TunnelCrack: Widespread design flaws in VPN clients
https://ift.tt/2TEcVvg
Submitted August 09, 2023 at 11:44AM by Tall-Cauliflower9753
via reddit https://ift.tt/IPrCx6s
https://ift.tt/2TEcVvg
Submitted August 09, 2023 at 11:44AM by Tall-Cauliflower9753
via reddit https://ift.tt/IPrCx6s
Mathyvanhoef
TunnelCrack: Widespread design flaws in VPN clients
We present two widespread design flaws in VPN client. These can be abused to make a victim leak traffic in plaintext outside the protected VPN tunnel.
Ultimate guide to Rubber Ducky attacks using Kali NetHunter
https://ift.tt/76mAv0N
Submitted August 09, 2023 at 03:19PM by barakadua131
via reddit https://ift.tt/tBs31Zn
https://ift.tt/76mAv0N
Submitted August 09, 2023 at 03:19PM by barakadua131
via reddit https://ift.tt/tBs31Zn
Mobile Hacker
NetHunter Hacker VI: Ultimate guide to HID attacks using Rubber Ducky noscripts and Bad USB MITM attack - Mobile Hacker
Have you ever wondered how hackers can compromise a computer with just a USB device? In this blogpost, we will explore the concept of HID attacks, which are a type of physical host attack that use a programmable device to emulate a keyboard or mouse and execute…
Hacking AI: technical deep dive into low level exploits in Apache MXnet
https://ift.tt/GQ1D4VR
Submitted August 09, 2023 at 03:42PM by FlyingTriangle
via reddit https://ift.tt/PFWxdXG
https://ift.tt/GQ1D4VR
Submitted August 09, 2023 at 03:42PM by FlyingTriangle
via reddit https://ift.tt/PFWxdXG
Mlsecops
MXNet Unsafe Pointer Usage
Security researcher Bryce Bearchell in collaboration with Protect AI and huntr.mlsecops.com, discovered a bug in MXnet, a library for creating ML models.
EmploLeaks is an OSINT tool that helps detect members of a company with leaked credentials
https://ift.tt/ifxrOL1
Submitted August 09, 2023 at 11:07PM by fede_k
via reddit https://ift.tt/u32XtSc
https://ift.tt/ifxrOL1
Submitted August 09, 2023 at 11:07PM by fede_k
via reddit https://ift.tt/u32XtSc
GitHub
GitHub - infobyte/emploleaks: An OSINT tool that helps detect members of a company with leaked credentials
An OSINT tool that helps detect members of a company with leaked credentials - infobyte/emploleaks
Smashing the state machine: the true potential of web race conditions
https://ift.tt/wdius9H?
Submitted August 09, 2023 at 11:47PM by albinowax
via reddit https://ift.tt/uy5pE86
https://ift.tt/wdius9H?
Submitted August 09, 2023 at 11:47PM by albinowax
via reddit https://ift.tt/uy5pE86
PortSwigger Research
Smashing the state machine: the true potential of web race conditions
For too long, web race condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding
Vnet
http://azure.com
Submitted August 10, 2023 at 06:03AM by Paranoid-notdroid
via reddit https://ift.tt/DVPrkZ0
http://azure.com
Submitted August 10, 2023 at 06:03AM by Paranoid-notdroid
via reddit https://ift.tt/DVPrkZ0
Microsoft
Cloud Computing Services | Microsoft Azure
Invent with purpose, realize cost savings, and make your organization more efficient with Microsoft Azure’s open and flexible cloud computing platform.
Extended resume writing guidance for InfoSec professionals
https://ift.tt/45iKcCS
Submitted August 10, 2023 at 09:18AM by fabledparable
via reddit https://ift.tt/YTg2Jny
https://ift.tt/45iKcCS
Submitted August 10, 2023 at 09:18AM by fabledparable
via reddit https://ift.tt/YTg2Jny
I'm a female leader and I'm looking for some active female CTF players to join our team. Here is the team information.
https://ift.tt/SbId9ui
Submitted August 10, 2023 at 11:35AM by Potential-Baby4611
via reddit https://ift.tt/f3DO4bg
https://ift.tt/SbId9ui
Submitted August 10, 2023 at 11:35AM by Potential-Baby4611
via reddit https://ift.tt/f3DO4bg
ctftime.org
CTFtime.org / S.O.A.P
Welcome to our team page :)
We are a beginner to intermediate team.
