Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
https://ift.tt/K13lICX
Submitted October 11, 2023 at 05:24PM by RedTeamPentesting
via reddit https://ift.tt/Pw68iyl
RedTeam Pentesting - Blog
Better dSAFER than Sorry - An Attacker's Overview of Ghostnoscript
Ghostnoscript is the backbone of document processing for a lot of web apps and programs. If you have never heard of Ghostnoscript yet, you still have very likely already used it a lot through various programs such as PDF viewers, office suites or …
Not Your Stdout Bug - RCE in Cosmos SDK
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
https://ift.tt/XoByqbj
Submitted October 11, 2023 at 08:26PM by mdulin2
via reddit https://ift.tt/XGKMUFj
Strikeout Security Blog
Not Your Stdout Bug - RCE in Cosmos SDK
Hacking the Cosmos SDK via the watchdog process manager Cosmovisor.
Key management of OpenPGP Card
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
https://ift.tt/kwvrcmF
Submitted October 11, 2023 at 07:48PM by hardenedvault
via reddit https://ift.tt/S9ARjMO
hardenedvault.net
Key management of OpenPGP Card
Background As blank smartcards supporting Java Card 3.0.4 become increasingly available, it is becoming popular to use projects like SmartPGP to create homemade OpenPGP Cards to store OpenPGP private keys.
PEN-300/OSEP NetSecFocus Trophy list - Great boxes to look for prepping
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
https://ift.tt/ZK6oQLY
Submitted October 12, 2023 at 04:16AM by McLabraid
via reddit https://ift.tt/IQSLVEz
Google Docs
NetSecFocus Trophy Room
PWK V1
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
PWK V1 LIST: ,Disclaimer: The boxes that are contained in this list should be used as a way to get started, to build your practical skills, or brush up on any weak points that you may have in your pentesting methodology. This list is not a substitute…
Hands-on guide to triaging firmware vulnerability alerts with full system emulation. Based on the case study of CVE-2023-4249. (command injection)
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
https://ift.tt/cEYnk4R
Submitted October 12, 2023 at 02:19PM by BugProve
via reddit https://ift.tt/Fu3Sqlv
Bugprove
IoT Bug Hunting - Part 2 - Walkthrough of discovering command injections in firmware binaries
We present the steps that can lead you to another variation of an OS command injection vulnerability (CVE-2023-4249) in multiple Zavio IP camera models.
How to detect Wi-Fi deauthentication attack and even receive notification on your smartphone
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
https://ift.tt/wIzXJrq
Submitted October 12, 2023 at 03:56PM by barakadua131
via reddit https://ift.tt/MQ1f07z
Mobile Hacker
Detect Wi-Fi deauthentication attack using ESP8266 and receive notification on smartphone - Mobile Hacker
A Wi-Fi deauthentication attack, also known as a "deauth attack" or "disassociation attack," is a type of denial-of-service that targets wireless networks. The primary goal of this attack is to disconnect or deauthenticate devices (such as smartphones, laptops…
Length extension attack + HMAC explained
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
https://cryptography.re/notes/LEA/
Submitted October 12, 2023 at 10:04PM by ijk_xyz2
via reddit https://www.reddit.com/r/netsec/comments/176b80m/length_extension_attack_hmac_explained/?utm_source=ifttt
Reddit
From the netsec community on Reddit: Length extension attack + HMAC explained
Posted by ijk_xyz2 - 6 votes and no comments
Good Day Ransomware malware analysis
https://ift.tt/AI502GN
Submitted October 13, 2023 at 06:58AM by ShadowStackRE
via reddit https://ift.tt/TtMdRWV
https://ift.tt/AI502GN
Submitted October 13, 2023 at 06:58AM by ShadowStackRE
via reddit https://ift.tt/TtMdRWV
ShadowStackRE
Good Day Ransomware analysis — ShadowStackRE
Good Day ransomware technical malware analysis
2023 microsoft office XSS
https://ift.tt/dPQFZOm
Submitted October 12, 2023 at 08:17AM by Z4ck_01
via reddit https://ift.tt/6cYHBu5
https://ift.tt/dPQFZOm
Submitted October 12, 2023 at 08:17AM by Z4ck_01
via reddit https://ift.tt/6cYHBu5
PKSecurity
2023 Microsoft Office XSS
Found by @adm1nkyj and @justlikebono
LLM Security Series - Prompt Injection
https://ift.tt/NZvkb8E
Submitted October 13, 2023 at 02:51PM by r0075h3ll
via reddit https://ift.tt/8U92XfL
https://ift.tt/NZvkb8E
Submitted October 13, 2023 at 02:51PM by r0075h3ll
via reddit https://ift.tt/8U92XfL
r0075h3ll.github.io
LLM Security Series - Prompt Injection | r0075h3ll
An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
https://ift.tt/F4l0cfe
Submitted October 13, 2023 at 04:19PM by poltess0
via reddit https://ift.tt/908WpwV
https://ift.tt/F4l0cfe
Submitted October 13, 2023 at 04:19PM by poltess0
via reddit https://ift.tt/908WpwV
Blogspot
An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
By Ian Beer A graph representation of the sandbox escape NSExpression payload In April this year Google's Threat Analysis Group, in ...
