Introducing cmloot.py - New tooling for attacking Configuration Manager
https://ift.tt/jHtKn9y
Submitted October 05, 2023 at 03:11PM by ivxrehc
via reddit https://ift.tt/dt0M7G1
https://ift.tt/jHtKn9y
Submitted October 05, 2023 at 03:11PM by ivxrehc
via reddit https://ift.tt/dt0M7G1
Shelltrail - Swedish offensive security experts
Introducing cmloot.py - New tooling for attacking Configuration Manager | Shelltrail - Swedish offensive security experts
cmloot.py introduces new angles to exploit Configuration Manager, which has become the new black in internal security assessments of Active Directory environments.
Yet More Unauth Remote Command Execution Vulns in Firewalls - Sangfor Edition
https://ift.tt/DsYUGfa
Submitted October 05, 2023 at 02:58PM by dx7r__
via reddit https://ift.tt/FCvgYie
https://ift.tt/DsYUGfa
Submitted October 05, 2023 at 02:58PM by dx7r__
via reddit https://ift.tt/FCvgYie
watchTowr Labs
Yet More Unauth Remote Command Execution Vulns in Firewalls - Sangfor Edition
You’re likely seeing a trend - yes, we know, we look at a lot of enterprise-grade software and appliances. Today, we’re not here to change your expectations of us - we’re looking at more enterprise-grade software and appliances.
Today, we’re looking at Sangfor’s…
Today, we’re looking at Sangfor’s…
NetHunter Hacker IX: How to use MANA Toolkit to create Wi-Fi rogue access point and intercept traffic
https://ift.tt/zQujfs3
Submitted October 05, 2023 at 04:40PM by barakadua131
via reddit https://ift.tt/ajpEXns
https://ift.tt/zQujfs3
Submitted October 05, 2023 at 04:40PM by barakadua131
via reddit https://ift.tt/ajpEXns
Mobile Hacker
NetHunter Hacker IX: Use MANA Toolkit to create Wi-Fi rogue access point and intercept traffic Mobile Hacker
MANA allows you to perform various Wi-Fi attacks even using your Android device. The MANA (MITM And Network Attacks) Wireless Toolkit is a suite of tools that can be used to perform man-in-the-middle (MITM) attacks, create evil access point, denial of service…
Curl: Severity HIGH security problem to be announced with curl 8.4.0
https://ift.tt/QBSz2sW
Submitted October 05, 2023 at 04:24PM by Wiremask
via reddit https://ift.tt/wBxYgy3
https://ift.tt/QBSz2sW
Submitted October 05, 2023 at 04:24PM by Wiremask
via reddit https://ift.tt/wBxYgy3
GitHub
Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 · curl/curl · Discussion #12026
We are cutting the release cycle short and will release curl 8.4.0 on October 11, including fixes for a severity HIGH CVE and one severity LOW. The one rated HIGH is probably the worst curl securit...
Beyond XSS: Explore the Web Front-end Security Universe
https://ift.tt/1yIZq6g
Submitted October 05, 2023 at 02:26PM by Available-Egg-7367
via reddit https://ift.tt/aE27cSb
https://ift.tt/1yIZq6g
Submitted October 05, 2023 at 02:26PM by Available-Egg-7367
via reddit https://ift.tt/aE27cSb
aszx87410.github.io
About This Series | Beyond XSS
As a software engineer, you must be familiar with information security. In your work projects, you may have gone through security audits, including static code scanning, vulnerability scanning, or penetration testing. You may have even done more comprehensive…
GitHub - kitabisa/teler-proxy: 🔐 teler Proxy enabling seamless integration with teler WAF 🛡️ to protect locally running web service against a web-based attacks. 🥷
https://ift.tt/M9PEh8R
Submitted October 06, 2023 at 02:49PM by dwisiswant0
via reddit https://ift.tt/gM5VlXP
https://ift.tt/M9PEh8R
Submitted October 06, 2023 at 02:49PM by dwisiswant0
via reddit https://ift.tt/gM5VlXP
GitHub
GitHub - kitabisa/teler-proxy: 🔐 teler Proxy enabling seamless integration with teler WAF 🛡️ to protect locally running web service…
🔐 teler Proxy enabling seamless integration with teler WAF 🛡️ to protect locally running web service against a web-based attacks. 🥷 - GitHub - kitabisa/teler-proxy: 🔐 teler Proxy enabling seamless ...
