Exim 4.96.2 - SMTP Mail Server - Message Transfer Agent (MTA) - CVE ZDI
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
https://exim.org/
Submitted October 16, 2023 at 12:29AM by Neustradamus
via reddit https://ift.tt/JQUt3Oa
www.exim.org
Exim Internet Mailer
Exim is a message transfer agent (MTA) developed at the University of Cambridge for use on Unix systems connected to the Internet.
GitHub - sterrasec/dummy: Generator of static files for testing file upload. It can generate the png file of any number of bytes!
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
https://ift.tt/DUqQrCT
Submitted October 16, 2023 at 07:54AM by tkmru
via reddit https://ift.tt/GmZRFNL
GitHub
GitHub - sterrasec/dummy: Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files…
Generator of static files(csv, jpeg, png, pdf) for testing file upload. It can generate csv and png files of any number of bytes! - sterrasec/dummy
Designing, Building and Running CTFs in 2023
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
https://ift.tt/EBWbhQJ
Submitted October 16, 2023 at 03:30PM by DLLCoolJ
via reddit https://ift.tt/XKghzTm
Battle of The Bots
Building Micro-CGC Events - Art of The Flag
Battle of The Bots Website
“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts
https://ift.tt/L2Ufl36
Submitted October 16, 2023 at 02:45PM by exotic_jj
via reddit https://ift.tt/rciFDkR
https://ift.tt/L2Ufl36
Submitted October 16, 2023 at 02:45PM by exotic_jj
via reddit https://ift.tt/rciFDkR
guard.io
“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts
Public AWS RDS
https://ift.tt/RnGo7Ph
Submitted October 16, 2023 at 10:57PM by Current_Pomelo_3402
via reddit https://ift.tt/DyPBG6Z
https://ift.tt/RnGo7Ph
Submitted October 16, 2023 at 10:57PM by Current_Pomelo_3402
via reddit https://ift.tt/DyPBG6Z
Cloud Security Partners Blog
RDS Revealed? Time to Give It Some Shade!
By: John Poulin
At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A…
At Cloud Security Partners, we have audited thousands of customer AWS accounts as part of our security reviews. Across our customers, roughly 5% of the AWS Relational Database Service (RDS) instances we analyze are publicly accessible. A…
Hacking ServiceNow Instances While Unauthenticated For Fun and Profit
https://ift.tt/p9vnDHm
Submitted October 16, 2023 at 11:46PM by dantalion4040
via reddit https://ift.tt/m0sH8br
https://ift.tt/p9vnDHm
Submitted October 16, 2023 at 11:46PM by dantalion4040
via reddit https://ift.tt/m0sH8br
Enumerated
Data Exposure and ServiceNow: The Elephant in the ITSM Room — Enumerated
This research is written and discovered by Aaron Costello (Twitter @ConspiracyProof). Daniel Miessler has had absolutely no part in the research nor this article. His sole link to the research is taking statements from this very article and reposting them…
Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
https://ift.tt/BAb3jai
Submitted October 17, 2023 at 11:11AM by albhed
via reddit https://ift.tt/XClg4S6
https://ift.tt/BAb3jai
Submitted October 17, 2023 at 11:11AM by albhed
via reddit https://ift.tt/XClg4S6
Persistent cross-site-noscripting vulnerabilities in Liferay Portal software
https://ift.tt/LEefPDS
Submitted October 17, 2023 at 10:55AM by aunga
via reddit https://ift.tt/ybqVTGL
https://ift.tt/LEefPDS
Submitted October 17, 2023 at 10:55AM by aunga
via reddit https://ift.tt/ybqVTGL
Pentagrid AG
Persistent cross-site noscripting vulnerabilities in Liferay Portal
CVE-2023-42627, CVE-2023-42628, CVE-2023-42629: Several stored cross-site noscripting vulnerabilities in Liferay Portal
Authentication Bypass(es) in CasaOS (CVE-2023-37265, CVE-2023-37266)
https://ift.tt/Yw9sRyB
Submitted October 17, 2023 at 03:25PM by monoimpact
via reddit https://ift.tt/fXl27no
https://ift.tt/Yw9sRyB
Submitted October 17, 2023 at 03:25PM by monoimpact
via reddit https://ift.tt/fXl27no
Sonarsource
Security Vulnerabilities in CasaOS
We recently uncovered two critical code vulnerabilities in the personal cloud system CasaOS. Let's see what we can learn from them.
