CVE-2023-43208: NextGen Mirth Connect Pre-Auth RCE Deep-Dive
https://ift.tt/SuAGIan
Submitted January 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/xarFA15
https://ift.tt/SuAGIan
Submitted January 12, 2024 at 08:08PM by scopedsecurity
via reddit https://ift.tt/xarFA15
Horizon3.ai
Writeup for CVE-2023-43208: NextGen Mirth Connect Pre-Auth RCE – Horizon3.ai
Mirth Connect, by NextGen HealthCare, versions prior to 4.4.1 are vulnerable to an unauthenticated RCE vulnerability, CVE-2023-43208.
CVE-2023-39143: PaperCut WebDAV RCE Deep-Dive
https://ift.tt/95hTGC1
Submitted January 12, 2024 at 08:07PM by scopedsecurity
via reddit https://ift.tt/tO4YZDA
https://ift.tt/95hTGC1
Submitted January 12, 2024 at 08:07PM by scopedsecurity
via reddit https://ift.tt/tO4YZDA
Horizon3.ai
Writeup for CVE-2023-39143: PaperCut WebDAV Vulnerability – Horizon3.ai
Introduction Back in Aug. 2023 we released an advisory for CVE-2023-39143, a critical vulnerability that affects Windows installs of the PaperCut NG/MF print management software. Attackers can exploit this vulnerability […]
A BadUSB that can exfiltrate stored WiFi passwords
https://ift.tt/wi2uMFa
Submitted January 12, 2024 at 08:40PM by 42-is-the-number
via reddit https://ift.tt/Z3tL0SN
https://ift.tt/wi2uMFa
Submitted January 12, 2024 at 08:40PM by 42-is-the-number
via reddit https://ift.tt/Z3tL0SN
GitHub
GitHub - AleksaMCode/WiFi-password-stealer: Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data…
Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password). - AleksaMCode/WiFi-password-stealer
VBA: having fun with macros, overwritten pointers & R/W/X memory
https://ift.tt/1c6dgGY
Submitted January 13, 2024 at 04:21PM by gid0rah
via reddit https://ift.tt/SC8JXyT
https://ift.tt/1c6dgGY
Submitted January 13, 2024 at 04:21PM by gid0rah
via reddit https://ift.tt/SC8JXyT
VBA: having fun with macros, overwritten pointers & R/W/X memory |
VBA: having fun with macros, overwritten pointers & R/W/X memory | AdeptsOf0xCC
Article describing an alternative method to trigger shellcode execution
Privilege escalation using the XAML diagnostics API (CVE-2023-36003)
https://ift.tt/h4QO0gs
Submitted January 13, 2024 at 03:41PM by m417z
via reddit https://ift.tt/DoR8F14
https://ift.tt/h4QO0gs
Submitted January 13, 2024 at 03:41PM by m417z
via reddit https://ift.tt/DoR8F14
M417Z
Privilege escalation using the XAML diagnostics API (CVE-2023-36003)
This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in December’s Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or…
Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887 (watchTowr Labs)
https://ift.tt/I4TBSO5
Submitted January 13, 2024 at 05:58PM by dx7r__
via reddit https://ift.tt/Tizlu7c
https://ift.tt/I4TBSO5
Submitted January 13, 2024 at 05:58PM by dx7r__
via reddit https://ift.tt/Tizlu7c
watchTowr Labs - Blog
Welcome To 2024, The SSLVPN Chaos Continues - Ivanti CVE-2023-46805 & CVE-2024-21887
Did you have a good break? Have you had a chance to breathe? Wake up.
It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry has been alerted to in-the-wild exploitation of 2 incredibly serious 0days (CVE-2023-46805 and…
It’s 2024, and the chaos continues - thanks to Volexity (Volexity’s writeup), the industry has been alerted to in-the-wild exploitation of 2 incredibly serious 0days (CVE-2023-46805 and…
Hedera and Algorand team up to create the DeRec Alliance, wow this is huge! This is a pretty big deal for security on the decentralized web. I generated this article while researching it, you may find it interesting. Note: Contains some affiliate links at the end for cryptography books.
