Weaponizing DHCP DNS Spoofing: Part 2 — A Hands-On Guide
https://ift.tt/yNnfHR5
Submitted December 21, 2023 at 09:00PM by oridavid1231
via reddit https://ift.tt/ytqsiHQ
https://ift.tt/yNnfHR5
Submitted December 21, 2023 at 09:00PM by oridavid1231
via reddit https://ift.tt/ytqsiHQ
Akamai
Weaponizing DHCP DNS Spoofing — A Hands-On Guide | Akamai
In part 2 of this two-part series, Akamai researchers detail methods and attack imitations within DHCP to spoof DNS — and introduce a new tool for your toolkit.
Ghidriff: Ghidra Binary Diffing Engine
https://ift.tt/wOEMTSV
Submitted December 21, 2023 at 11:56PM by onlinereadme
via reddit https://ift.tt/7BmSe5C
https://ift.tt/wOEMTSV
Submitted December 21, 2023 at 11:56PM by onlinereadme
via reddit https://ift.tt/7BmSe5C
clearbluejar
Ghidriff: Ghidra Binary Diffing Engine
As seen in most security blog posts today, binary diffing tools are essential for reverse engineering, vulnerability research, and malware analysis. Patch diffing is a technique widely used to identify changes across versions of binaries as related to security…
SSH ProxyCommand == RCE
https://ift.tt/X8bp5kJ
Submitted December 22, 2023 at 02:19AM by nex25519
via reddit https://ift.tt/S9ZhCFW
https://ift.tt/X8bp5kJ
Submitted December 22, 2023 at 02:19AM by nex25519
via reddit https://ift.tt/S9ZhCFW
Vin01’s Blog
SSH ProxyCommand == RCE
Summary
SSH ProxyCommand == unexpected code execution (CVE-2023-51385)
https://ift.tt/X8bp5kJ
Submitted December 22, 2023 at 05:44PM by nex25519
via reddit https://ift.tt/tfUQnIK
https://ift.tt/X8bp5kJ
Submitted December 22, 2023 at 05:44PM by nex25519
via reddit https://ift.tt/tfUQnIK
Vin01’s Blog
SSH ProxyCommand == RCE
Summary
Developers are juicy targets: DCOM & Visual Studio
https://ift.tt/yIrCeqi
Submitted December 24, 2023 at 03:11PM by gid0rah
via reddit https://ift.tt/COJK0Yx
https://ift.tt/yIrCeqi
Submitted December 24, 2023 at 03:11PM by gid0rah
via reddit https://ift.tt/COJK0Yx
Developers are juicy targets: DCOM & Visual Studio |
Developers are juicy targets: DCOM & Visual Studio | AdeptsOf0xCC
Umpteenth time that you will see a lateral movement based on DCOM. This time it's Visual Studio.
PNLS: Tool that captures and displays SSIDs from device's Preferred Network List in the nearby vicinity.
https://ift.tt/1qEsJL7
Submitted December 24, 2023 at 04:36PM by ssj_aleksa
via reddit https://ift.tt/6lo0kmd
https://ift.tt/1qEsJL7
Submitted December 24, 2023 at 04:36PM by ssj_aleksa
via reddit https://ift.tt/6lo0kmd
GitHub
GitHub - AleksaMCode/Preferred-Network-List-Sniffer: A reconnaissance tool for capturing and displaying SSIDs from device's Preferred…
A reconnaissance tool for capturing and displaying SSIDs from device's Preferred Network List. - AleksaMCode/Preferred-Network-List-Sniffer
GitHub - dwisiswant0/ngocok: ngrok Collaborator Link — yet another Burp Collaborator alternative for free with ngrok.
https://ift.tt/DzObC0w
Submitted December 25, 2023 at 03:24AM by dwisiswant0
via reddit https://ift.tt/0djgJB9
https://ift.tt/DzObC0w
Submitted December 25, 2023 at 03:24AM by dwisiswant0
via reddit https://ift.tt/0djgJB9
GitHub
GitHub - dwisiswant0/ngocok: ngrok Collaborator Link — yet another Burp Collaborator alternative for free with ngrok.
