StripedFly: Perennially flying under the radar, infecting 1 million hosts.
https://ift.tt/i5lb91H
Submitted October 30, 2023 at 08:10PM by thehunter699
via reddit https://ift.tt/sGhJFvE
https://ift.tt/i5lb91H
Submitted October 30, 2023 at 08:10PM by thehunter699
via reddit https://ift.tt/sGhJFvE
Securelist
StripedFly: Perennially flying under the radar
Nobody would even suspect the mining malware was merely a mask, masquerading behind an intricate modular framework that supports both Linux and Windows. The amount of effort that went into creating the framework is truly remarkable, and its disclosure was…
DOM-based race condition: racing in the browser for fun
https://ift.tt/DmloFOv
Submitted October 31, 2023 at 03:01PM by poltess0
via reddit https://ift.tt/sFCj2Yb
https://ift.tt/DmloFOv
Submitted October 31, 2023 at 03:01PM by poltess0
via reddit https://ift.tt/sFCj2Yb
blog.ryotak.net
DOM-based race condition: racing in the browser for fun
Disclaimer All projects mentioned in this blog post have been contacted, and I confirmed that the behavior described in this article is either working as intended, already fixed, or will not be fixed.
TL;DR The browser loads elements in the HTML from top…
TL;DR The browser loads elements in the HTML from top…
How to get Wi-Fi password via WPS Button attack using Kali NetHunter
https://ift.tt/UhLycNJ
Submitted October 31, 2023 at 04:18PM by barakadua131
via reddit https://ift.tt/nIowKET
https://ift.tt/UhLycNJ
Submitted October 31, 2023 at 04:18PM by barakadua131
via reddit https://ift.tt/nIowKET
Mobile Hacker
NetHunter Hacker X: WPS attacks - Mobile Hacker
Ever wanted to hack your Wi-Fi network, but your internal adapter doesn’t support monitor mode and you don’t have external adapter? Without switching your Wi-Fi adapter in to monitor mode, WPS attacks allows you to perform various attacks on wireless access…
LDAP authentication in Active Directory environments
https://ift.tt/HxhuQgc
Submitted October 31, 2023 at 05:35PM by AlmondOffSec
via reddit https://ift.tt/aQVP7Um
https://ift.tt/HxhuQgc
Submitted October 31, 2023 at 05:35PM by AlmondOffSec
via reddit https://ift.tt/aQVP7Um
Endomorph: Convert little-endian to big-endian and vice-versa
https://ift.tt/Q6UKlbv
Submitted October 31, 2023 at 06:24PM by r0075h3ll
via reddit https://ift.tt/k7vIP46
https://ift.tt/Q6UKlbv
Submitted October 31, 2023 at 06:24PM by r0075h3ll
via reddit https://ift.tt/k7vIP46
GitHub
GitHub - r0075h3ll/Endomorph: Convert little-endian to big-endian and vice-versa
Convert little-endian to big-endian and vice-versa - r0075h3ll/Endomorph
confluence cve-2023-22518
https://ift.tt/k54Lujo
Submitted October 31, 2023 at 07:10PM by Alfrede81
via reddit https://ift.tt/2LeHp8l
https://ift.tt/k54Lujo
Submitted October 31, 2023 at 07:10PM by Alfrede81
via reddit https://ift.tt/2LeHp8l
How I use John the Ripper for Windows Password Cracking
https://ift.tt/EUHgzib
Submitted October 31, 2023 at 09:48PM by keshav_xplore
via reddit https://ift.tt/R5SaFXj
https://ift.tt/EUHgzib
Submitted October 31, 2023 at 09:48PM by keshav_xplore
via reddit https://ift.tt/R5SaFXj
Keshav Xplore
How to use John the Ripper for Windows Password Cracking
Discover John the Ripper's password-cracking prowess. Crack Windows 10, 8, and 7 passwords and extract hashes with ease.