Founded by Catmil...,S.O.A.P
We are a beginner to intermediate team.
Founded by Catmil...,S.O.A.P
.NET developers alert: Moq NuGET package exfiltrates user emails from git
https://ift.tt/wteSauh
Submitted August 10, 2023 at 11:27AM by lirantal
via reddit https://ift.tt/Z2AEN9J
https://ift.tt/wteSauh
Submitted August 10, 2023 at 11:27AM by lirantal
via reddit https://ift.tt/Z2AEN9J
Snyk
.NET developers alert: Moq NuGET package exfiltrates user emails from git | Snyk
On August 8th 2023, the .NET community was made aware that the testing library called Moq exfiltrates developers emails from their development machine, and sends them off to third-party remote servers.
“Please do not make it public”: Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping
https://ift.tt/s0xEc9a
Submitted August 10, 2023 at 01:31PM by poltess0
via reddit https://ift.tt/Uelur8F
https://ift.tt/s0xEc9a
Submitted August 10, 2023 at 01:31PM by poltess0
via reddit https://ift.tt/Uelur8F
The Citizen Lab
“Please do not make it public”: Vulnerabilities in Sogou Keyboard encryption expose keypresses to network eavesdropping - The Citizen…
In this report, we analyze the Windows, Android, and iOS versions of Tencent’s Sogou Input Method, the most popular Chinese-language input method in China. Our analysis found serious vulnerabilities in the app’s custom encryption system and how it encrypts…
Client-side desync attack on Azure CDN
https://ift.tt/Gq0ijbJ
Submitted August 10, 2023 at 09:29PM by albinowax
via reddit https://ift.tt/W560aMB
https://ift.tt/Gq0ijbJ
Submitted August 10, 2023 at 09:29PM by albinowax
via reddit https://ift.tt/W560aMB
Jeti's blog
Knocking on the Front Door (client side desync attack on Azure CDN)
A few months ago, I embarked on a security bug hunt within the scope of a private program available through the Intigriti platform. During this endeavor, I encountered an intriguing anomaly while analyzing the redirect from HTTP to HTTPS traffic on a particular…
Lexmark Printer Command Injection - Credential Dumping POC
https://ift.tt/vkhzmsO
Submitted August 11, 2023 at 02:23AM by scopedsecurity
via reddit https://ift.tt/k0WDnsh
https://ift.tt/vkhzmsO
Submitted August 11, 2023 at 02:23AM by scopedsecurity
via reddit https://ift.tt/k0WDnsh
Horizon3.ai
Lexmark Command Injection Vulnerability ZDI-CAN-19470 Pwn2Own Toronto 2022 – Horizon3.ai
Introduction In December 2022, we competed at our first pwn2own. We were able to successfully exploit the Lexmark MC3224i using a command injection 0-day. This post will detail the process we used to discover, weaponize, and have some fun with this vulnerability.…
A Pain in the NAS: Exploiting Cloud Connectivity to PWN your NAS: WD PR4100 Edition
https://ift.tt/qFs0Upd
Submitted August 11, 2023 at 01:46AM by sh0n1z
via reddit https://ift.tt/FMAa7eo
https://ift.tt/qFs0Upd
Submitted August 11, 2023 at 01:46AM by sh0n1z
via reddit https://ift.tt/FMAa7eo
Claroty
Exploiting Cloud Connectivity to PWN your NAS: WD PR4100
Claroty unveils a unique attack technique that could allow an attacker to impersonate Western Digital (WD) network-attached storage (NAS) devices. Learn more.