The MGM Resorts Attack: How Attackers Gained Highly Privileged Access Through Social Engineering
https://ift.tt/aIWwzxp
Submitted October 17, 2023 at 03:18PM by geewasfee
via reddit https://ift.tt/JjOaDNe
https://ift.tt/aIWwzxp
Submitted October 17, 2023 at 03:18PM by geewasfee
via reddit https://ift.tt/JjOaDNe
www.reco.ai
The MGM Resorts Cyber Attack
Learn how SaaS super admins targeted Okta in a social engineering campaign, and how to keep your Okta tenant and highly privileged SaaS identities secure using Reco’s AI-driven approach and comprehensive mapping of data, apps, and identities.
BLE Spam allows now to send unwanted notifications to iOS, Android and Windows at once using Flipper Zero or Android
https://ift.tt/8t4UoFY
Submitted October 17, 2023 at 03:43PM by barakadua131
via reddit https://ift.tt/C0WutX7
https://ift.tt/8t4UoFY
Submitted October 17, 2023 at 03:43PM by barakadua131
via reddit https://ift.tt/C0WutX7
Mobile Hacker
Spam iOS, Android and Windows with Bluetooth pairing messages using Flipper Zero or Android smartphone Mobile Hacker
So far, it was possible to spam through proximity paring messages only iOS devices, either using Flipper Zero, Arduino board or any Android as explained in my previous blog here. However, recently developers of Xtreme firmware for Flipper Zero pushed and…
Widespread Cisco IOS XE Implants in the Wild
https://ift.tt/qkVcxDa
Submitted October 17, 2023 at 05:24PM by chicksdigthelongrun
via reddit https://ift.tt/A7I96RY
https://ift.tt/qkVcxDa
Submitted October 17, 2023 at 05:24PM by chicksdigthelongrun
via reddit https://ift.tt/A7I96RY
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Finding a POP chain on a common Symfony bundle : part 2
https://ift.tt/ptkZwEn
Submitted October 17, 2023 at 06:29PM by meowerguy
via reddit https://ift.tt/BXft3lA
https://ift.tt/ptkZwEn
Submitted October 17, 2023 at 06:29PM by meowerguy
via reddit https://ift.tt/BXft3lA
Synacktiv
Finding a POP chain on a common Symfony bundle : part 2
Bluetooth paring notifications can be now send to iOS, Android and Windows at once using Flipper Zero or any Android
https://ift.tt/8t4UoFY
Submitted October 17, 2023 at 10:06PM by barakadua131
via reddit https://ift.tt/c8T9NRw
https://ift.tt/8t4UoFY
Submitted October 17, 2023 at 10:06PM by barakadua131
via reddit https://ift.tt/c8T9NRw
Mobile Hacker
Spam iOS, Android and Windows with Bluetooth pairing messages using Flipper Zero or Android smartphone Mobile Hacker
So far, it was possible to spam through proximity paring messages only iOS devices, either using Flipper Zero, Arduino board or any Android as explained in my previous blog here. However, recently developers of Xtreme firmware for Flipper Zero pushed and…
Tool to perform GCP Domain Wide Delegation abuse and access Gmail and Drive data
https://ift.tt/3BHe2nG
Submitted October 17, 2023 at 09:43PM by lutzenfried
via reddit https://ift.tt/HRJPcTd
https://ift.tt/3BHe2nG
Submitted October 17, 2023 at 09:43PM by lutzenfried
via reddit https://ift.tt/HRJPcTd
GitHub
GitHub - lutzenfried/Delegate: Tool to perform GCP Domain Wide Delegation abuse and access Gmail and Drive data
Tool to perform GCP Domain Wide Delegation abuse and access Gmail and Drive data - lutzenfried/Delegate
PsMapExec - Windows and Active Directory Lateral Movement Tool
https://ift.tt/g4wzaAr
Submitted October 17, 2023 at 11:15PM by AkimboViper
via reddit https://ift.tt/ATb7R0N
https://ift.tt/g4wzaAr
Submitted October 17, 2023 at 11:15PM by AkimboViper
via reddit https://ift.tt/ATb7R0N
GitHub
GitHub - The-Viper-One/PsMapExec: Dominate Active Directory with PowerShell.
