Correction: the previous CA injection method doesn't work on Android 14, but there is still a way.
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
https://ift.tt/sIGXlc1
Submitted September 16, 2023 at 05:29AM by pi3ch
via reddit https://ift.tt/FpVcnNY
g1a55er::blog
Android 14 Still Allows Modification of System Certificates
Tim Perry recently claimed in an article that “Android 14 blocks all modification of system certificates, even as root”. This sparked significant discussion on Hacker News. Thankfully my tests show that it is still possible to adjust the system certificate…
New analysis tool: donut-decryptor: Retrieve inner payloads from Donut samples
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
https://ift.tt/legBFKD
Submitted September 16, 2023 at 08:49PM by transt
via reddit https://ift.tt/VGnKl9F
GitHub
GitHub - volexity/donut-decryptor: Retrieve inner payloads from Donut samples
Retrieve inner payloads from Donut samples. Contribute to volexity/donut-decryptor development by creating an account on GitHub.
The bogus CVE problem
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
https://ift.tt/bBntavL
Submitted September 16, 2023 at 09:35PM by keissiaresa
via reddit https://ift.tt/B4tciEp
lwn.net
The bogus CVE problem
The "Common Vulnerabilities and
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Exposures" (CVE) system was launched late
in the previous century (September 1999) to track vulnerabilities in
software. Over the years since, it has had a somewhat checkered
reputation, along with some some attempts to
replace…
Similar issues detected in different cryptocurrency exchange backends
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
https://ift.tt/9Goy5hK
Submitted September 16, 2023 at 10:40PM by arrowflakes
via reddit https://ift.tt/KdsJ08l
CoinFabrik
Quality Assurance QA/QC backend in Cryptocurrency Exchanges
Explore the vital role of quality assurance (QA/QC) backend processes in cryptocurrency exchanges ensuring quality and reliability.
A Big Look at Security in OpenAPI
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
https://ift.tt/2rZH7G8
Submitted September 17, 2023 at 12:15PM by keissiaresa
via reddit https://ift.tt/ftZz34P
Liblab
OpenAPI Security: Five types & best practices
Explore OpenAPI security best practices. Learn the key methods and how they're implemented. See how liblab enhances SDK creation.
Tickling ksmbd: fuzzing SMB in the Linux kernel
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
https://ift.tt/QVwZ0XE
Submitted September 17, 2023 at 02:05PM by buherator
via reddit https://ift.tt/NM6mRUH
Pwning Tech
Tickling ksmbd: fuzzing SMB in the Linux kernel
Following the adventure of manually discovering network-based vulnerabilities in the Linux kernel, I'm adding ksmbd-fuzzing functionality to the already extensive kernel-fuzzing tool that is Syzkaller.
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
https://ift.tt/TIrBcvn
Submitted September 17, 2023 at 02:03PM by buherator
via reddit https://ift.tt/cuOZpma
pyn3rd.github.io
CVE-2023-34040 Spring Kafka Deserialization Remote Code Execution
0x01 PrefaceHere is the explicit denoscription about Spring Kafka deserialization vulnerability in Vmware security bulletin. Reference https://spring.io/security/cve-2023-34040 According to the descrip
CVE-2022-32947: macOS GPU-launched kernel privilege escalation exploit (walkthrough slides + demo)
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
https://ift.tt/MhcX62w
Submitted September 17, 2023 at 03:38PM by AsahiLina
via reddit https://ift.tt/H1eSMyq
Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
https://ift.tt/upRNsbU
Submitted September 17, 2023 at 07:19PM by yqopmin
via reddit https://ift.tt/Kxn5XwN
A Practical Approach to SBOM in CI/CD. Presenting concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
https://ift.tt/xrA2BeI
Submitted September 17, 2023 at 10:27PM by theowni
via reddit https://ift.tt/WqHJ4mM
Medium
A Practical Approach to SBOM in CI/CD Part I — CycloneDX
The article covers the concept of SBOM, its advantages, popular formats and practical implementations for both Java and Python projects.
