VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
https://ift.tt/Bp8RmAD
Submitted September 05, 2023 at 10:42AM by kongwenbin
via reddit https://ift.tt/NFpoqT6
My Learning Journey
VulnHub Kioptrix Level 1.1 CTF Walkthrough - Step-by-step with Explanations - My Learning Journey
Setup Kioptrix 1.1 & start hacking, commenting & showing every step from recon, port scan, exploitation, privilege escalation & becoming root
When URL parsers disagree (CVE-2023-38633)
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
https://ift.tt/AeQsXgu
Submitted September 05, 2023 at 01:27PM by ScottContini
via reddit https://ift.tt/iUNWTyM
canva.dev
When URL parsers disagree (CVE-2023-38633) - Canva Engineering Blog
Discovery and walkthrough of CVE-2023-38633 in librnoscript, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path traversal.
LFI/RCE Vulnerability in WordPress Media Library Assistant Plugin - CVE-2023-4634 - Patrowl
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
https://ift.tt/IgOBvMy
Submitted September 05, 2023 at 01:52PM by Pepito_oh
via reddit https://ift.tt/fqhSzOJ
Patrowl
External Exposure Management as a Service | Patrowl - Patrowl
Identify and harden your External Security Posture with the leader. Let us manage time-consuming tasks and focus on remediation
Improving nmap's service scanning accuracy and speed with nmap-service-probes data
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
https://ift.tt/IuydGWU
Submitted September 05, 2023 at 03:54PM by MegaManSec2
via reddit https://ift.tt/S6AJwr9
Joshua.Hu
Improve nmap’s service scanning with this 1 weird trick!
In my past two blog posts, I’ve explored how to combine multiple port scanning tools to create a fast service scanning tool for large networks, and how I sped up nmap’s service scanning by changing its “wait for content” time. In this post, I’m going to be…
Analysis of a new Facebook profile stealer written in Node.js
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
https://ift.tt/viba2rX
Submitted September 05, 2023 at 05:07PM by nareksays
via reddit https://ift.tt/QUO51to
Trend Micro
Analyzing a Facebook Profile Stealer Written in Node js
We analyze an information stealer written in Node.js, packaged into an executable, exfiltrated stolen data via both Telegram bot API and a C&C server, and employed GraphQL as a channel for C&C communication.
Live API Keys and Source Code Leaked in 4,500 of the Top Alexa Sites
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
https://ift.tt/wMmcTZX
Submitted September 05, 2023 at 09:58PM by Phorcez
via reddit https://ift.tt/2w0ZWho
Truffle Security
4,500 of the Top 1 Million Websites Leaked Source Code, Secrets - Truffle Security
TruffleHog scanned the top 1 Million visited websites and discovered 4,500 exposed git directories and hundreds of leaked API keys + secrets.
Flaws in IBM Security Verify allows hackers to steal sensitive information
https://ift.tt/AacoeGd
Submitted September 05, 2023 at 09:47PM by nareksays
via reddit https://ift.tt/F24vOuS
https://ift.tt/AacoeGd
Submitted September 05, 2023 at 09:47PM by nareksays
via reddit https://ift.tt/F24vOuS
V9BET
V9BET - Trang cá cược thể thao uy tín, an toàn bậc nhất
V9BET là địa chỉ chơi game online chất lượng hàng đầu tại Việt Nam hiện nay. Mọi thể loại cá cược đều có tại sân chơi. Hãy nhấp link này để khám phá thêm.
Android 14 blocks all modification of system certificates, even as root
https://ift.tt/gUTfzbD
Submitted September 06, 2023 at 03:24AM by pi3ch
via reddit https://ift.tt/B3h0j2U
https://ift.tt/gUTfzbD
Submitted September 06, 2023 at 03:24AM by pi3ch
via reddit https://ift.tt/B3h0j2U
Httptoolkit
Android 14 blocks modification of system certificates, even as root
Update: This post sparked a lot of excellent discussion and debate on workarounds, and there are now multple working solutions to allow certificate injection...
Peeking under the bonnet of the Litter Robot 3
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
https://ift.tt/tsJm5TN
Submitted September 06, 2023 at 07:17AM by thinkV
via reddit https://ift.tt/M3Y8DSI
Elttam
RE of LR3
elttam is an independent security company providing research-driven security assessment services. We combine pragmatism and deep technical insight to help our customers secure their most important assets.
Lord Of The Ring0 part 5 is out (kernel development series)
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
https://ift.tt/1laR4Td
Submitted September 06, 2023 at 11:04AM by Idov31
via reddit https://ift.tt/pDIOmzo
idov31.github.io
Lord Of The Ring0 - Part 5 | Saruman's Manipulation - Ido Veltzman - Security Blog
PrologueIn the last blog post, we learned about the different types of kernel callbacks and created our registry protector driver.In this blog post, I’ll exp...