Looking for CVE-2023-43261 in the Real World (Industrial Cellular Router)
https://ift.tt/9Vf5pxy
Submitted October 13, 2023 at 10:30PM by chicksdigthelongrun
via reddit https://ift.tt/YmDTpOG
https://ift.tt/9Vf5pxy
Submitted October 13, 2023 at 10:30PM by chicksdigthelongrun
via reddit https://ift.tt/YmDTpOG
VulnCheck
Looking for CVE-2023-43261 in the Real World - Blog - VulnCheck
VulnCheck was excited to breach ICS networks when CVE-2023-43261 was first disclosed. However, there is more to this than the CVE denoscription would lead you to believe. Follow VulnCheck’s journey from CVE denoscription to exploitation in the wild
GitHub - ZephrFish/Stompy: Timestomp Tool to flatten MAC times with a specific timestamp
https://ift.tt/eDmvfbz
Submitted October 15, 2023 at 06:44AM by ZephrX112
via reddit https://ift.tt/MQSW5vG
https://ift.tt/eDmvfbz
Submitted October 15, 2023 at 06:44AM by ZephrX112
via reddit https://ift.tt/MQSW5vG
GitHub
GitHub - ZephrFish/Stompy: Timestomp Tool to flatten MAC times with a specific timestamp
Timestomp Tool to flatten MAC times with a specific timestamp - ZephrFish/Stompy
cloudgrep now supports GCP and Azure - Open source tool for searching in cloud storage
https://ift.tt/RVCedQA
Submitted October 15, 2023 at 05:34PM by 0x636f6f6c
via reddit https://ift.tt/sFjkKOq
https://ift.tt/RVCedQA
Submitted October 15, 2023 at 05:34PM by 0x636f6f6c
via reddit https://ift.tt/sFjkKOq
GitHub
Release Latest: Merge pull request #7 from cado-security/cdoman/add-version · cado-security/cloudgrep
Add version 1.01
Exim 4.96.2 - SMTP Mail Server - Message Transfer Agent (MTA) - CVE ZDI
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
www.exim.org
Exim Internet Mailer
Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet.
GitHub - sterrasec/dummy: Generator of static files for testing file upload. It can generate the png file of any number of bytes!
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
GitHub
GitHub - sterrasec/dummy: Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files…
Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files of any number of bytes! - sterrasec/dummy
Designing, Building and Running CTFs in 2023
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
Battle of The Bots
Building Micro-CGC Events - Art of The Flag
Battle of The Bots Website
“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts
https://ift.tt/L2Ufl36
Submitted October 16, 2023 at 02:45PM by exotic_jj
via reddit https://ift.tt/rciFDkR
https://ift.tt/L2Ufl36
Submitted October 16, 2023 at 02:45PM by exotic_jj
via reddit https://ift.tt/rciFDkR
guard.io
“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts
Public AWS RDS
https://ift.tt/RnGo7Ph
Submitted October 16, 2023 at 10:57PM by Current_Pomelo_3402
via reddit https://ift.tt/DyPBG6Z
https://ift.tt/RnGo7Ph
Submitted October 16, 2023 at 10:57PM by Current_Pomelo_3402
via reddit https://ift.tt/DyPBG6Z
Cloud Security Partners Blog
RDS Revealed? Time to Give It Some Shade!
By: John Poulin
At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A…
At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A…
Hacking ServiceNow Instances While Unauthenticated For Fun and Profit
https://ift.tt/p9vnDHm
Submitted October 16, 2023 at 11:46PM by dantalion4040
via reddit https://ift.tt/m0sH8br
https://ift.tt/p9vnDHm
Submitted October 16, 2023 at 11:46PM by dantalion4040
via reddit https://ift.tt/m0sH8br
Enumerated
Data Exposure and ServiceNow: The Elephant in the ITSM Room — Enumerated
This research is written and discovered by Aaron Costello (Twitter @ConspiracyProof). Daniel Miessler has had absolutely no part in the research nor this article. His sole link to the research is taking statements from this very article and reposting them…
Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
https://ift.tt/BAb3jai
Submitted October 17, 2023 at 11:11AM by albhed
via reddit https://ift.tt/XClg4S6
https://ift.tt/BAb3jai
Submitted October 17, 2023 at 11:11AM by albhed
via reddit https://ift.tt/XClg4S6