De4py: A toolkit for python reverse engineering
https://ift.tt/zmK1gkp
Submitted February 01, 2024 at 09:47PM by AhmedMinegames
via reddit https://ift.tt/6POJ4bc
https://ift.tt/zmK1gkp
Submitted February 01, 2024 at 09:47PM by AhmedMinegames
via reddit https://ift.tt/6POJ4bc
GitHub
GitHub - Fadi002/de4py: toolkit for python reverse engineering
toolkit for python reverse engineering. Contribute to Fadi002/de4py development by creating an account on GitHub.
Opera zero Day vulnerability for cross platform execution "MyFlaw"
https://ift.tt/sjKJHyZ
Submitted February 01, 2024 at 11:48PM by Altrntiv-to-security
via reddit https://ift.tt/R9q8f5B
https://ift.tt/sjKJHyZ
Submitted February 01, 2024 at 11:48PM by Altrntiv-to-security
via reddit https://ift.tt/R9q8f5B
DARKRELAY
Opera Browser Zero-Day RCE Vulnerability on Cross-Platforms
In a recent investigation a zero-day vulnerability surfaced within the popular Opera web browser family. This flaw, allows attackers RCE on Windows or MacOS systems through specially crafted third-party browser extension.
Your Security Program Is Shit
https://ift.tt/Nw4I9D1
Submitted February 02, 2024 at 12:59AM by burpadurp
via reddit https://ift.tt/5DQwH9u
https://ift.tt/Nw4I9D1
Submitted February 02, 2024 at 12:59AM by burpadurp
via reddit https://ift.tt/5DQwH9u
Crankysec
Your Security Program Is Shit
Very shit
ModSecurity: Path Confusion and easy bypass on v2 and v3
https://ift.tt/vhABEXC
Submitted February 02, 2024 at 04:24PM by theMiddleBlue
via reddit https://ift.tt/04gfjl6
https://ift.tt/vhABEXC
Submitted February 02, 2024 at 04:24PM by theMiddleBlue
via reddit https://ift.tt/04gfjl6
Sicuranext Blog
ModSecurity: Path Confusion and really easy bypass on v2 and v3
TL;DR both ModSecurity v2 and v3 share a similar bug that can result in a really simple WAF bypass. The bug in the v3 branch has been fixed in version 3.0.12 and has been assigned the CVE number CVE-2024-1019. However, the bug in the v2 line remains
There Are Too Many Damn Honeypots
https://ift.tt/xB7YdeJ
Submitted February 03, 2024 at 02:53AM by chicksdigthelongrun
via reddit https://ift.tt/CaDBryo
https://ift.tt/xB7YdeJ
Submitted February 03, 2024 at 02:53AM by chicksdigthelongrun
via reddit https://ift.tt/CaDBryo
VulnCheck
There Are Too Many Damn Honeypots - Blog - VulnCheck
VulnCheck faces a horde of honeypots while assessing the potential impact of Atlassian Confluence's CVE-2023-22527. This blog delves into Shodan queries to filter out honeypots and uncover the actual on-premise Confluence install base.
Deluder: Python utility for intercepting traffic of applications. Deluder can be used as an alternative for EchoMirage. It supports OpenSSL, GnuTLS, SChannel, WinSock and Linux Sockets out of the box. There is also support for remote hosts and optional GUI support through PETEP integration.
https://ift.tt/9E0YprH
Submitted February 03, 2024 at 09:15PM by vutmajk
via reddit https://ift.tt/ij35gUN
https://ift.tt/9E0YprH
Submitted February 03, 2024 at 09:15PM by vutmajk
via reddit https://ift.tt/ij35gUN
GitHub
GitHub - Warxim/deluder: Deluder is a tool for intercepting traffic of proxy unaware applications. Currently, Deluder supports…
Deluder is a tool for intercepting traffic of proxy unaware applications. Currently, Deluder supports OpenSSL, GnuTLS, SChannel, WinSock and Linux Sockets out of the box. ⚡ - GitHub - Warxim/delu...
scanme vs nmap
http://GitHub.com
Submitted February 04, 2024 at 01:00AM by Technical_Shelter621
via reddit https://ift.tt/epxSI8A
http://GitHub.com
Submitted February 04, 2024 at 01:00AM by Technical_Shelter621
via reddit https://ift.tt/epxSI8A
GitHub
GitHub · Change is constant. GitHub keeps you ahead.
Join the world's most widely adopted, AI-powered developer platform where millions of developers, businesses, and the largest open source community build software that advances humanity.
How I Hacked My Air Purifier to Remove Cloud Dependency [Detailed Write-Up]
https://ift.tt/lUZi41y
Submitted February 05, 2024 at 05:22AM by jmswrnr
via reddit https://ift.tt/DIjuw5Y
https://ift.tt/lUZi41y
Submitted February 05, 2024 at 05:22AM by jmswrnr
via reddit https://ift.tt/DIjuw5Y
James Warner
Hacking a Smart Home Device
How I reverse engineered an ESP32-based smart home device to gain remote control access and integrate it with Home Assistant.
