How I made a heap overflow in curl
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/
Submitted October 11, 2023 at 12:28PM by sanitybit
via reddit https://www.reddit.com/r/netsec/comments/1757u9m/how_i_made_a_heap_overflow_in_curl/?utm_source=ifttt
Reddit
From the netsec community on Reddit: How I made a heap overflow in curl
Posted by sanitybit - 42 votes and no comments
curl - SOCKS5 heap buffer overflow
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
https://curl.se/docs/CVE-2023-38545.html
Submitted October 11, 2023 at 11:28AM by Vegetable_Machine_45
via reddit https://ift.tt/pPuVxL6
Reddit
From the netsec community on Reddit: curl - SOCKS5 heap buffer overflow
Posted by Vegetable_Machine_45 - 108 votes and 27 comments
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
https://ift.tt/rv5JPMs
Submitted October 11, 2023 at 01:26PM by MegaManSec2
via reddit https://ift.tt/0wEoui3
Squid-Security-Audit
Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
A detailed repository of vulnerabilities that I discovered in The Squid Caching Proxy.
Critically close to zero (day): Exploiting Microsoft Kernel streaming service
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
https://ift.tt/PZLOR0S
Submitted October 11, 2023 at 12:54PM by albinowax
via reddit https://ift.tt/kHJ3uxD
Security Intelligence
Critically close to zero(day): Exploiting Microsoft Kernel streaming service
Microsoft recently found and patched a vulnerability in the Microsoft Kernel streaming service. Learn more here.
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
RedTeam Pentesting - Blog
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
Ghostnoscript is the backbone of document processing for a lot of web apps and programs. If you have never heard of Ghostnoscript yet, you still have very likely already used it a lot through various programs such as PDF viewers, office suites or …
Not Your Stdout Bug - RCE in Cosmos SDK
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
Strikeout Security Blog
Not Your Stdout Bug - RCE in Cosmos SDK
Hacking the Cosmos SDK via the watchdog process manager Cosmovisor.
Key management of OpenPGP Card
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
hardenedvault.net
Key management of OpenPGP Card
Background As blank smartcards supporting Java Card 3.0.4 become increasingly available, it is becoming popular to use projects like SmartPGP to create homemade OpenPGP Cards to store OpenPGP private keys.
PEN-300/OSEP NetSecFocus Trophy list - Great boxes to look for prepping
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
Google Docs
NetSecFocus Trophy Room
PWK V1
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
Hands-on guide to triaging firmware vulnerability alerts with full system emulation. Based on the case study of CVE-2023-4249. (command injection)
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
Bugprove
IoT Bug Hunting - Part 2 - Walkthrough of discovering command injections in firmware binaries
We present the steps that can lead you to another variation of an OS command injection vulnerability (CVE-2023-4249) in multiple Zavio IP camera models.
How to detect Wi-Fi deauthentication attack and even receive notification on your smartphone
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
Mobile Hacker
Detect Wi-Fi deauthentication attack using ESP8266 and receive notification on smartphone - Mobile Hacker
A Wi-Fi deauthentication attack, also known as a "deauth attack" or "disassociation attack," is a type of denial-of-service that targets wireless networks. The primary goal of this attack is to disconnect or deauthenticate devices (such as smartphones, laptops…
Length extension attack + HMAC explained
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
Reddit
From the netsec community on Reddit: Length extension attack + HMAC explained
Posted by ijk_xyz2 - 6 votes and no comments
Good Day Ransomware malware analysis
https://ift.tt/AI502GN
Submitted October 13, 2023 at 06:58AM by ShadowStackRE
via reddit https://ift.tt/TtMdRWV
https://ift.tt/AI502GN
Submitted October 13, 2023 at 06:58AM by ShadowStackRE
via reddit https://ift.tt/TtMdRWV
ShadowStackRE
Good Day Ransomware analysis — ShadowStackRE
Good Day ransomware technical malware analysis
2023 microsoft office XSS
https://ift.tt/dPQFZOm
Submitted October 12, 2023 at 08:17AM by Z4ck_01
via reddit https://ift.tt/6cYHBu5
https://ift.tt/dPQFZOm
Submitted October 12, 2023 at 08:17AM by Z4ck_01
via reddit https://ift.tt/6cYHBu5
PKSecurity
2023 Microsoft Office XSS
Found by @adm1nkyj and @justlikebono
LLM Security Series - Prompt Injection
https://ift.tt/NZvkb8E
Submitted October 13, 2023 at 02:51PM by r0075h3ll
via reddit https://ift.tt/8U92XfL
https://ift.tt/NZvkb8E
Submitted October 13, 2023 at 02:51PM by r0075h3ll
via reddit https://ift.tt/8U92XfL
r0075h3ll.github.io
LLM Security Series - Prompt Injection | r0075h3ll
An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
https://ift.tt/F4l0cfe
Submitted October 13, 2023 at 04:19PM by poltess0
via reddit https://ift.tt/908WpwV
https://ift.tt/F4l0cfe
Submitted October 13, 2023 at 04:19PM by poltess0
via reddit https://ift.tt/908WpwV
Blogspot
An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
By Ian Beer A graph representation of the sandbox escape NSExpression payload In April this year Google's Threat Analysis Group, in ...
Looking for CVE-2023-43261 in the Real World (Industrial Cellular Router)
https://ift.tt/9Vf5pxy
Submitted October 13, 2023 at 10:30PM by chicksdigthelongrun
via reddit https://ift.tt/YmDTpOG
https://ift.tt/9Vf5pxy
Submitted October 13, 2023 at 10:30PM by chicksdigthelongrun
via reddit https://ift.tt/YmDTpOG
VulnCheck
Looking for CVE-2023-43261 in the Real World - Blog - VulnCheck
VulnCheck was excited to breach ICS networks when CVE-2023-43261 was first disclosed. However, there is more to this than the CVE denoscription would lead you to believe. Follow VulnCheck’s journey from CVE denoscription to exploitation in the wild
GitHub - ZephrFish/Stompy: Timestomp Tool to flatten MAC times with a specific timestamp
https://ift.tt/eDmvfbz
Submitted October 15, 2023 at 06:44AM by ZephrX112
via reddit https://ift.tt/MQSW5vG
https://ift.tt/eDmvfbz
Submitted October 15, 2023 at 06:44AM by ZephrX112
via reddit https://ift.tt/MQSW5vG
GitHub
GitHub - ZephrFish/Stompy: Timestomp Tool to flatten MAC times with a specific timestamp
Timestomp Tool to flatten MAC times with a specific timestamp - ZephrFish/Stompy
cloudgrep now supports GCP and Azure - Open source tool for searching in cloud storage
https://ift.tt/RVCedQA
Submitted October 15, 2023 at 05:34PM by 0x636f6f6c
via reddit https://ift.tt/sFjkKOq
https://ift.tt/RVCedQA
Submitted October 15, 2023 at 05:34PM by 0x636f6f6c
via reddit https://ift.tt/sFjkKOq
GitHub
Release Latest: Merge pull request #7 from cado-security/cdoman/add-version · cado-security/cloudgrep
Add version 1.01
Exim 4.96.2 - SMTP Mail Server - Message Transfer Agent (MTA) - CVE ZDI
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
www.exim.org
Exim Internet Mailer
Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet.
GitHub - sterrasec/dummy: Generator of static files for testing file upload. It can generate the png file of any number of bytes!
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
GitHub
GitHub - sterrasec/dummy: Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files…
Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files of any number of bytes! - sterrasec/dummy
Designing, Building and Running CTFs in 2023
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
Battle of The Bots
Building Micro-CGC Events - Art of The Flag
Battle of The Bots Website