Practical DoS Attacks Against OPC UA Implementations
https://ift.tt/mZATD0z
Submitted October 31, 2023 at 10:14PM by derp6996
via reddit https://ift.tt/vzgFJBe
https://ift.tt/mZATD0z
Submitted October 31, 2023 at 10:14PM by derp6996
via reddit https://ift.tt/vzgFJBe
Claroty
OPC UA Deep Dive Series (Part 7): Practical Denial of Service Attacks
Throughout our extensive OPC UA Deep Dive Series, we researched the OPC UA protocol and its different functions and importance within operational technology (OT) environments. The centerpiece tool of our work is an advanced OPC UA Exploit Framework we built…
Supercharging Red-Teaming with Infrastructure as Code Integration
https://ift.tt/7dOARnH
Submitted November 01, 2023 at 12:13AM by RoseSec_
via reddit https://ift.tt/oGlBzgp
https://ift.tt/7dOARnH
Submitted November 01, 2023 at 12:13AM by RoseSec_
via reddit https://ift.tt/oGlBzgp
GitHub
GitHub - RoseSecurity-Research/WolfPack: WolfPack combines the capabilities of Terraform and Packer to streamline the deployment…
WolfPack combines the capabilities of Terraform and Packer to streamline the deployment of red team redirectors on a large scale. - GitHub - RoseSecurity-Research/WolfPack: WolfPack combines the ca...
Data-bouncing - New Exfil and C2 Technique
https://ift.tt/QJ4E5B9
Submitted November 01, 2023 at 06:27AM by ZephrX112
via reddit https://ift.tt/AGPnuwS
https://ift.tt/QJ4E5B9
Submitted November 01, 2023 at 06:27AM by ZephrX112
via reddit https://ift.tt/AGPnuwS
The Contractor 🏴☠️🧯
Data-bouncing
Data-Bouncing - The art of indirect exfiltration. Using & Abusing Trusted Domains as a 2nd Order Transport.
How to crack Windows Password
https://ift.tt/EUHgzib
Submitted November 01, 2023 at 08:27AM by keshav_xplore
via reddit https://ift.tt/xJkvO2Y
https://ift.tt/EUHgzib
Submitted November 01, 2023 at 08:27AM by keshav_xplore
via reddit https://ift.tt/xJkvO2Y
Keshav Xplore
How to use John the Ripper for Windows Password Cracking
Discover John the Ripper's password-cracking prowess. Crack Windows 10, 8, and 7 passwords and extract hashes with ease.
Impersonating Slack Users - Red Team Tradecraft
https://ift.tt/0nwkcfl
Submitted November 01, 2023 at 11:41AM by FalconSpy
via reddit https://ift.tt/HjV7wSO
https://ift.tt/0nwkcfl
Submitted November 01, 2023 at 11:41AM by FalconSpy
via reddit https://ift.tt/HjV7wSO
FalconSpy
Impersonating Slack Users - Red Team Tradecraft
Introduction
Critical phpFox RCE Vulnerability Risked Social Networks
https://ift.tt/12F4QxD
Submitted November 01, 2023 at 04:52PM by eg1x
via reddit https://ift.tt/HvQbgFV
https://ift.tt/12F4QxD
Submitted November 01, 2023 at 04:52PM by eg1x
via reddit https://ift.tt/HvQbgFV
LHN
Critical PHPFox RCE Vulnerability Risked Social Networks
Heads up, phpFox users! A critical remote code execution vulnerability existed in the phpFox service that allowed community takeovers. Following the bug report, phpFox patched the flaw with the latest service version to which, the
Official release of CVSS v4.0
https://ift.tt/C80KsAB
Submitted November 01, 2023 at 11:39PM by adityatelange
via reddit https://ift.tt/6BcFGkm
https://ift.tt/C80KsAB
Submitted November 01, 2023 at 11:39PM by adityatelange
via reddit https://ift.tt/6BcFGkm
Infosec Exchange
FIRST.org (@firstdotorg@infosec.exchange)
Attached: 1 image
The CVSS Special Interest Group is proud to announce the official release of CVSS v4.0. This latest release marks a significant step forward with added capabilities crucial for teams with the importance of using threat intelligence and…
The CVSS Special Interest Group is proud to announce the official release of CVSS v4.0. This latest release marks a significant step forward with added capabilities crucial for teams with the importance of using threat intelligence and…
EKS Cluster Games: An EKS-focused CTF Challenge
https://ift.tt/bwh3iNc
Submitted November 01, 2023 at 10:59PM by nirohf
via reddit https://ift.tt/nGQiVK1
https://ift.tt/bwh3iNc
Submitted November 01, 2023 at 10:59PM by nirohf
via reddit https://ift.tt/nGQiVK1
Eksclustergames
EKS Cluster Games
The mission? To identify common AWS EKS security issues and vulnerabilities and learn how to exploit them in practice.
