WatchGuard Firewall Clientless SSO sends out its password hashes to random devices on the network.
https://ift.tt/RP9Arst
Submitted October 09, 2023 at 04:56AM by ezzzzz
via reddit https://ift.tt/x15Z8Sg
https://ift.tt/RP9Arst
Submitted October 09, 2023 at 04:56AM by ezzzzz
via reddit https://ift.tt/x15Z8Sg
Research Blog | Project Black
A Watchguard Vulnerability That's a "Feature" - GuardLapse
Picture this: a feature from a security appliance that willingly dispatches its password hashes to any device on the network. That is precisely what WatchGuard's SSO does under certain circumstances. Does a bad feature warrant filing a CVE? I'm not sure.
PersistenceSniper v1.13.0 and in-depth Wiki by @last0x00
https://ift.tt/MCvAGFR
Submitted October 09, 2023 at 01:39PM by last0x00
via reddit https://ift.tt/YXToqBD
https://ift.tt/MCvAGFR
Submitted October 09, 2023 at 01:39PM by last0x00
via reddit https://ift.tt/YXToqBD
GitHub
GitHub - last-byte/PersistenceSniper: Powershell module that can be used by Blue Teams, Incident Responders and System Administrators…
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w...
Smashing the state machine: the true potential of web race conditions
https://ift.tt/lQBwhcA
Submitted October 09, 2023 at 03:58PM by meowerguy
via reddit https://ift.tt/fXqjodI
https://ift.tt/lQBwhcA
Submitted October 09, 2023 at 03:58PM by meowerguy
via reddit https://ift.tt/fXqjodI
PortSwigger Research
Smashing the state machine: the true potential of web race conditions
For too long, web race condition attacks have focused on a tiny handful of scenarios. Their true potential has been masked thanks to tricky workflows, missing tooling, and simple network jitter hiding
Hacking GTA V RP Servers Using Web Exploitation Techniques
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
www.nullpt.rs
nullpt.rs • blog
A technical blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
The GitHub Blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
CVE-2023-43641 is a vulnerability in libcue, which can lead to code execution by downloading a file on GNOME.
Doxing in 2023
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
Livejournal
⋚ doxing 2.0 ⋚ evolved, modern methods
author : pad, x.com/123456 i just stumbled into a skiptracing/ssn doxing service on fiverr wow and it inspired me to write a second post on doxing that is relevant in 2023. the skiptracing/ssn platform in question on fiverr is called tloxp - a tool used by…
Microsoft is finally deprecating vbnoscript
https://ift.tt/h518KnH
Submitted October 10, 2023 at 11:13AM by FireFart
via reddit https://ift.tt/VjTe1uQ
https://ift.tt/h518KnH
Submitted October 10, 2023 at 11:13AM by FireFart
via reddit https://ift.tt/VjTe1uQ
Docs
Deprecated features in the Windows client
Review the list of features that Microsoft is no longer actively developing in Windows 10 and Windows 11.
How to build a IP Geolocation Database from Scratch
https://ift.tt/DGUA6yI
Submitted October 10, 2023 at 01:43PM by incolumitas
via reddit https://ift.tt/v2uKL4w
https://ift.tt/DGUA6yI
Submitted October 10, 2023 at 01:43PM by incolumitas
via reddit https://ift.tt/v2uKL4w
ipapi.is
ipapi.is - Geolocation
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
D-Link DAP-X1860: RCE via crafted SSID name (CVE-2023-45208)
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
www.redteam-pentesting.de
RedTeam Pentesting - D-Link DAP-X1860: Remote Command Injection
The Wi-Fi network scanning functionality of the D-Link DAP-X1860 range extender is susceptible to remote command injection. Attackers who create a Wi-Fi network with a crafted SSID in range of the extender can run shell commands during the setup process or…
Colour me purple | CyberCX
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
CyberCX
Colour me purple
Shifting organisations from traditional point-in-time security assessments to a holistic view of overall security requires an innovative approach to cyber security assessments.
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
LoyaltyLobby
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
Air Europa leaks credit card information and advices passengers to call their banks and cancel payment cards.
CVE-2023-44487 - HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
F5
HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
Update your NGINX configuration to mitigate a possible denial-of-service attack implemented on the server-side portion of the HTTP/2 specification.
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
The Cloudflare Blog
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet.
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
Shelltrail - Swedish offensive security experts
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension | Shelltrail - Swedish offensive security…
New research into an (legacy) extension for Microsoft Endpoint Configuration Manager/SCCM/ConfigMgr reveal new attack paths for Active Directory domain compromise or elevation of privileges.
Google mitigated the largest DDoS attack to date, peaking above 398 million rps
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
Google Cloud Blog
Google Cloud mitigated largest DDoS attack, peaking above 398 million rps | Google Cloud Blog
Google Cloud stopped the largest known DDoS attack to date, which exploited HTTP/2 stream multiplexing using the new “Rapid Reset” technique.
Cloud Provider Credentials Targeted in New PyPI Malware Campaign
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
Phylum
Malicious PyPI packages stealing cloud credentials
Malware packages found on PyPI stealing cloud credentials from unsuspecting developers.
An Algorithm to Detect Hosting Providers and their IP Ranges
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
ipapi.is
ipapi.is - An Algorithm to Detect Hosting Providers and their IP Ranges
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
Security Tips & Devices for Digital Nomads
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
How I made a heap overflow in curl
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
Reddit
From the netsec community on Reddit: How I made a heap overflow in curl
Posted by sanitybit - 42 votes and no comments
curl - SOCKS5 heap buffer overflow
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
Reddit
From the netsec community on Reddit: curl - SOCKS5 heap buffer overflow
Posted by Vegetable_Machine_45 - 108 votes and 27 comments
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
Squid-Security-Audit
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
A detailed repository of vulnerabilities that I discovered in The Squid Caching Proxy.