Dominate Active Directory with PowerShell. . Contribute to The-Viper-One/PsMapExec development by creating an account on GitHub.
Synology Replaces Weak PRNG in its NAS Devices, Shuts Down Account Takeover
https://ift.tt/B2ej3x0
Submitted October 18, 2023 at 12:41AM by derp6996
via reddit https://ift.tt/b5GtlM1
https://ift.tt/B2ej3x0
Submitted October 18, 2023 at 12:41AM by derp6996
via reddit https://ift.tt/b5GtlM1
Claroty
Synology NAS DSM Account Takeover: When Random is not Secure
Getting RCE in Chrome with incomplete object initialization in the Maglev compiler
https://ift.tt/GPySdvV
Submitted October 18, 2023 at 12:47PM by poltess0
via reddit https://ift.tt/n2KO1hf
https://ift.tt/GPySdvV
Submitted October 18, 2023 at 12:47PM by poltess0
via reddit https://ift.tt/n2KO1hf
The GitHub Blog
Getting RCE in Chrome with incomplete object initialization in the Maglev compiler
In this post, I'll exploit CVE-2023-4069, a type confusion in Chrome that allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site.
Snapshot fuzzing Windows' direct composition with WTF
https://ift.tt/pINWw8f
Submitted October 18, 2023 at 01:53PM by poltess0
via reddit https://ift.tt/7pg5TOP
https://ift.tt/pINWw8f
Submitted October 18, 2023 at 01:53PM by poltess0
via reddit https://ift.tt/7pg5TOP
Cisco Talos Blog
Snapshot fuzzing direct composition with WTF
Although there is public research on Direct Composition, only a few discuss fuzzing this feature, and none, to our knowledge, that covers snapshot fuzzing.
The single-packet attack: making remote race-conditions 'local'
https://ift.tt/jE4Z6Nc
Submitted October 18, 2023 at 06:34PM by albinowax
via reddit https://ift.tt/i4cnve5
https://ift.tt/jE4Z6Nc
Submitted October 18, 2023 at 06:34PM by albinowax
via reddit https://ift.tt/i4cnve5
PortSwigger Research
The single-packet attack: making remote race-conditions 'local'
The single-packet attack is a new technique for triggering web race conditions. It works by completing multiple HTTP/2 requests with a single TCP packet, which effectively eliminates network jitter an
I made a quick and dirty DLL spoofer in python for DLL hijacking POC's. Makes life a little easier.
https://ift.tt/ebJWBqy
Submitted October 18, 2023 at 08:29PM by thehunter699
via reddit https://ift.tt/kxm4g7z
https://ift.tt/ebJWBqy
Submitted October 18, 2023 at 08:29PM by thehunter699
via reddit https://ift.tt/kxm4g7z
GitHub
GitHub - MitchHS/DLL-Spoofer: POC for a DLL spoofer to determine DLL Hijacking
POC for a DLL spoofer to determine DLL Hijacking. Contribute to MitchHS/DLL-Spoofer development by creating an account on GitHub.