ngrok Collaborator Link — yet another Burp Collaborator alternative for free with ngrok. - dwisiswant0/ngocok
Check out OpenSSF's "Source Code Management Platform Configuration Best Practices" and Legitify - a cli tool that helps you comply
https://ift.tt/sqwlATG
Submitted December 25, 2023 at 04:32AM by roy_6472
via reddit https://ift.tt/AId5KjV
https://ift.tt/sqwlATG
Submitted December 25, 2023 at 04:32AM by roy_6472
via reddit https://ift.tt/AId5KjV
OpenSSF Best Practices Working Group
Source Code Management Platform Configuration Best Practices
The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
Active Directory and Internal Pentest Cheatsheets - Internal All The Things
https://ift.tt/f2p0hUO
Submitted December 27, 2023 at 02:27PM by K0llam_fury
via reddit https://ift.tt/P9Vobp5
https://ift.tt/f2p0hUO
Submitted December 27, 2023 at 02:27PM by K0llam_fury
via reddit https://ift.tt/P9Vobp5
swisskyrepo.github.io
Internal All The Things
Active Directory and Internal Pentest Cheatsheets
The Google 0-day all Infostealer groups are exploiting
https://ift.tt/r3IFNQX
Submitted December 27, 2023 at 03:40PM by Malwarebeasts
via reddit https://ift.tt/GXjfwUJ
https://ift.tt/r3IFNQX
Submitted December 27, 2023 at 03:40PM by Malwarebeasts
via reddit https://ift.tt/GXjfwUJ
InfoStealers
The Google 0-day all Infostealer groups are exploiting.
Today, even despite attempts to alert Google over a month ago that there is an ongoing 0-day being exploited by Infostealer groups.
SecButler: a comprehensive utility tool for pentester, bug-bounty hunters and security researchers
https://ift.tt/GyhWwAa
Submitted December 27, 2023 at 08:45PM by deleee
via reddit https://ift.tt/wOCU9pv
https://ift.tt/GyhWwAa
Submitted December 27, 2023 at 08:45PM by deleee
via reddit https://ift.tt/wOCU9pv
GitHub
GitHub - groundsec/secbutler: The perfect butler for pentesters, bug-bounty hunters and security researchers
The perfect butler for pentesters, bug-bounty hunters and security researchers - groundsec/secbutler
Operation Triangulation: The last (hardware) mystery
https://ift.tt/nSL8K2g
Submitted December 27, 2023 at 11:49PM by _vavkamil_
via reddit https://ift.tt/hTcAHg1
https://ift.tt/nSL8K2g
Submitted December 27, 2023 at 11:49PM by _vavkamil_
via reddit https://ift.tt/hTcAHg1
Securelist
Operation Triangulation: The last (hardware) mystery
Recent iPhone models have additional hardware-based security protection for sensitive regions of the kernel memory. We discovered that to bypass this hardware-based security protection, the attackers used another hardware feature of Apple-designed SoCs.
