Hacking GTA V RP Servers Using Web Exploitation Techniques
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
https://ift.tt/xluPbz8
Submitted October 09, 2023 at 03:57PM by meowerguy
via reddit https://ift.tt/VQ9jNZ5
www.nullpt.rs
nullpt.rs • blog
A technical blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
https://ift.tt/UmrVb3L
Submitted October 09, 2023 at 10:47PM by f311a
via reddit https://ift.tt/sS45L3Y
The GitHub Blog
Coordinated Disclosure: 1-Click RCE on GNOME (CVE-2023-43641)
CVE-2023-43641 is a vulnerability in libcue, which can lead to code execution by downloading a file on GNOME.
Doxing in 2023
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
https://ift.tt/i1OZx6I
Submitted October 10, 2023 at 06:18AM by nantucket
via reddit https://ift.tt/fTD74nI
Livejournal
⋚ doxing 2.0 ⋚ evolved, modern methods
author : pad, x.com/123456 i just stumbled into a skiptracing/ssn doxing service on fiverr wow and it inspired me to write a second post on doxing that is relevant in 2023. the skiptracing/ssn platform in question on fiverr is called tloxp - a tool used by…
Microsoft is finally deprecating vbnoscript
https://ift.tt/h518KnH
Submitted October 10, 2023 at 11:13AM by FireFart
via reddit https://ift.tt/VjTe1uQ
https://ift.tt/h518KnH
Submitted October 10, 2023 at 11:13AM by FireFart
via reddit https://ift.tt/VjTe1uQ
Docs
Deprecated features in the Windows client
Review the list of features that Microsoft is no longer actively developing in Windows 10 and Windows 11.
How to build a IP Geolocation Database from Scratch
https://ift.tt/DGUA6yI
Submitted October 10, 2023 at 01:43PM by incolumitas
via reddit https://ift.tt/v2uKL4w
https://ift.tt/DGUA6yI
Submitted October 10, 2023 at 01:43PM by incolumitas
via reddit https://ift.tt/v2uKL4w
ipapi.is
ipapi.is - Geolocation
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
D-Link DAP-X1860: RCE via crafted SSID name (CVE-2023-45208)
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
www.redteam-pentesting.de
RedTeam Pentesting - D-Link DAP-X1860: Remote Command Injection
The Wi-Fi network scanning functionality of the D-Link DAP-X1860 range extender is susceptible to remote command injection. Attackers who create a Wi-Fi network with a crafted SSID in range of the extender can run shell commands during the setup process or…
Colour me purple | CyberCX
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
CyberCX
Colour me purple
Shifting organisations from traditional point-in-time security assessments to a holistic view of overall security requires an innovative approach to cyber security assessments.
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
LoyaltyLobby
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
Air Europa leaks credit card information and advices passengers to call their banks and cancel payment cards.
CVE-2023-44487 - HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
F5
HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
Update your NGINX configuration to mitigate a possible denial-of-service attack implemented on the server-side portion of the HTTP/2 specification.
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
The Cloudflare Blog
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet.
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
Shelltrail - Swedish offensive security experts
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension | Shelltrail - Swedish offensive security…
New research into an (legacy) extension for Microsoft Endpoint Configuration Manager/SCCM/ConfigMgr reveal new attack paths for Active Directory domain compromise or elevation of privileges.
Google mitigated the largest DDoS attack to date, peaking above 398 million rps
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
Google Cloud Blog
Google Cloud mitigated largest DDoS attack, peaking above 398 million rps | Google Cloud Blog
Google Cloud stopped the largest known DDoS attack to date, which exploited HTTP/2 stream multiplexing using the new “Rapid Reset” technique.
Cloud Provider Credentials Targeted in New PyPI Malware Campaign
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
Phylum
Malicious PyPI packages stealing cloud credentials
Malware packages found on PyPI stealing cloud credentials from unsuspecting developers.
An Algorithm to Detect Hosting Providers and their IP Ranges
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
ipapi.is
ipapi.is - An Algorithm to Detect Hosting Providers and their IP Ranges
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
Security Tips & Devices for Digital Nomads
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
How I made a heap overflow in curl
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
Reddit
From the netsec community on Reddit: How I made a heap overflow in curl
Posted by sanitybit - 42 votes and no comments
curl - SOCKS5 heap buffer overflow
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
Reddit
From the netsec community on Reddit: curl - SOCKS5 heap buffer overflow
Posted by Vegetable_Machine_45 - 108 votes and 27 comments
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
Squid-Security-Audit
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
A detailed repository of vulnerabilities that I discovered in The Squid Caching Proxy.
Critically close to zero (day): Exploiting Microsoft Kernel streaming service
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
Security Intelligence
Critically close to zero(day): Exploiting Microsoft Kernel streaming service
Microsoft recently found and patched a vulnerability in the Microsoft Kernel streaming service. Learn more here.
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
RedTeam Pentesting - Blog
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
Ghostnoscript is the backbone of document processing for a lot of web apps and programs. If you have never heard of Ghostnoscript yet, you still have very likely already used it a lot through various programs such as PDF viewers, office suites or …
Not Your Stdout Bug - RCE in Cosmos SDK
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
Strikeout Security Blog
Not Your Stdout Bug - RCE in Cosmos SDK
Hacking the Cosmos SDK via the watchdog process manager Cosmovisor.