NMAP-formatter: convert NMAP results to HTML, CSV, JSON, graphviz (dot), SQLite
https://ift.tt/53FSbdc
Submitted January 28, 2024 at 12:22AM by netsec_burn
via reddit https://ift.tt/tTSIKzW
https://ift.tt/53FSbdc
Submitted January 28, 2024 at 12:22AM by netsec_burn
via reddit https://ift.tt/tTSIKzW
GitHub
GitHub - vdjagilev/nmap-formatter: A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot)…
A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot) or sqlite. Simply put it's nmap converter. - GitHub - vdjagilev/nmap-formatter: A tool that allow...
ExecIT: Evasive DLL-Based Shellcode Loader
https://ift.tt/Glg63La
Submitted January 28, 2024 at 04:05PM by florilsk
via reddit https://ift.tt/q5BChJP
https://ift.tt/Glg63La
Submitted January 28, 2024 at 04:05PM by florilsk
via reddit https://ift.tt/q5BChJP
GitHub
GitHub - florylsk/ExecIT: Execute shellcode files with rundll32
Execute shellcode files with rundll32. Contribute to florylsk/ExecIT development by creating an account on GitHub.
TyphoonCon 2024 early bird ticket are now on sale!
https://ift.tt/dxBhPtT
Submitted January 28, 2024 at 09:50PM by Straight-Zombie-646
via reddit https://ift.tt/Vwcmti3
https://ift.tt/dxBhPtT
Submitted January 28, 2024 at 09:50PM by Straight-Zombie-646
via reddit https://ift.tt/Vwcmti3
Eventbrite
TyphoonCon 2024
TyphoonCon conference and training focus on highly technical offensive security topics.
The event is organized by SSD Secure Disclosure.
The event is organized by SSD Secure Disclosure.
“Scammers Paradise” —Exploring Telegram’s Dark Markets, Breeding Ground for Modern Phishing Operations
https://ift.tt/KT9tgIU
Submitted January 29, 2024 at 08:33PM by figgymmr
via reddit https://ift.tt/hBtPGKi
https://ift.tt/KT9tgIU
Submitted January 29, 2024 at 08:33PM by figgymmr
via reddit https://ift.tt/hBtPGKi
Medium
“Scammers Paradise” —Exploring Telegram’s Dark Markets, Breeding Ground for Modern Phishing Operations
By Oleg Zaytsev, Nati Tal (Guardio Labs)
Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
https://ift.tt/exZjTpY
Submitted January 29, 2024 at 07:58PM by TheDFIRReport
via reddit https://ift.tt/JpKmkaw
https://ift.tt/exZjTpY
Submitted January 29, 2024 at 07:58PM by TheDFIRReport
via reddit https://ift.tt/JpKmkaw
The DFIR Report
Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours
Key Takeaways In late December 2022, we observed threat actors exploiting a publicly exposed Remote Desktop Protocol (RDP) host, leading to data exfiltration and the deployment of Trigona ransomwar…
Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise
https://ift.tt/4QOJZSp
Submitted January 29, 2024 at 09:16PM by shulginlegacy
via reddit https://ift.tt/tkajWfC
https://ift.tt/4QOJZSp
Submitted January 29, 2024 at 09:16PM by shulginlegacy
via reddit https://ift.tt/tkajWfC
Orca Security
Sys:All: How A Simple Loophole in Google Kubernetes Engine Puts Clusters at Risk of Compromise
The Orca Research Pod has discovered a risk in Google Kubernetes Engine (GKE) that would allow an attacker with any Google account to take over a Kubernetes cluster. Learn about this risk dubbed Sys:All and the recommended actions to take.
Your Firewalls and Proxies are about to be blind to real TLS destinations: Learn about Encrypted Client Hello
https://ift.tt/Jmo7HGn
Submitted January 30, 2024 at 12:14AM by Shu_asha
via reddit https://ift.tt/EcGIPw4
https://ift.tt/Jmo7HGn
Submitted January 30, 2024 at 12:14AM by Shu_asha
via reddit https://ift.tt/EcGIPw4
Most leaked keys aren't revoked, learn about API key rotation
https://ift.tt/aJ4EUTB
Submitted January 30, 2024 at 12:08AM by Phorcez
via reddit https://ift.tt/PAtB5vw
https://ift.tt/aJ4EUTB
Submitted January 30, 2024 at 12:08AM by Phorcez
via reddit https://ift.tt/PAtB5vw
Trufflesecurity
How to Remediate Leaked Secrets ◆ Truffle Security Co.
