Technology Security Career Advice
http://uwu.com
Submitted August 05, 2023 at 12:48AM by emizzle6250
via reddit https://ift.tt/5BkRajv
http://uwu.com
Submitted August 05, 2023 at 12:48AM by emizzle6250
via reddit https://ift.tt/5BkRajv
Reddit
From the netsec community on Reddit: Technology Security Career Advice
Posted by emizzle6250 - 1 vote and 2 comments
GitHub - kryptokrona/kryptokrona-kotlin-sdk: Kryptokrona SDK in Kotlin for building decentralized private communication and payment systems.
https://ift.tt/wnszYZR
Submitted August 05, 2023 at 03:18PM by xzzzv
via reddit https://ift.tt/EOyiQ0D
https://ift.tt/wnszYZR
Submitted August 05, 2023 at 03:18PM by xzzzv
via reddit https://ift.tt/EOyiQ0D
GitHub
GitHub - kryptokrona/kryptokrona-kotlin-sdk: Build decentralized private communication/payment systems in Kotlin.
Build decentralized private communication/payment systems in Kotlin. - kryptokrona/kryptokrona-kotlin-sdk
Attacking JS engines: Fundamentals for understanding memory corruption crashes
https://ift.tt/v2xhNUq
Submitted August 05, 2023 at 08:54PM by adityatelange
via reddit https://ift.tt/SNnzGIx
https://ift.tt/v2xhNUq
Submitted August 05, 2023 at 08:54PM by adityatelange
via reddit https://ift.tt/SNnzGIx
www.sidechannel.blog
Attacking JS engines: Fundamentals for understanding memory corruption crashes | SideChannel – Tempest
It will be possible to better understand the Javanoscript structures in memory while executing code in browsers or in any other program that makes use of the most famous JS interpreters, such as Firefox, Google Chrome, Internet Explorer and Safari
Burp HTTP history browser (BHHB)
https://ift.tt/nKfd2SJ
Submitted August 05, 2023 at 08:52PM by adityatelange
via reddit https://ift.tt/4mrn7JP
https://ift.tt/nKfd2SJ
Submitted August 05, 2023 at 08:52PM by adityatelange
via reddit https://ift.tt/4mrn7JP
GitHub
GitHub - adityatelange/bhhb: Burp HTTP history browser (BHHB) - A tool to view HTTP history exported from Burp Suite Community…
Burp HTTP history browser (BHHB) - A tool to view HTTP history exported from Burp Suite Community Edition - adityatelange/bhhb
New acoustic attack steals data from keystrokes with 95% accuracy
https://ift.tt/YBLSQDI
Submitted August 06, 2023 at 01:27AM by WashingtonPass
via reddit https://ift.tt/uTZrVdz
https://ift.tt/YBLSQDI
Submitted August 06, 2023 at 01:27AM by WashingtonPass
via reddit https://ift.tt/uTZrVdz
Living Off the Land: Reverse Engineering Methodology + Tips & Tricks (Cmdl32 Case Study)
https://ift.tt/W8bJAYc
Submitted August 07, 2023 at 03:01AM by elliotkillick
via reddit https://ift.tt/qvmXhcG
https://ift.tt/W8bJAYc
Submitted August 07, 2023 at 03:01AM by elliotkillick
via reddit https://ift.tt/qvmXhcG
Elliot on Security
Elliot on Security - Living Off the Land: Reverse Engineering Methodology + Tips & Tricks (Cmdl32 Case Study)
Gain the reverse engineering proficiency needed to find new (undiscovered) 'living off the land' programs in Windows as they exist right now. Plus, how this one went under the radar for over a decade!
Vulnerable WordPress: Release 2023 July - Plugins:142 Vulns:179
https://ift.tt/6g7Dc2Y
Submitted August 07, 2023 at 12:37PM by seyyid_
via reddit https://ift.tt/JjayC7D
https://ift.tt/6g7Dc2Y
Submitted August 07, 2023 at 12:37PM by seyyid_
via reddit https://ift.tt/JjayC7D
GitHub
Release 2023 July - Lake Urmia · onhexgroup/Vulnerable-WordPress
Information about this release:
Worpress version: 6.2.2
Number of installed plugins (Clean and Vulnerable) : 142
Number of vulnerabilities: 179
adminuser: onhexgroup
adminpass: jidCy(SbEz!25qyjT...
