Multiple Vulnerabilities In Extreme Networks ExtremeXOS
https://ift.tt/HsaPVjK
Submitted December 05, 2023 at 11:23PM by hackers_and_builders
via reddit https://ift.tt/nRZv5xi
https://ift.tt/HsaPVjK
Submitted December 05, 2023 at 11:23PM by hackers_and_builders
via reddit https://ift.tt/nRZv5xi
Rhino Security Labs
Multiple Vulnerabilities In Extreme Networks ExtremeXOS
Multiple vulnerabilities found in ExtremeNetworks ExtremeXOS by Rhino Security Labs.
Android Reverse Engineering - apk.sh v1.0.8 is out!
https://ift.tt/UWpkciK
Submitted December 06, 2023 at 06:13AM by recovo_recovo
via reddit https://ift.tt/CDAYUso
https://ift.tt/UWpkciK
Submitted December 06, 2023 at 06:13AM by recovo_recovo
via reddit https://ift.tt/CDAYUso
GitHub
Releases · ax/apk.sh
Makes reverse engineering Android apps easier, automating repetitive tasks like pulling, decoding, rebuilding and patching an APK. - ax/apk.sh
Pre-Auth Kiosk Escape Privilege Escalation in One Identity Password Manager Secure Password Extension
https://ift.tt/sGeBMl2
Submitted December 06, 2023 at 12:08PM by 0x9000
via reddit https://ift.tt/UEIeN7v
https://ift.tt/sGeBMl2
Submitted December 06, 2023 at 12:08PM by 0x9000
via reddit https://ift.tt/UEIeN7v
SEC Consult
Kiosk Escape Privilege Escalation in One Identity Password Manager Secure Password Extension
The Password Manager Extension from One Identity can be used to perform two different kiosk escapes on the lock screen of a Windows client. These two escapes allow an attacker to execute commands with the highest permissions of a user with the SYSTEM role.
RFC 1510: The Kerberos Network Authentication Service (V5)
https://ift.tt/AkOGfvQ
Submitted December 06, 2023 at 03:04PM by ducm
via reddit https://ift.tt/RMaO0pG
https://ift.tt/AkOGfvQ
Submitted December 06, 2023 at 03:04PM by ducm
via reddit https://ift.tt/RMaO0pG
IETF Datatracker
RFC 1510: The Kerberos Network Authentication Service (V5)
This document gives an overview and specification of Version 5 of the protocol for the Kerberos network authentication system. [STANDARDS-TRACK]
Blind CSS Exfiltration: exfiltrate unknown web pages
https://ift.tt/YI7yFZB
Submitted December 06, 2023 at 03:48PM by albinowax
via reddit https://ift.tt/1efF2p5
https://ift.tt/YI7yFZB
Submitted December 06, 2023 at 03:48PM by albinowax
via reddit https://ift.tt/1efF2p5
PortSwigger Research
Blind CSS Exfiltration: exfiltrate unknown web pages
This is a gif of the exfiltration process (We've increased the speed so you're not waiting around for 1 minute). Read on to discover how this works... CSS Cafe presentation I presented this technique
+1500 HuggingFace API Tokens were exposed, leaving millions of Meta-Llama, Bloom, and Pythia users vulnerable to supply chain attacks
https://ift.tt/g2LTbWp
Submitted December 06, 2023 at 05:38PM by Lany_B
via reddit https://ift.tt/SXyvZml
https://ift.tt/g2LTbWp
Submitted December 06, 2023 at 05:38PM by Lany_B
via reddit https://ift.tt/SXyvZml
Vulnerability disclosure for Zyxel's personal cloud storage device (NAS326) - Part1
https://ift.tt/DVWasYM
Submitted December 06, 2023 at 07:22PM by BugProve
via reddit https://ift.tt/sOujdC5
https://ift.tt/DVWasYM
Submitted December 06, 2023 at 07:22PM by BugProve
via reddit https://ift.tt/sOujdC5
Bugprove
CVE-2023-4473 & CVE-2023-4474 - Authentication bypass and multiple blind OS command injection vulnerabilities in Zyxel’s NAS326…
BugProve discovers additional zero-day vulnerabilities in Zyxel's personal cloud storage device. Detailed writeup of the firmware analysis process.
