWX6s
Submitted July 20, 2023 at 01:23AM by mikeVVcm
via reddit https://ift.tt/XfoBQ2z
Zolder B.V.
Using MiTMProxy as a noscriptable pre-proxy for BurpSuite
TLDR: you can use mitmproxy to modify stuff before it sent to Burp Proxy. Instruction below. Recently we were asked to asses a oldschool Java client server application. After configuring BurpSuite …
Improve your API Security Testing with Burp BCheck Scripts
https://ift.tt/XGymQku
Submitted July 20, 2023 at 01:22AM by mikeVVcm
via reddit https://ift.tt/PgExTzU
https://ift.tt/XGymQku
Submitted July 20, 2023 at 01:22AM by mikeVVcm
via reddit https://ift.tt/PgExTzU
Dana Epp's Blog
Improve your API Security Testing with Burp BCheck Scripts
Learn how to write your own Burp BCheck noscripts to tap into the web vulnerability scanner to automate your API security testing.
CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent
https://ift.tt/cjO08XA
Submitted July 20, 2023 at 12:50AM by 0xdea
via reddit https://ift.tt/UsNDqrO
https://ift.tt/cjO08XA
Submitted July 20, 2023 at 12:50AM by 0xdea
via reddit https://ift.tt/UsNDqrO
Webmesh: Yet another WireGuard Mesh/VPN solution
https://ift.tt/i8l3aSy
Submitted July 20, 2023 at 01:45AM by jews4beer
via reddit https://ift.tt/qdLfGCV
https://ift.tt/i8l3aSy
Submitted July 20, 2023 at 01:45AM by jews4beer
via reddit https://ift.tt/qdLfGCV
GitHub
GitHub - webmeshproj/webmesh: A simple, distributed, zero-configuration WireGuard mesh solution
A simple, distributed, zero-configuration WireGuard mesh solution - webmeshproj/webmesh