Worpress version: 6.2.2
Number of installed plugins (Clean and Vulnerable) : 142
Number of vulnerabilities: 179
adminuser: onhexgroup
adminpass: jidCy(SbEz!25qyjT...
One-click setup SCCM Lab (as snaplabs.io template) for offensive tool testing (or for anything else)
https://ift.tt/7iEZRtN
Submitted August 07, 2023 at 01:54PM by an0n_r0
via reddit https://ift.tt/fsCh63l
https://ift.tt/7iEZRtN
Submitted August 07, 2023 at 01:54PM by an0n_r0
via reddit https://ift.tt/fsCh63l
3D-Printed Dead Man Switch (Proof-of-Concept Demo)
https://ift.tt/GvIjXkw
Submitted August 07, 2023 at 09:25PM by maltfield
via reddit https://ift.tt/l280xTy
https://ift.tt/GvIjXkw
Submitted August 07, 2023 at 09:25PM by maltfield
via reddit https://ift.tt/l280xTy
BusKill
3D Printable BusKill Proof-of-Concept - BusKill
We were successfully able to initiate a BusKill lockscreen trigger using a 3D-printed BusKill (DIY USB kill cord) prototype
Attack & defense
https://ift.tt/HAI9tnv
Submitted August 07, 2023 at 11:18PM by Pretend-Piglet-2978
via reddit https://ift.tt/NG96zAP
https://ift.tt/HAI9tnv
Submitted August 07, 2023 at 11:18PM by Pretend-Piglet-2978
via reddit https://ift.tt/NG96zAP
Getting pwn'd by AI: Penetration Testing with Large Language Models
https://ift.tt/GwWbFca
Submitted August 08, 2023 at 01:28PM by andreashappe
via reddit https://ift.tt/9p1FAxJ
https://ift.tt/GwWbFca
Submitted August 08, 2023 at 01:28PM by andreashappe
via reddit https://ift.tt/9p1FAxJ
Revealing VS Code's Vulnerability: Token Storage is Accessible Across All Extensions
https://ift.tt/b6NHCqL
Submitted August 08, 2023 at 02:25PM by OreenLivni
via reddit https://ift.tt/FVQSKMd
https://ift.tt/b6NHCqL
Submitted August 08, 2023 at 02:25PM by OreenLivni
via reddit https://ift.tt/FVQSKMd
Cycode
VS Code's Token Security: Keeping Your Secrets... Not So Secretly - Cycode
Discover how a vulnerability in VS Code’s secure token storage enables high-risk ‘Token Stealing’ attacks, exposing third-party application tokens and organizational security.
Kubernetes Exposed: One Yaml away from Disaster
https://ift.tt/MZOfbwA
Submitted August 08, 2023 at 05:55PM by mkatch
via reddit https://ift.tt/I7pHUgM
https://ift.tt/MZOfbwA
Submitted August 08, 2023 at 05:55PM by mkatch
via reddit https://ift.tt/I7pHUgM
Aqua
Kubernetes Exposed: One Yaml away from Disaster
We found two main misconfigurations in Kubernetes clusters belonging to more than 350 organizations openly accessible and largely unprotected.
Evading signature-based phishing detections
https://ift.tt/ZzIwk4t
Submitted August 08, 2023 at 08:00PM by S3cur3Th1sSh1t
via reddit https://ift.tt/QGnwvi6
https://ift.tt/ZzIwk4t
Submitted August 08, 2023 at 08:00PM by S3cur3Th1sSh1t
via reddit https://ift.tt/QGnwvi6
www.r-tec.net
Evade signature-based phishing detections
Phishing attacks: Examples of unsafe web resources are social engineering sites and sites that host malware or unwanted software. Come see what's possible.