Split-Second DNS Rebinding in Chrome, Edge and Safari
https://ift.tt/iWUDO75
Submitted December 06, 2023 at 06:59PM by dcthatch
via reddit https://ift.tt/2EW4jX5
https://ift.tt/iWUDO75
Submitted December 06, 2023 at 06:59PM by dcthatch
via reddit https://ift.tt/2EW4jX5
www.intruder.io
Tricks for Reliable Split-Second DNS Rebinding in Chrome and Safari
This is the second post in a two-part series on DNS rebinding. In this post, I introduce new techniques for achieving reliable, split-second DNS rebinding in Chrome, Edge, and Safari when IPv6 is available, as well as a technique for bypassing the local network…
Unicode XSS via Combining Characters
https://ift.tt/Stf6rZl
Submitted December 05, 2023 at 07:42PM by ablativeyoyo
via reddit https://ift.tt/jrbFD6x
https://ift.tt/Stf6rZl
Submitted December 05, 2023 at 07:42PM by ablativeyoyo
via reddit https://ift.tt/jrbFD6x
Gist
index.md
GitHub Gist: instantly share code, notes, and snippets.
New RCE popchain in Laravel
https://ift.tt/I4yZm2a
Submitted December 06, 2023 at 09:23PM by monoimpact
via reddit https://ift.tt/hVt4yNF
https://ift.tt/I4yZm2a
Submitted December 06, 2023 at 09:23PM by monoimpact
via reddit https://ift.tt/hVt4yNF
Fenrisk
Gadgets chain in Laravel
Security experts
Red team or adversary? Hunting Supply Chain Threat Actors Targeting A Major Financial Institution.
https://ift.tt/0WiHBPk
Submitted December 07, 2023 at 03:29AM by louis11
via reddit https://ift.tt/hJZ7H0z
https://ift.tt/0WiHBPk
Submitted December 07, 2023 at 03:29AM by louis11
via reddit https://ift.tt/hJZ7H0z
Phylum
Encrypted npm Packages Found Targeting Major Financial Institution
Determining the intent behind a package publication is notoriously difficult. Is it a legitimate threat actor or a security researcher? We can rarely make this determination, so Phylum generally errs on the side of caution and annotates packages that exhibit…
Cybresec & Opensource firmware online party! - today at 5 PM UTC
https://ift.tt/Er6lWTz
Submitted December 07, 2023 at 02:12PM by Mike-Banon1
via reddit https://ift.tt/DiMuRav
https://ift.tt/Er6lWTz
Submitted December 07, 2023 at 02:12PM by Mike-Banon1
via reddit https://ift.tt/DiMuRav
Attendize.com
Dasharo User Group #4
Dasharo User Group (DUG) #4 and Dasharo Developers vPub 0x9 When? 07th December 2023 5PM UTC to last hacker standing...
What is Loader Lock?
https://ift.tt/uHYk46n
Submitted December 07, 2023 at 12:48AM by elliotkillick
via reddit https://ift.tt/YC8FbWO
https://ift.tt/uHYk46n
Submitted December 07, 2023 at 12:48AM by elliotkillick
via reddit https://ift.tt/YC8FbWO
Elliot on Security
Elliot on Security - What is Loader Lock?
A modern investigation of the Windows loader architecure and loader lock
Cueing up a calculator: an introduction to exploit development on Linux
https://ift.tt/vLqlTpt
Submitted December 07, 2023 at 02:03PM by poltess0
via reddit https://ift.tt/UyxmGTP
https://ift.tt/vLqlTpt
Submitted December 07, 2023 at 02:03PM by poltess0
via reddit https://ift.tt/UyxmGTP
The GitHub Blog
Cueing up a calculator: an introduction to exploit development on Linux
Using CVE-2023-43641 as an example, I’ll explain how to develop an exploit for a memory corruption vulnerability on Linux. The exploit has to bypass several mitigations to achieve code execution.