This webinar will focus on strategies for remediating leaked keys, managing key rotation, and handling platform-specific processes for the leading SaaS providers.
Using client-side JavaScript to build a tool for Port-scanning and LAN Host Detection.
https://blog.vsim.xyz/article/east-west-client.html
Submitted January 30, 2024 at 12:44AM by Vsimpro
via reddit https://ift.tt/iMf71gI
https://blog.vsim.xyz/article/east-west-client.html
Submitted January 30, 2024 at 12:44AM by Vsimpro
via reddit https://ift.tt/iMf71gI
Reddit
From the netsec community on Reddit: Using client-side JavaScript to build a tool for Port-scanning and LAN Host Detection.
Posted by Vsimpro - 3 votes and 1 comment
LLM Assisted Jailbreak & Doxing
https://ift.tt/sWh92mC
Submitted January 30, 2024 at 01:49AM by katahdinsecurity
via reddit https://ift.tt/3AxtPhw
https://ift.tt/sWh92mC
Submitted January 30, 2024 at 01:49AM by katahdinsecurity
via reddit https://ift.tt/3AxtPhw
Import Device Tree Information onto your Ghidra memory map in order to simplify bootloader, kernel and driver reverse engineering
https://ift.tt/zocxbL2
Submitted January 30, 2024 at 01:35AM by AssociationTop7723
via reddit https://ift.tt/z4N8qPc
https://ift.tt/zocxbL2
Submitted January 30, 2024 at 01:35AM by AssociationTop7723
via reddit https://ift.tt/z4N8qPc
GitHub
GitHub - antoniovazquezblanco/GhidraDeviceTreeBlob: Import Device Tree Information onto your Ghidra memory map
Import Device Tree Information onto your Ghidra memory map - antoniovazquezblanco/GhidraDeviceTreeBlob
Exploring secureCodeBox — An Open-Source Continuous Security Testing Solution for DevSecOps
https://ift.tt/EkIYSde
Submitted January 30, 2024 at 02:36AM by theowni
via reddit https://ift.tt/U2rAqVX
https://ift.tt/EkIYSde
Submitted January 30, 2024 at 02:36AM by theowni
via reddit https://ift.tt/U2rAqVX
Medium
Exploring secureCodeBox — An Open-Source Continuous Security Testing Solution for DevSecOps
A Comprehensive Review of secureCodeBox — an Open-Source Platform for Continuous Security Utilizing Popular Testing Tools. Presenting…
bof-launcher: Beacon Object File (BOF) launcher - library for executing BOF files in C/C++/Zig applications
https://ift.tt/qTbykNp
Submitted January 30, 2024 at 02:02PM by mzet-
via reddit https://ift.tt/YrgDQ0S
https://ift.tt/qTbykNp
Submitted January 30, 2024 at 02:02PM by mzet-
via reddit https://ift.tt/YrgDQ0S
GitHub
GitHub - The-Z-Labs/bof-launcher: Beacon Object File (BOF) launcher - library for executing BOF files in C/C++/Zig applications
Beacon Object File (BOF) launcher - library for executing BOF files in C/C++/Zig applications - The-Z-Labs/bof-launcher
Is Your SAP Cloud Connector Safe? The Risk You Can't Ignore
https://ift.tt/7eZYsKP
Submitted January 30, 2024 at 02:00PM by vah_13
via reddit https://ift.tt/lYQOJGb
https://ift.tt/7eZYsKP
Submitted January 30, 2024 at 02:00PM by vah_13
via reddit https://ift.tt/lYQOJGb
RedRays - Your SAP Security Solution
Is Your SAP Cloud Connector Safe? The Risk You Can't Ignore
Learn how to enhance the security of your SAP Cloud Connector (SAP CC) deployment on Windows. Discover essential role management strategies, mitigate security risks, and gain insights into securing your SAP infrastructure. Explore best practices to protect…
Hunting for (Un)authenticated n-days in Asus Routers - Shielder
https://ift.tt/wLl6qrc
Submitted January 30, 2024 at 07:04PM by smaury
via reddit https://ift.tt/90RU128
https://ift.tt/wLl6qrc
Submitted January 30, 2024 at 07:04PM by smaury
via reddit https://ift.tt/90RU128
Shielder
Shielder - Hunting for ~~Un~~authenticated n-days in Asus Routers
Notes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240.