Looking for someone learn from
https://ift.tt/tAS6TLr
Submitted September 06, 2023 at 01:35PM by Puzzleheaded_Cut_273
via reddit https://ift.tt/Kwe0xGX
https://ift.tt/tAS6TLr
Submitted September 06, 2023 at 01:35PM by Puzzleheaded_Cut_273
via reddit https://ift.tt/Kwe0xGX
How to Write a Secure JWT Library If You Absolutely Must
https://ift.tt/ngrAWoe
Submitted September 06, 2023 at 01:58PM by sarciszewski
via reddit https://ift.tt/C1ZYepT
https://ift.tt/ngrAWoe
Submitted September 06, 2023 at 01:58PM by sarciszewski
via reddit https://ift.tt/C1ZYepT
Semantically Secure
How to Write a Secure JWT Library If You Absolutely Must
I am famously not a fan of JSON Web Tokens (JWT). Like most cryptography and security experts familiar with JWT, I would much rather you use something else if you can. I even proposed a secure alte…
XSS vulnerability in Proton Mail allowed to leak unencrypted emails
https://ift.tt/ua3rwkV
Submitted September 06, 2023 at 03:14PM by SonarPaul
via reddit https://ift.tt/z2NF4kP
https://ift.tt/ua3rwkV
Submitted September 06, 2023 at 03:14PM by SonarPaul
via reddit https://ift.tt/z2NF4kP
Sonarsource
Code Vulnerabilities Put Proton Mails at Risk
The Sonar Research team discovered critical code vulnerabilities in Proton Mail, Skiff and Tutanota. This post covers the technical details of the XSS vulnerability in Proton Mail.
eBPF Offensive Capabilities
https://ift.tt/gGxkl7K
Submitted September 06, 2023 at 07:08PM by weseven
via reddit https://ift.tt/6fnUBgs
https://ift.tt/gGxkl7K
Submitted September 06, 2023 at 07:08PM by weseven
via reddit https://ift.tt/6fnUBgs
Sysdig
eBPF Offensive Capabilities - Get Ready for Next-gen Malware
In this article, we will explore some of the offensive capabilities that eBPF can provide to an attacker and how to defend against them.
Apache Superset Part II: RCE, Credential Harvesting and More
https://ift.tt/OnTc5rA
Submitted September 06, 2023 at 08:13PM by scopedsecurity
via reddit https://ift.tt/41Hxndk
https://ift.tt/OnTc5rA
Submitted September 06, 2023 at 08:13PM by scopedsecurity
via reddit https://ift.tt/41Hxndk
Horizon3.ai
Apache Superset Part II: RCE, Credential Harvesting and More – Horizon3.ai
Apache Superset is a popular open source data exploration and visualization tool. In a previous post, we disclosed a vulnerability, CVE-2023-27524, affecting thousands of Superset servers on the Internet, that […]
Main Analytical Frameworks for CTI
https://ift.tt/ftZR1dn
Submitted September 06, 2023 at 08:04PM by ziyahanalbeniz
via reddit https://ift.tt/5G3hxMz
https://ift.tt/ftZR1dn
Submitted September 06, 2023 at 08:04PM by ziyahanalbeniz
via reddit https://ift.tt/5G3hxMz
SOCRadar® Cyber Intelligence Inc.
Main Analytical Frameworks for Cyber Threat Intelligence
Threat intelligence is a cyber-security discipline focusing on detailed knowledge about the cyber threats targeting an organization. Threat...
Dissect : hi all looking for command dissect framework : how can i export image file or just it. how can check hash for hidden file or restore file, i try it by going true the documation but i could'nt found the correct way thanks :)
https://ift.tt/K87R5mT
Submitted September 06, 2023 at 10:30PM by SULeI_man
via reddit https://ift.tt/liVtaJo
https://ift.tt/K87R5mT
Submitted September 06, 2023 at 10:30PM by SULeI_man
via reddit https://ift.tt/liVtaJo
DogeRAT malware targets Indian users (tracks Locations, makes illegal payments, and more)
https://ift.tt/kavyE7F
Submitted September 06, 2023 at 10:08PM by nareksays
via reddit https://ift.tt/zvJtSf4
https://ift.tt/kavyE7F
Submitted September 06, 2023 at 10:08PM by nareksays
via reddit https://ift.tt/zvJtSf4
Deform
DogeRAT Malware Strikes India: Tracks Locations, Makes Unauthorized Payments - Deform
Indian Android users are under threat from DogeRAT, a malicious software that illicitly accesses critical data, including banking information, contacts, and
Results of Major Technical Investigations for Storm-0558 Key Acquisition (How a threat actor acquired and used a Microsoft signing key to access customer emails)
https://ift.tt/zjtQLv8
Submitted September 07, 2023 at 12:25AM by The_Electric_Feel
via reddit https://ift.tt/8Z4OKak
https://ift.tt/zjtQLv8
Submitted September 07, 2023 at 12:25AM by The_Electric_Feel
via reddit https://ift.tt/8Z4OKak
Microsoft
Results of Major Technical Investigations for Storm-0558 Key Acquisition | MSRC Blog
| Microsoft Security Response Center
| Microsoft Security Response Center
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
https://ift.tt/u1UzGXS
Submitted September 07, 2023 at 03:46AM by k4m1ll0
via reddit https://ift.tt/w5tnp7u
https://ift.tt/u1UzGXS
Submitted September 07, 2023 at 03:46AM by k4m1ll0
via reddit https://ift.tt/w5tnp7u
www.vicarius.io
A tale about a Red Team exercise and the Forcepoint Endpoint One DLP client - vsociety
Mastering Third Party Risk Assessments: A Detailed Guide
https://ift.tt/1O4PaFo
Submitted September 07, 2023 at 07:54AM by OkPossible7152
via reddit https://ift.tt/Hg67pLN
https://ift.tt/1O4PaFo
Submitted September 07, 2023 at 07:54AM by OkPossible7152
via reddit https://ift.tt/Hg67pLN
Virtual Cybersecurit
Mastering Third Party Risk Assessments: A Detailed Guide
Steps for Conducting a Third-Party Risk Assessment: Define Assessment Criteria (NIST Framework Integration): Tailoring NIST's Cybersecurity Framework to your organization's specific needs is crucial when defining assessment criteria. These criteria encompass…