Web API testing techniques & labs
https://ift.tt/qsIM1eL
Submitted December 07, 2023 at 07:23PM by albinowax
via reddit https://ift.tt/4eLlJtH
https://ift.tt/qsIM1eL
Submitted December 07, 2023 at 07:23PM by albinowax
via reddit https://ift.tt/4eLlJtH
portswigger.net
API testing | Web Security Academy
APIs (Application Programming Interfaces) enable software systems and applications to communicate and share data. API testing is important as ...
Introducing Fuzzomatic: Using AI to Automatically Fuzz Rust Projects from Scratch
https://ift.tt/iulgUTy
Submitted December 07, 2023 at 09:02PM by tmlxs
via reddit https://ift.tt/9UzbLWA
https://ift.tt/iulgUTy
Submitted December 07, 2023 at 09:02PM by tmlxs
via reddit https://ift.tt/9UzbLWA
Kudelski Security Research
Introducing Fuzzomatic: Using AI to Automatically Fuzz Rust Projects from Scratch
Introduction In August 2023, Google published research they did on AI-powered fuzzing. They showed they could automatically improve fuzzing code coverage of C/C++ projects already enrolled in OSS-F…
Qilin Ransomware malware analysis
https://ift.tt/alSX6i9
Submitted December 07, 2023 at 08:52PM by ShadowStackRE
via reddit https://ift.tt/s5H82nN
https://ift.tt/alSX6i9
Submitted December 07, 2023 at 08:52PM by ShadowStackRE
via reddit https://ift.tt/s5H82nN
ShadowStackRE
Qilin Ransomware malware analysis — ShadowStackRE
CVE-2023-46818: PHP Code Injection Vulnerability in ISPConfig <= 3.2.11
https://ift.tt/PGEhI5S
Submitted December 07, 2023 at 10:26PM by eg1x
via reddit https://ift.tt/gU58MWf
https://ift.tt/PGEhI5S
Submitted December 07, 2023 at 10:26PM by eg1x
via reddit https://ift.tt/gU58MWf
Karmainsecurity
ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
CISA ICS Advisory: ControlbyWeb Relay
https://ift.tt/ahliWp5
Submitted December 08, 2023 at 01:10AM by deepwatch_sec
via reddit https://ift.tt/rixsoPX
https://ift.tt/ahliWp5
Submitted December 08, 2023 at 01:10AM by deepwatch_sec
via reddit https://ift.tt/rixsoPX
Spoofing DNS records by abusing Microsoft DHCP server
https://ift.tt/o0GdFeV
Submitted December 08, 2023 at 02:50AM by oridavid1231
via reddit https://ift.tt/6p5sHzJ
https://ift.tt/o0GdFeV
Submitted December 08, 2023 at 02:50AM by oridavid1231
via reddit https://ift.tt/6p5sHzJ
Akamai
Spoofing DNS Records by Abusing DHCP DNS Dynamic Updates | Akamai
Akamai researchers discovered a new set of attacks against Active Directory (AD) using Microsoft DHCP servers that can lead to full AD takeover.
BSidesSF 2024 CFP is now open!
https://ift.tt/Zx73toq
Submitted December 08, 2023 at 07:48AM by sarah-bsidessf
via reddit https://ift.tt/V5S8Dua
https://ift.tt/Zx73toq
Submitted December 08, 2023 at 07:48AM by sarah-bsidessf
via reddit https://ift.tt/V5S8Dua
BSidesSF
BSidesSF 2025 Call For Participation
BSidesSF is soliciting submissions for the annual BSidesSF conference on April 26-27, 2025. Call for Participation is currently open for all tracks.Note: We DO NOT provide speaker or travel ...