Parsing MSDN for (Documented) Technique Development
https://ift.tt/Oj3IirQ
Submitted December 28, 2023 at 02:46AM by KharosSig
via reddit https://ift.tt/It19eOQ
https://ift.tt/Oj3IirQ
Submitted December 28, 2023 at 02:46AM by KharosSig
via reddit https://ift.tt/It19eOQ
Signal Labs
Parsing MSDN for (Documented) Technique Development | Advanced Offensive Cybersecurity Training
Parsing MSDN to discover potentially abusable APIs
Domainim: A domain reconnaissance tool for organizational network scanning
https://ift.tt/EqfyGiW
Submitted December 28, 2023 at 03:42AM by pptx704
via reddit https://ift.tt/5QFo01X
https://ift.tt/EqfyGiW
Submitted December 28, 2023 at 03:42AM by pptx704
via reddit https://ift.tt/5QFo01X
GitHub
GitHub - pptx704/domainim: A fast and comprehensive tool for organizational network scanning
A fast and comprehensive tool for organizational network scanning - pptx704/domainim
A burn-after-download file service
https://meltr.io/
Submitted December 28, 2023 at 03:32AM by rythmiclizard
via reddit https://ift.tt/mF468bk
https://meltr.io/
Submitted December 28, 2023 at 03:32AM by rythmiclizard
via reddit https://ift.tt/mF468bk
Reddit
From the netsec community on Reddit: A burn-after-download file service
Posted by rythmiclizard - No votes and 6 comments
The Present Threat of Row Hammer Attacks
https://ift.tt/1CwKzv4
Submitted December 28, 2023 at 04:30PM by the_liberty
via reddit https://ift.tt/8CIGnpt
https://ift.tt/1CwKzv4
Submitted December 28, 2023 at 04:30PM by the_liberty
via reddit https://ift.tt/8CIGnpt
Medium
The Present Threat of Row Hammer Attacks
In 2014 Google researchers discovered strange interference between memory locations in DDR3, DDR4, and DDR5 Random Access Memory (RAM.) On…
New payloads to exploit Error-based SQL injection - PostgreSQL database
https://ift.tt/WXtac27
Submitted December 28, 2023 at 06:14PM by 1046ica
via reddit https://ift.tt/yMt1WQI
https://ift.tt/WXtac27
Submitted December 28, 2023 at 06:14PM by 1046ica
via reddit https://ift.tt/yMt1WQI
www.mannulinux.org
New payloads to exploit Error-based SQL injection - PostgreSQL database
Learn Basic Concepts of Linux. Best site to learn Linux from beginner to Advanced.
Breaking through the Infostealer Exploit and the Enigma of Cookie Restoration
https://ift.tt/oI6dQNH
Submitted December 29, 2023 at 08:30PM by Malwarebeasts
via reddit https://ift.tt/mo5xcQ1
https://ift.tt/oI6dQNH
Submitted December 29, 2023 at 08:30PM by Malwarebeasts
via reddit https://ift.tt/mo5xcQ1
InfoStealers
Breaking through the Infostealer Exploit and the Enigma of Cookie Restoration.
Lumma Infostealer’s cookie restoration method operates by leveraging a key from restore files, allowing the revival of expired Google cookies
Network Scanning Options
https://www.google.com
Submitted December 29, 2023 at 11:34PM by LevitatingGuru
via reddit https://ift.tt/K4rg8PB
https://www.google.com
Submitted December 29, 2023 at 11:34PM by LevitatingGuru
via reddit https://ift.tt/K4rg8PB
Reddit
[deleted by user] : r/netsec
514K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to…
Autorize – IDOR research tool - extension for Burp Suite
https://ift.tt/zJCfpik
Submitted December 30, 2023 at 06:14AM by quitten11
via reddit https://ift.tt/UEAlizg
https://ift.tt/zJCfpik
Submitted December 30, 2023 at 06:14AM by quitten11
via reddit https://ift.tt/UEAlizg
GitHub
GitHub - Quitten/Autorize: Automatic authorization enforcement detection extension for burp suite written in Jython developed by…
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa...
OSINT tool to search 1.4 Billion clear text credentials from Email
https://ift.tt/GyIqx54
Submitted December 31, 2023 at 07:59AM by UpstairsWord4042
via reddit https://ift.tt/EyA05pC
https://ift.tt/GyIqx54
Submitted December 31, 2023 at 07:59AM by UpstairsWord4042
via reddit https://ift.tt/EyA05pC
Leet
OSINT tool to search 1.4 Billion clear text credentials from Email
This tool allows you to perform OSINT and reconnaissance on an organisation or an individual. It allows one to search 1.4 Billion clear text credentials which was dumped as part of...