New SocVel Quiz is out
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
https://ift.tt/DBpfwkb
Submitted September 18, 2023 at 02:16AM by jaco_za
via reddit https://ift.tt/D1JuLS7
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
https://ift.tt/1rYnMFh
Submitted September 18, 2023 at 03:29PM by MegaManSec2
via reddit https://ift.tt/UXpMbTr
Joshua.Hu
Fuzzing with multiple servers in parallel: AFL++ with Network File Systems
Introduction When fuzzing large-scale applications, using a single server (even with 4 64-core AMD Ryzen CPUs) may not be powerful enough by itself. That’s where parallelized/distributed fuzzing comes in (i.e. automatic sharing of results between fuzzing…
Risks in Liechtenstein's electronic health files and new vulns in the underlying Liferay portal software (article in German)
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
https://ift.tt/bzO9HoE
Submitted September 18, 2023 at 06:20PM by fr0r
via reddit https://ift.tt/dWNYjM1
Pentagrid AG
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Lie
IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein
When MFA isn't actually MFA
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
https://ift.tt/kxPigAS
Submitted September 18, 2023 at 08:06PM by _vavkamil_
via reddit https://ift.tt/thwJml6
Retool
When MFA isn't actually MFA
Due to a recent Google change, MFA isn't truly MFA.
Fileless Remote Code Execution on Juniper Firewalls
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
https://ift.tt/OiATbHg
Submitted September 18, 2023 at 08:55PM by chicksdigthelongrun
via reddit https://ift.tt/urEJ1G2
VulnCheck
Fileless Remote Code Execution on Juniper Firewalls - Blog - VulnCheck
Learn about VulnCheck's development of an exploit for CVE-2023-36845, leading to stealthy code execution on Juniper firewalls, while also assessing the prevalence of unpatched systems in the wild.
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation – Sysdig
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
https://ift.tt/tVpozw7
Submitted September 18, 2023 at 08:38PM by Hallow_Rose
via reddit https://ift.tt/5bD49M2
Sysdig
AWS's Hidden Threat: AMBERSQUID Cloud-Native Cryptojacking Operation
AMBERSQUID is a cloud-native cryptojacking operation that leverages AWS services and can cost victims more than $10,000/day.
Zero-Knowledge Middleboxes
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
https://ift.tt/GyHWnsh
Submitted September 19, 2023 at 12:12AM by arrowflakes
via reddit https://ift.tt/4koMUXR
Tor Browser - browse web anonymously sends thru 3 relays layer encryption removed each relay sites see exit relay IP Address. Use with bridges (obsf4, meek-azure, snowflake) if in a country that censors Tor. Also access onion services only accessible via Tor aka "dark web."
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
https://ift.tt/JWP4HCb
Submitted September 19, 2023 at 03:08AM by ComprehensiveFudge22
via reddit https://ift.tt/yxLJuQo
www.torproject.org
The Tor Project | Privacy & Freedom Online
Defend yourself against tracking and surveillance. Circumvent censorship.
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
https://ift.tt/bCMxNrJ
Submitted September 19, 2023 at 11:05AM by fr0r
via reddit https://ift.tt/QltRm2b
Pentagrid AG
Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2
CVE-2023-38346 is a directory traversal vulnerability in Wind River's tarExtract function in VxWorks discovered by Pentagrid during a penetration test and source code review.
DEF CON 31 Main Stage Talks
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
https://www.youtube.com/playlist?list=PL9fPq3eQfaaDLMTtVZDqq4aoU97NhZFP9
Submitted September 19, 2023 at 12:40PM by albinowax
via reddit https://ift.tt/mAJkTWz
Reddit
From the netsec community on Reddit: DEF CON 31 Main Stage Talks
Explore this post and more from the netsec community
#ShortAndMalicious — DarkGate
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
https://ift.tt/vmYrM3i
Submitted September 19, 2023 at 05:15PM by OwnPreparation3424
via reddit https://ift.tt/JiEhXwa
Medium
#ShortAndMalicious — DarkGate
Dissecting DarkGate’s new key log encryption and tools to decrypt key log files