Reverse Engineering the Apple MultiPeer Connectivity Framework
https://ift.tt/ATnk8R5
Submitted August 08, 2023 at 10:52PM by arrowflakes
via reddit https://ift.tt/Ha5CZFm
https://ift.tt/ATnk8R5
Submitted August 08, 2023 at 10:52PM by arrowflakes
via reddit https://ift.tt/Ha5CZFm
evilsocket
Reverse Engineering the Apple MultiPeer Connectivity Framework
Some time ago I was using Logic Pro to record some of my music and I needed a way to start and stop the recording from an iPhone, so I found about Logic Remote and was quite happy with it.After the se
CVE-2023-34034 Spring WebFlux Security Bypass - Write-up & PoC
https://ift.tt/zsLm2ar
Submitted August 08, 2023 at 09:42PM by n0llbyte
via reddit https://ift.tt/DOp9bEx
https://ift.tt/zsLm2ar
Submitted August 08, 2023 at 09:42PM by n0llbyte
via reddit https://ift.tt/DOp9bEx
JFrog
CVE-2023-34034 Spring WebFlux Security Bypass Write-up & PoC
Understanding the Spring Security CVE-2023-34034 vulnerability. Read our detailed analysis, learn what's vulnerable and discover remediations.
Downfall attacks (another speculative execution attack on Intel silicon)
https://downfall.page/
Submitted August 08, 2023 at 11:33PM by Exilewhat
via reddit https://ift.tt/1Ir4jbg
https://downfall.page/
Submitted August 08, 2023 at 11:33PM by Exilewhat
via reddit https://ift.tt/1Ir4jbg
Reddit
From the netsec community on Reddit: Downfall attacks (another speculative execution attack on Intel silicon)
Explore this post and more from the netsec community
Multi-party computation is (sort of) changing the game
https://ift.tt/CVpL5lq
Submitted August 09, 2023 at 03:18AM by Ecmoy
via reddit https://ift.tt/nFWtN1o
https://ift.tt/CVpL5lq
Submitted August 09, 2023 at 03:18AM by Ecmoy
via reddit https://ift.tt/nFWtN1o
Evervault
Multi-party computation is (sort of) changing the game — Blog — Evervault
Multi-party computing has a lot of potential. Unfortunately, it’s rarely worth the hassle.
TunnelCrack: Widespread design flaws in VPN clients
https://ift.tt/2TEcVvg
Submitted August 09, 2023 at 11:44AM by Tall-Cauliflower9753
via reddit https://ift.tt/IPrCx6s
https://ift.tt/2TEcVvg
Submitted August 09, 2023 at 11:44AM by Tall-Cauliflower9753
via reddit https://ift.tt/IPrCx6s
Mathyvanhoef
TunnelCrack: Widespread design flaws in VPN clients
We present two widespread design flaws in VPN client. These can be abused to make a victim leak traffic in plaintext outside the protected VPN tunnel.
Ultimate guide to Rubber Ducky attacks using Kali NetHunter
https://ift.tt/76mAv0N
Submitted August 09, 2023 at 03:19PM by barakadua131
via reddit https://ift.tt/tBs31Zn
https://ift.tt/76mAv0N
Submitted August 09, 2023 at 03:19PM by barakadua131
via reddit https://ift.tt/tBs31Zn
Mobile Hacker
NetHunter Hacker VI: Ultimate guide to HID attacks using Rubber Ducky noscripts and Bad USB MITM attack - Mobile Hacker
Have you ever wondered how hackers can compromise a computer with just a USB device? In this blogpost, we will explore the concept of HID attacks, which are a type of physical host attack that use a programmable device to emulate a keyboard or mouse and execute…
Hacking AI: technical deep dive into low level exploits in Apache MXnet
https://ift.tt/GQ1D4VR
Submitted August 09, 2023 at 03:42PM by FlyingTriangle
via reddit https://ift.tt/PFWxdXG
https://ift.tt/GQ1D4VR
Submitted August 09, 2023 at 03:42PM by FlyingTriangle
via reddit https://ift.tt/PFWxdXG
Mlsecops
MXNet Unsafe Pointer Usage
Security researcher Bryce Bearchell in collaboration with Protect AI and huntr.mlsecops.com, discovered a bug in MXnet, a library for creating ML models.