8 Commandments of Red Cross (ICRC) to Hacker Groups: Do Not Harm Civilians
https://ift.tt/0EtVT4H
Submitted October 06, 2023 at 04:16PM by ziyahanalbeniz
via reddit https://ift.tt/fPLzNgv
https://ift.tt/0EtVT4H
Submitted October 06, 2023 at 04:16PM by ziyahanalbeniz
via reddit https://ift.tt/fPLzNgv
SOCRadar® Cyber Intelligence Inc.
8 Commandments of Red Cross (ICRC) to Hacker Groups: Do Not Harm Civilians
For the very first time, the International Committee of the Red Cross (ICRC) has released a set of guidelines outlining rules of engagement...
Predator Files: Technical deep-dive into Intellexa Alliance's surveillance products
https://ift.tt/Jfukc9E
Submitted October 06, 2023 at 06:13PM by DonnchaOC
via reddit https://ift.tt/pMbK94O
https://ift.tt/Jfukc9E
Submitted October 06, 2023 at 06:13PM by DonnchaOC
via reddit https://ift.tt/pMbK94O
Amnesty International Security Lab
Predator Files: Technical deep-dive into Intellexa Alliance's surveillance products - Amnesty International Security Lab
An expose the Intellexa Alliance's surveillance capabilities including advanced spyware, mass surveillance platforms, and tactical systems for targeting and intercepting nearby devices.
To Schnorr and beyond (Part 1)
https://ift.tt/8BT5sIV
Submitted October 06, 2023 at 07:31PM by feross
via reddit https://ift.tt/RWYDHsf
https://ift.tt/8BT5sIV
Submitted October 06, 2023 at 07:31PM by feross
via reddit https://ift.tt/RWYDHsf
A Few Thoughts on Cryptographic Engineering
To Schnorr and beyond (Part 1)
Warning: extremely wonky cryptography post. Also, possibly stupid and bound for nowhere. One of the hardest problems in applied cryptography (and perhaps all of computer science!) is explaining why…
Vulnerabilities.io - A single pane of glass for your software and software supply chain risks. We're a new platform and looking for user trials and feedback. Identify secrets in code, generate real-time software bill of materials and discover vulnerable third party dependencies. Sign up for free!
https://ift.tt/GEUmP5K
Submitted October 07, 2023 at 02:14AM by VulnerabilitiesIo
via reddit https://ift.tt/z7BsV6S
https://ift.tt/GEUmP5K
Submitted October 07, 2023 at 02:14AM by VulnerabilitiesIo
via reddit https://ift.tt/z7BsV6S
www.vulnerabilities.io
vulnerabilities.io - Vulnerability identification and management
Vulnerability identification and management in one place - a cost-effective developer friendly platform for managing vulnerabilities
Python scanner for critical Atlassian Confluence vulnerability (CVE-2023-22515)
https://ift.tt/f35Q1r6
Submitted October 07, 2023 at 03:20AM by kalibabka
via reddit https://ift.tt/gGJm3ZS
https://ift.tt/f35Q1r6
Submitted October 07, 2023 at 03:20AM by kalibabka
via reddit https://ift.tt/gGJm3ZS
GitHub
GitHub - ErikWynter/CVE-2023-22515-Scan: Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence
Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence - ErikWynter/CVE-2023-22515-Scan
Phishing 2FA 25 years ago
https://ift.tt/Khlpeqj
Submitted October 07, 2023 at 03:14AM by nantucket
via reddit https://ift.tt/YOABG6E
https://ift.tt/Khlpeqj
Submitted October 07, 2023 at 03:14AM by nantucket
via reddit https://ift.tt/YOABG6E
Livejournal
❅ phishing 2fa 25 years ago ❅
two-factor authentication is revered as the end all be all of account security. it shouldn't be. it's been easy to phish 2fa since the 90s. aol employees used physical "rsa securid" devices displaying 6 digits that changed once per minute. i once conceptualized…
AI based ethical hacking tool
https://ift.tt/9mIofP4
Submitted October 07, 2023 at 06:58AM by Civil_Alternative410
via reddit https://ift.tt/Nby4IZq
https://ift.tt/9mIofP4
Submitted October 07, 2023 at 06:58AM by Civil_Alternative410
via reddit https://ift.tt/Nby4IZq
GitHub
GitHub - berylliumsec/nebula: AI-Powered Ethical Hacking Assistant
AI-Powered Ethical Hacking Assistant. Contribute to berylliumsec/nebula development by creating an account on GitHub.