CRLF Injection in SAP HTTP Content Server - CVE-2023-26457
https://ift.tt/CKiAJzW
Submitted November 02, 2023 at 03:21PM by usdAG
via reddit https://ift.tt/y0bOIsR
https://ift.tt/CKiAJzW
Submitted November 02, 2023 at 03:21PM by usdAG
via reddit https://ift.tt/y0bOIsR
usd HeroLab
usd-2022-0046 | usd HeroLab
Advisory ID: usd-2022-0046 | Product: SAP HTTP Content Server | Vulnerability Type: Neutralization of HTTP Headers for Scripting Syntax (CWE-644)
LdrLockLiberator: For when DLLMain is the only way
https://ift.tt/s9QmCwi
Submitted November 02, 2023 at 02:39PM by elliotkillick
via reddit https://ift.tt/Bvb3JNH
https://ift.tt/s9QmCwi
Submitted November 02, 2023 at 02:39PM by elliotkillick
via reddit https://ift.tt/Bvb3JNH
GitHub
GitHub - ElliotKillick/LdrLockLiberator: For when DLLMain is the only way
For when DLLMain is the only way. Contribute to ElliotKillick/LdrLockLiberator development by creating an account on GitHub.
Free and open-source approach to Domain Monitoring.
https://ift.tt/qlCpI5s
Submitted November 02, 2023 at 09:31PM by Seaerkin2
via reddit https://ift.tt/NSOhK3s
https://ift.tt/qlCpI5s
Submitted November 02, 2023 at 09:31PM by Seaerkin2
via reddit https://ift.tt/NSOhK3s
Guardyourdomain
DomainGuard | Threat Visibility Platform
We guard your domain, so you have peace of mind. Threat Visibility Platform.
Security Researchers from Salt-Security explain in a super detailed post how they did account takeover on Grammarly.com, Booking.com, Expo.io, Codecademy.com, Vidio.com, Bukalapak.com, and 100+ Other Websites.
https://ift.tt/9DTVNfd
Submitted November 02, 2023 at 10:06PM by MoreMoreMoreM
via reddit https://ift.tt/vcWihBN
https://ift.tt/9DTVNfd
Submitted November 02, 2023 at 10:06PM by MoreMoreMoreM
via reddit https://ift.tt/vcWihBN
salt.security
Salt Labs Finds OAuth Abuse Used to Take Over Accounts
OAuth Account Takeover. Salt Labs shows how hackers could abuse OAuth to take over millions of accounts on Grammarly, Vidio, and Bukalapak.
Advice For Catching a RedLine Stealer - includes tools to identify C2 protocol
https://ift.tt/gWRkT9M
Submitted November 02, 2023 at 09:56PM by The_Abjuri5t
via reddit https://ift.tt/oOcASZI
https://ift.tt/gWRkT9M
Submitted November 02, 2023 at 09:56PM by The_Abjuri5t
via reddit https://ift.tt/oOcASZI
Medium
Advice For Catching a RedLine Stealer
RedLine Stealer is an infamous malware strain that provides cyber-criminals with a reliable payload for stealing sensitive information from…
Firmware Security Analyzer - EMBA v1.3.1 with firmware diffing mechanism available
https://ift.tt/2Pig6nC
Submitted November 02, 2023 at 11:47PM by _m-1-k-3_
via reddit https://ift.tt/uOBR1Hp
https://ift.tt/2Pig6nC
Submitted November 02, 2023 at 11:47PM by _m-1-k-3_
via reddit https://ift.tt/uOBR1Hp
GitHub
Release EMBA v1.3.1 - Diff it · e-m-b-a/emba
What happened since the last EMBA release?
There was the absolute great #Hackersummercamp with our talks at BSidesLV, ICS Village (DEF CON) and Black Hat (Arsenal). The recording of the BSides talk...
There was the absolute great #Hackersummercamp with our talks at BSidesLV, ICS Village (DEF CON) and Black Hat (Arsenal). The recording of the BSides talk...