https://ift.tt/aKWY8no
Submitted January 14, 2024 at 12:45AM by dima11235813
via reddit https://ift.tt/wve6G4n
https://ift.tt/aKWY8no
Submitted January 14, 2024 at 12:45AM by dima11235813
via reddit https://ift.tt/wve6G4n
Learn Internet Grow
🚀 Breaking News: Decentralized Key Management
Revolutionizing Digital Asset Security with the DeRec Alliance 🌐 🔐 #DeRecAlliance #DigitalAssetSecurity #Hedera & #Algorand
Scame
https://ift.tt/UM3uoXb
Submitted January 14, 2024 at 02:13AM by Technical_Shelter621
via reddit https://ift.tt/CaTsxk2
https://ift.tt/UM3uoXb
Submitted January 14, 2024 at 02:13AM by Technical_Shelter621
via reddit https://ift.tt/CaTsxk2
GitHub
GitHub - CyberRoute/scanme: A Golang package for scanning private and public IPs for open TCP ports 👁️
A Golang package for scanning private and public IPs for open TCP ports 👁️ - CyberRoute/scanme
v0.14.0 Release of Backhand - SquashFS library and binaries
https://ift.tt/tF4aYq6
Submitted January 14, 2024 at 03:33AM by arch_rust
via reddit https://ift.tt/6vVXkWq
https://ift.tt/tF4aYq6
Submitted January 14, 2024 at 03:33AM by arch_rust
via reddit https://ift.tt/6vVXkWq
GitHub
Release v0.14.0 · wcampbell0x2a/backhand
Major changes were made to the organization of this repo, with the library backhand now being separated from
the backhand-cli package, which is used to install unsquashfs, replace, and add.
backhan...
the backhand-cli package, which is used to install unsquashfs, replace, and add.
backhan...
CCDC 2024
https://ift.tt/2KdlRrk
Submitted January 14, 2024 at 03:59AM by TopShelfHockeyMN
via reddit https://ift.tt/rCBcQxh
https://ift.tt/2KdlRrk
Submitted January 14, 2024 at 03:59AM by TopShelfHockeyMN
via reddit https://ift.tt/rCBcQxh
Exploit Security CTF
https://ift.tt/O6uHLCx
Submitted January 14, 2024 at 05:48PM by 9lyph
via reddit https://ift.tt/6FLJf7V
https://ift.tt/O6uHLCx
Submitted January 14, 2024 at 05:48PM by 9lyph
via reddit https://ift.tt/6FLJf7V
Supply Chain Attack on GHA Runner Images
https://ift.tt/EgtmJCy
Submitted January 12, 2024 at 09:53PM by cyberforce218
via reddit https://ift.tt/MlhZHfG
https://ift.tt/EgtmJCy
Submitted January 12, 2024 at 09:53PM by cyberforce218
via reddit https://ift.tt/MlhZHfG
Adnan Khan's Blog
One Supply Chain Attack to Rule Them All – Poisoning GitHub’s Runner Images
I successfully exploited a critical misconfiguration vulnerability in GitHub’s actions/runner images repository. I gained control over build agents used by the repository, accessed secrets, a…
Just started new opensource tool for optimisation the process of analyzing web logs. Suggest for me some features you would like to see? Repo name : OSTE WEB LOG ANALYZER (OSTE WLA)
https://ift.tt/n4mi8Iv
Submitted January 14, 2024 at 11:30PM by OSTEsayed
via reddit https://ift.tt/hLxq2sW
https://ift.tt/n4mi8Iv
Submitted January 14, 2024 at 11:30PM by OSTEsayed
via reddit https://ift.tt/hLxq2sW
GitHub
GitHub - OSTEsayed/OSTE-Web-Log-Analyzer: OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer.