Intel Arc Graphics Cards Advisory
https://ift.tt/N1EHAvs
Submitted August 11, 2023 at 08:23PM by Titokhan
via reddit https://ift.tt/wkHmUd6
https://ift.tt/N1EHAvs
Submitted August 11, 2023 at 08:23PM by Titokhan
via reddit https://ift.tt/wkHmUd6
Intel
INTEL-SA-00812
VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF
https://ift.tt/Dayle2x
Submitted August 11, 2023 at 07:37PM by hardenedvault
via reddit https://ift.tt/mJxkUfD
https://ift.tt/Dayle2x
Submitted August 11, 2023 at 07:37PM by hardenedvault
via reddit https://ift.tt/mJxkUfD
GitHub
GitHub - hardenedvault/ved-ebpf: VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF
VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF - GitHub - hardenedvault/ved-ebpf: VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF
Chromium Blog: Protecting Chrome Traffic with Hybrid Kyber KEM
https://ift.tt/6JAweVq
Submitted August 12, 2023 at 12:05AM by sanitybit
via reddit https://ift.tt/aOR8cAL
https://ift.tt/6JAweVq
Submitted August 12, 2023 at 12:05AM by sanitybit
via reddit https://ift.tt/aOR8cAL
Chromium Blog
Protecting Chrome Traffic with Hybrid Kyber KEM
Teams across Google are working hard to prepare the web for the migration to quantum-resistant cryptography. Continuing with our strategy f...
Black Hat USA 2023 slides
https://ift.tt/B8Y2X5L
Submitted August 12, 2023 at 10:59AM by seyyid_
via reddit https://ift.tt/PyfLpjh
https://ift.tt/B8Y2X5L
Submitted August 12, 2023 at 10:59AM by seyyid_
via reddit https://ift.tt/PyfLpjh
GitHub
Conferences/Black Hat USA 2023 slides at main · onhexgroup/Conferences
Conference slides. Contribute to onhexgroup/Conferences development by creating an account on GitHub.
Speeding up nmap service scanning 16x
https://ift.tt/GOA7ckC
Submitted August 13, 2023 at 06:11PM by MegaManSec2
via reddit https://ift.tt/oQ1pluY
https://ift.tt/GOA7ckC
Submitted August 13, 2023 at 06:11PM by MegaManSec2
via reddit https://ift.tt/oQ1pluY
Joshua.Hu
Speeding up nmap service scanning 16x
In my previous post post, I began writing about how I was designing a port and service scanner for large-scale networks by combining port-scanning tools like masscan/zmap and service scanning tools like nmap. In this post, I’m going to dive into some of the…
How to Get Started in Bug Bounty for Beginners
https://ift.tt/I7Sdnsp
Submitted August 13, 2023 at 08:12PM by kongwenbin
via reddit https://ift.tt/ClyakTB
https://ift.tt/I7Sdnsp
Submitted August 13, 2023 at 08:12PM by kongwenbin
via reddit https://ift.tt/ClyakTB
My Learning Journey
How to Get Started in Bug Bounty for Beginners
How to get started in bug bounty? What technical skills are required? If you are a bug bounty beginner, check this out!
Why macOS anti-malware scans can behave oddly
https://ift.tt/jrvP6GS
Submitted August 13, 2023 at 11:46PM by louis11
via reddit https://ift.tt/YfXC9zt
https://ift.tt/jrvP6GS
Submitted August 13, 2023 at 11:46PM by louis11
via reddit https://ift.tt/YfXC9zt
The Eclectic Light Company
Why macOS anti-malware scans can behave oddly
Why XProtect Remediator scans can report BadPluginServiceSignature status_code 31 and abort, and why you don’t need to do anything about it.
SAP Security: Vulnerability Analysis By RedRays
https://ift.tt/bHpLaM0
Submitted August 14, 2023 at 02:48PM by vah_13
via reddit https://ift.tt/nzuisUV
https://ift.tt/bHpLaM0
Submitted August 14, 2023 at 02:48PM by vah_13
via reddit https://ift.tt/nzuisUV
RedRays - Your SAP Security Solution
SAP Security: Vulnerability Analysis By RedRays
RedRays' comprehensive SAP security analysis reveals critical vulnerabilities across 10,000 public IP addresses. Discover the severity distribution, insights into the most pressing vulnerabilities, and RedRays' innovative, accessible solutions for SAP security.