GitHub - mlcsec/SigFinder: Identify binaries with Authenticode digital signatures signed to an internal CA/domain
https://ift.tt/Dbj5AZg
Submitted January 30, 2024 at 06:45PM by Frequent_Passenger82
via reddit https://ift.tt/qU2novW
https://ift.tt/Dbj5AZg
Submitted January 30, 2024 at 06:45PM by Frequent_Passenger82
via reddit https://ift.tt/qU2novW
GitHub
GitHub - mlcsec/SigFinder: Identify binaries with Authenticode digital signatures signed to an internal CA/domain
Identify binaries with Authenticode digital signatures signed to an internal CA/domain - mlcsec/SigFinder
Post-auth blind Python code injection vulnerabilities detected in personal cloud storage device
https://ift.tt/4I2dCag
Submitted January 30, 2024 at 08:34PM by BugProve
via reddit https://ift.tt/XGtAVdp
https://ift.tt/4I2dCag
Submitted January 30, 2024 at 08:34PM by BugProve
via reddit https://ift.tt/XGtAVdp
Bugprove
CVE-2023-5372 - Post-auth blind Python code injection vulnerabilities in Zyxel’s NAS326 and NAS542 devices
Vulnerability disclosure about Zyxel's personal cloud storage device, under CVE-2023-5372
New Visual Studio Code plugin for IaC security (plus collaboration, semgrep integration)
https://ift.tt/1acMeoy
Submitted January 30, 2024 at 10:10PM by nibblesec
via reddit https://ift.tt/VonudFI
https://ift.tt/1acMeoy
Submitted January 30, 2024 at 10:10PM by nibblesec
via reddit https://ift.tt/VonudFI
[KIS-2024-01] XenForo <= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability
https://ift.tt/RSao0VC
Submitted January 30, 2024 at 11:47PM by eg1x
via reddit https://ift.tt/9qWgu71
https://ift.tt/RSao0VC
Submitted January 30, 2024 at 11:47PM by eg1x
via reddit https://ift.tt/9qWgu71
Karmainsecurity
XenForo <= 2.2.13 (ArchiveImport.php) Zip Slip Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Analysis Of Multiple Vulnerabilities In Ofbiz
https://ift.tt/KNQVrhj
Submitted January 30, 2024 at 10:30PM by appsec1337
via reddit https://ift.tt/kTF7XfI
https://ift.tt/KNQVrhj
Submitted January 30, 2024 at 10:30PM by appsec1337
via reddit https://ift.tt/kTF7XfI
Penetration Testing and CyberSecurity Solution - SecureLayer7
Analysis Of Multiple Vulnerabilities In Apache OFBiz
CVE-2023-51467 is an authentication bypass recently disclosed by SonicWall in Ofbiz—an Enterprise Resource Planning (ERP) system solution for automating applications and business management. ...
Intro to Websockets & Writing a WebSocket Server in Rust - any feedback welcome!
https://ift.tt/HCbLlOT
Submitted January 31, 2024 at 12:26AM by vaktibabat
via reddit https://ift.tt/nSHFN8r
https://ift.tt/HCbLlOT
Submitted January 31, 2024 at 12:26AM by vaktibabat
via reddit https://ift.tt/nSHFN8r
Vaktibabat
WebSockets - The Beginner’s Guide
Prelude In the start of the year, I started keeping myself a list of technologies I don’t understand and want to learn about. The first candidate I immediately thought about was WebSockets. I kept seeing them popping up in websites and CTFs, but they always…