OSTE WLA automate the process of analyzing web server logs with the Python Web Log Analyzer. - OSTEsayed/OSTE-Web-Log-Analyzer
Access Controls: ABAC vs RBAC
https://ift.tt/vY0hU1d
Submitted January 15, 2024 at 11:31AM by zolakrystie
via reddit https://ift.tt/MbX3xup
https://ift.tt/vY0hU1d
Submitted January 15, 2024 at 11:31AM by zolakrystie
via reddit https://ift.tt/MbX3xup
NextLabs
ABAC
Attribute-Based Access Control (ABAC)
The Definitive Guide to Attribute-Based Access Control (ABAC)
Attribute-based access control (ABAC) has emerged as the next-gen technology for secure access to business-critical data. The complexities of today’s
The Definitive Guide to Attribute-Based Access Control (ABAC)
Attribute-based access control (ABAC) has emerged as the next-gen technology for secure access to business-critical data. The complexities of today’s
Lateral Movement - Visual Studio DTE
https://ift.tt/JdfZ5Nr
Submitted January 15, 2024 at 05:01PM by netbiosX
via reddit https://ift.tt/vUgm02R
https://ift.tt/JdfZ5Nr
Submitted January 15, 2024 at 05:01PM by netbiosX
via reddit https://ift.tt/vUgm02R
Penetration Testing Lab
Lateral Movement – Visual Studio DTE
A lot of organizations have some sort of application development program and it is highly likely that developers will utilize Visual Studio for their development needs. Outside of the risk of from …
Introducing Super Sharp Shares
https://ift.tt/DRqgTvZ
Submitted January 16, 2024 at 06:33PM by ZephrX112
via reddit https://ift.tt/Hut9o0Q
https://ift.tt/DRqgTvZ
Submitted January 16, 2024 at 06:33PM by ZephrX112
via reddit https://ift.tt/Hut9o0Q
Lares Labs
Introducing Super Sharp Shares
SuperSharpShares is a tool designed to automate enumerating domain shares, allowing for quick verification of accessible shares by your associated domain account.
Web LLM attacks - techniques & labs
https://ift.tt/VpyZnWx
Submitted January 16, 2024 at 09:06PM by albinowax
via reddit https://ift.tt/u4tMQPc
https://ift.tt/VpyZnWx
Submitted January 16, 2024 at 09:06PM by albinowax
via reddit https://ift.tt/u4tMQPc
portswigger.net
Web LLM attacks | Web Security Academy
Organizations are rushing to integrate Large Language Models (LLMs) in order to improve their online customer experience. This exposes them to web LLM ...
PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack
https://ift.tt/UfVheak
Submitted January 16, 2024 at 10:05PM by guedou
via reddit https://ift.tt/ZdeT0kH
https://ift.tt/UfVheak
Submitted January 16, 2024 at 10:05PM by guedou
via reddit https://ift.tt/ZdeT0kH
Quarkslab
PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack.
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
https://ift.tt/5hyfJ4w
Submitted January 17, 2024 at 10:28PM by EatonZ
via reddit https://ift.tt/N2HEThK
https://ift.tt/5hyfJ4w
Submitted January 17, 2024 at 10:28PM by EatonZ
via reddit https://ift.tt/N2HEThK
Eaton-Works
Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website
A vulnerable API on Toyota Tsusho Insurance Broker India’s premium calculator website exposed Microsoft corporate cloud credentials.
libX11: Uncovering and exploiting a 35-year-old vulnerability – Part 1 of 2
https://ift.tt/hHIPWk8
Submitted January 18, 2024 at 02:56AM by SRMish3
via reddit https://ift.tt/7C0hPLB
https://ift.tt/hHIPWk8
Submitted January 18, 2024 at 02:56AM by SRMish3
via reddit https://ift.tt/7C0hPLB
JFrog
CVE-2023-43786 & CVE-2023-43787 Vulns in libX11: All You Need To Know
Learn all about the 35-year-old vulnerabilities found by our Security Team in libX11, causing a denial-of-service and remote code execution.
The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited - watchTowr Labs
https://ift.tt/k2lipPY
Submitted January 18, 2024 at 02:40PM by dx7r__
via reddit https://ift.tt/9zMjB80
https://ift.tt/k2lipPY
Submitted January 18, 2024 at 02:40PM by dx7r__
via reddit https://ift.tt/9zMjB80
watchTowr Labs - Blog
The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited
Who likes vulnerabilities in appliances from security vendors? Everyone loves appliance vulnerabilities! If, by 'everyone', you mean various ransomware and APT groups of course (and us).
Regular watchTowr-watchers (meta-towr-watchers?) will remember our…
Regular watchTowr-watchers (meta-towr-watchers?) will remember our…