D-Link DAP-X1860: RCE via crafted SSID name (CVE-2023-45208)
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
https://ift.tt/N38hyQi
Submitted October 10, 2023 at 01:28PM by RedTeamPentesting
via reddit https://ift.tt/lLbEeo4
www.redteam-pentesting.de
RedTeam Pentesting - D-Link DAP-X1860: Remote Command Injection
The Wi-Fi network scanning functionality of the D-Link DAP-X1860 range extender is susceptible to remote command injection. Attackers who create a Wi-Fi network with a crafted SSID in range of the extender can run shell commands during the setup process or…
Colour me purple | CyberCX
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
https://ift.tt/JjIFQKq
Submitted October 10, 2023 at 01:12PM by CptWin_NZ
via reddit https://ift.tt/n0YD8us
CyberCX
Colour me purple
Shifting organisations from traditional point-in-time security assessments to a holistic view of overall security requires an innovative approach to cyber security assessments.
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
https://ift.tt/CgIMpET
Submitted October 10, 2023 at 04:38PM by XS4Me
via reddit https://ift.tt/VeR3i7j
LoyaltyLobby
Air Europa Hacked & Passengers Advised To Cancel Credit Cards
Air Europa leaks credit card information and advices passengers to call their banks and cancel payment cards.
CVE-2023-44487 - HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
https://ift.tt/IXMjLtD
Submitted October 10, 2023 at 05:32PM by lochii
via reddit https://ift.tt/C3KPSVw
F5
HTTP/2 Rapid Reset Attack Impacting F5 NGINX Products
Update your NGINX configuration to mitigate a possible denial-of-service attack implemented on the server-side portion of the HTTP/2 specification.
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
https://ift.tt/LY4QRzS
Submitted October 10, 2023 at 06:38PM by moviuro
via reddit https://ift.tt/6xXQwzS
The Cloudflare Blog
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet.
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
https://ift.tt/QsIYDzX
Submitted October 10, 2023 at 06:50PM by ivxrehc
via reddit https://ift.tt/IxqaWc3
Shelltrail - Swedish offensive security experts
Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension | Shelltrail - Swedish offensive security…
New research into an (legacy) extension for Microsoft Endpoint Configuration Manager/SCCM/ConfigMgr reveal new attack paths for Active Directory domain compromise or elevation of privileges.
Google mitigated the largest DDoS attack to date, peaking above 398 million rps
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/
Submitted October 11, 2023 at 12:04AM by louis11
via reddit https://ift.tt/G47XYvD
Google Cloud Blog
Google Cloud mitigated largest DDoS attack, peaking above 398 million rps | Google Cloud Blog
Google Cloud stopped the largest known DDoS attack to date, which exploited HTTP/2 stream multiplexing using the new “Rapid Reset” technique.
Cloud Provider Credentials Targeted in New PyPI Malware Campaign
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
https://ift.tt/bSPWOpo
Submitted October 11, 2023 at 12:01AM by louis11
via reddit https://www.reddit.com/r/netsec/comments/174sdhl/cloud_provider_credentials_targeted_in_new_pypi/?utm_source=ifttt
Phylum
Malicious PyPI packages stealing cloud credentials
Malware packages found on PyPI stealing cloud credentials from unsuspecting developers.
An Algorithm to Detect Hosting Providers and their IP Ranges
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
https://ift.tt/1WSrvIy
Submitted October 11, 2023 at 01:15AM by incolumitas
via reddit https://ift.tt/ikoxs6n
ipapi.is
ipapi.is - An Algorithm to Detect Hosting Providers and their IP Ranges
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
Security Tips & Devices for Digital Nomads
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
https://officercia.mirror.xyz/GX0LvoKDcC12ACXzhT3F_3PVRSfEyhE8cJYMZnoia9U
Submitted October 11, 2023 at 05:17AM by Silent-Homework7613
via reddit https://ift.tt/rZ5yXSj
How I made a heap overflow in curl
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
Reddit
From the netsec community on Reddit: How I made a heap overflow in curl
Posted by sanitybit - 42 votes and no comments
curl - SOCKS5 heap buffer overflow
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
Reddit
From the netsec community on Reddit: curl - SOCKS5 heap buffer overflow
Posted by Vegetable_Machine_45 - 108 votes and 27 comments
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
Squid-Security-Audit
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
A detailed repository of vulnerabilities that I discovered in The Squid Caching Proxy.
Critically close to zero (day): Exploiting Microsoft Kernel streaming service
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
Security Intelligence
Critically close to zero(day): Exploiting Microsoft Kernel streaming service
Microsoft recently found and patched a vulnerability in the Microsoft Kernel streaming service. Learn more here.
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
RedTeam Pentesting - Blog
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
Ghostnoscript is the backbone of document processing for a lot of web apps and programs. If you have never heard of Ghostnoscript yet, you still have very likely already used it a lot through various programs such as PDF viewers, office suites or …
Not Your Stdout Bug - RCE in Cosmos SDK
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
Strikeout Security Blog
Not Your Stdout Bug - RCE in Cosmos SDK
Hacking the Cosmos SDK via the watchdog process manager Cosmovisor.
Key management of OpenPGP Card
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
hardenedvault.net
Key management of OpenPGP Card
Background As blank smartcards supporting Java Card 3.0.4 become increasingly available, it is becoming popular to use projects like SmartPGP to create homemade OpenPGP Cards to store OpenPGP private keys.
PEN-300/OSEP NetSecFocus Trophy list - Great boxes to look for prepping
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
Google Docs
NetSecFocus Trophy Room
PWK V1
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
Hands-on guide to triaging firmware vulnerability alerts with full system emulation. Based on the case study of CVE-2023-4249. (command injection)
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
Bugprove
IoT Bug Hunting - Part 2 - Walkthrough of discovering command injections in firmware binaries
We present the steps that can lead you to another variation of an OS command injection vulnerability (CVE-2023-4249) in multiple Zavio IP camera models.
How to detect Wi-Fi deauthentication attack and even receive notification on your smartphone
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
Mobile Hacker
Detect Wi-Fi deauthentication attack using ESP8266 and receive notification on smartphone - Mobile Hacker
A Wi-Fi deauthentication attack, also known as a "deauth attack" or "disassociation attack," is a type of denial-of-service that targets wireless networks. The primary goal of this attack is to disconnect or deauthenticate devices (such as smartphones, laptops…
Length extension attack + HMAC explained
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
Reddit
From the netsec community on Reddit: Length extension attack + HMAC explained
Posted by ijk_xyz2 - 6 votes and no comments