۶ attacking tumblr in 2011 ۶
https://ift.tt/br3KEu1
Submitted October 08, 2023 at 04:29AM by nantucket
via reddit https://ift.tt/iGzQy1L
https://ift.tt/br3KEu1
Submitted October 08, 2023 at 04:29AM by nantucket
via reddit https://ift.tt/iGzQy1L
Livejournal
۶ attacking tumblr in 2011 ۶
author : pad, x.com/123456 i was the most prolific tumblr spammer in 2011/2012. tumblr was popular then - so hacking/spamming it paid the rent. the most heavily publicized tumblr-related event i cast into existence was a scaled phishing attack. i wrote a…
Exploring What AI-powered Cyberattacks Could Look Like
https://ift.tt/CsNeAUI
Submitted October 08, 2023 at 10:07PM by sshh12
via reddit https://ift.tt/0ikGDhE
https://ift.tt/CsNeAUI
Submitted October 08, 2023 at 10:07PM by sshh12
via reddit https://ift.tt/0ikGDhE
blog.sshh.io
AI-powered Cyberattacks
What could cyberattacks look like with advanced generative AI capabilities?
WatchGuard Firewall Clientless SSO sends out its password hashes to random devices on the network.
https://ift.tt/RP9Arst
Submitted October 09, 2023 at 04:56AM by ezzzzz
via reddit https://ift.tt/x15Z8Sg
https://ift.tt/RP9Arst
Submitted October 09, 2023 at 04:56AM by ezzzzz
via reddit https://ift.tt/x15Z8Sg
Research Blog | Project Black
A Watchguard Vulnerability That's a "Feature" - GuardLapse
Picture this: a feature from a security appliance that willingly dispatches its password hashes to any device on the network. That is precisely what WatchGuard's SSO does under certain circumstances. Does a bad feature warrant filing a CVE? I'm not sure.
PersistenceSniper v1.13.0 and in-depth Wiki by @last0x00
https://ift.tt/MCvAGFR
Submitted October 09, 2023 at 01:39PM by last0x00
via reddit https://ift.tt/YXToqBD
https://ift.tt/MCvAGFR
Submitted October 09, 2023 at 01:39PM by last0x00
via reddit https://ift.tt/YXToqBD
GitHub
GitHub - last-byte/PersistenceSniper: Powershell module that can be used by Blue Teams, Incident Responders and System Administrators…
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w...
Smashing the state machine: the true potential of web race conditions
https://ift.tt/lQBwhcA
Submitted October 09, 2023 at 03:58PM by meowerguy
via reddit https://ift.tt/fXqjodI
https://ift.tt/lQBwhcA
Submitted October 09, 2023 at 03:58PM by meowerguy
via reddit https://ift.tt/fXqjodI
PortSwigger Research
Smashing the state machine: the true potential of web race conditions
For too long, web race condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding
Hacking GTA V RP Servers Using Web Exploitation Techniques
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
www.nullpt.rs
nullpt.rs • blog
A technical blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
The GitHub Blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
CVE-2023-43641 is a vulnerability in libcue, which can lead to code execution by downloading a file on GNOME.
Doxing in 2023
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
Livejournal
⋚ doxing 2.0 ⋚ evolved, modern methods
author : pad, x.com/123456 i just stumbled into a skiptracing/ssn doxing service on fiverr wow and it inspired me to write a second post on doxing that is relevant in 2023. the skiptracing/ssn platform in question on fiverr is called tloxp - a tool used by…