Persistence – Windows Setup Script
https://ift.tt/t0pfFK1
Submitted February 05, 2024 at 05:00PM by netbiosX
via reddit https://ift.tt/YkxH73F
https://ift.tt/t0pfFK1
Submitted February 05, 2024 at 05:00PM by netbiosX
via reddit https://ift.tt/YkxH73F
Penetration Testing Lab
Persistence – Windows Setup Script
When the Windows Operating system is installed via a clean installation or via an upgrade, the Windows Setup binary is executed. The Windows setup allows custom noscripts to be executed such as the S…
WordPress Security Providers Falsely Claimed Cloudflare's Plugin Contained Vulnerability
https://ift.tt/6a05Clo
Submitted February 05, 2024 at 11:55PM by PluginVulns
via reddit https://ift.tt/iKI3MHU
https://ift.tt/6a05Clo
Submitted February 05, 2024 at 11:55PM by PluginVulns
via reddit https://ift.tt/iKI3MHU
Plugin Vulnerabilities
WordPress Security Providers Falsely Claimed Cloudflare’s Plugin Contained Vulnerability
Rust Won't Save Us: An Analysis of 2023's Known Exploited Vulnerabilities – Horizon3.ai
https://ift.tt/7LsVzwj
Submitted February 06, 2024 at 04:48PM by scopedsecurity
via reddit https://ift.tt/Z96AIwG
https://ift.tt/7LsVzwj
Submitted February 06, 2024 at 04:48PM by scopedsecurity
via reddit https://ift.tt/Z96AIwG
Horizon3.ai
Rust Won’t Save Us: An Analysis of 2023’s Known Exploited Vulnerabilities
A technical and root cause analysis of CISA’s Known Exploited Vulnerabilities from 2023.
Trends in Phishing, Fraud, 'Dark AI Models', and how to better protect yourself.
https://ift.tt/TtqCwes
Submitted February 06, 2024 at 10:27PM by Seaerkin2
via reddit https://ift.tt/bY4cEdQ
https://ift.tt/TtqCwes
Submitted February 06, 2024 at 10:27PM by Seaerkin2
via reddit https://ift.tt/bY4cEdQ
Guardyourdomain
DomainGuard | Threat Visibility Platform
We guard your domain, so you have peace of mind. Threat Visibility Platform.
Using Scapy for Network Fuzzing on Vsftpd
https://ift.tt/CfYxQwL
Submitted February 07, 2024 at 12:08AM by Altrntiv-to-security
via reddit https://ift.tt/z03KDTI
https://ift.tt/CfYxQwL
Submitted February 07, 2024 at 12:08AM by Altrntiv-to-security
via reddit https://ift.tt/z03KDTI
DARKRELAY
Unleashing the Power of Scapy for Protocol Fuzzing
Scapy's comprehensive set of features enables the creation of customized network traffic, making it an ideal tool for fuzzing.
NTLM Relay Gat: Automating Mass Exploitation of ntlmrelayx Authenticated Sessions
https://ift.tt/pky1bVx
Submitted February 07, 2024 at 01:27AM by ad0nis
via reddit https://ift.tt/BwmGsxA
https://ift.tt/pky1bVx
Submitted February 07, 2024 at 01:27AM by ad0nis
via reddit https://ift.tt/BwmGsxA
GitHub
GitHub - ad0nis/ntlm_relay_gat
Contribute to ad0nis/ntlm_relay_gat development by creating an account on GitHub.
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK.
https://ift.tt/Ug6fn5C
Submitted February 07, 2024 at 03:08AM by recovo_recovo
via reddit https://ift.tt/fL2HoR6
https://ift.tt/Ug6fn5C
Submitted February 07, 2024 at 03:08AM by recovo_recovo
via reddit https://ift.tt/fL2HoR6
GitHub
GitHub - ax/apk.sh: apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding…
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK. - ax/apk.sh
How to create a Secure, Random Password with JavaScript
https://ift.tt/qwY4Jby
Submitted February 07, 2024 at 12:09PM by hannob
via reddit https://ift.tt/vPu1AoG
https://ift.tt/qwY4Jby
Submitted February 07, 2024 at 12:09PM by hannob
via reddit https://ift.tt/vPu1AoG
Enumerate AWS tags, account ids, and org ids of accessible AWS resources
https://ift.tt/jW8XoB3
Submitted February 07, 2024 at 08:32AM by dagrz-cloudsec
via reddit https://ift.tt/24V6eJt
https://ift.tt/jW8XoB3
Submitted February 07, 2024 at 08:32AM by dagrz-cloudsec
via reddit https://ift.tt/24V6eJt
Plerion
Conditional Love for AWS Metadata Enumeration
How would you feel if an attacker could read your AWS resource tags? Turns out they can! Find out how and test your environment with our tool.
Unpack RedLine stealer to extract config using pe-sieve -Part 2 - Securityinbits
https://ift.tt/0cnSsqI
Submitted February 07, 2024 at 06:52PM by securityinbits
via reddit https://ift.tt/53KG67S
https://ift.tt/0cnSsqI
Submitted February 07, 2024 at 06:52PM by securityinbits
via reddit https://ift.tt/53KG67S
Securityinbits
Unpack RedLine stealer to extract config using pe-sieve -Part 2 - Securityinbits
Unpack RedLine stealer to extract config using pe-sieve. pe-sieve dumps then unpacked files from memory. Then, extract the config from the dumped file.
ShmooCon 2024 Videos are up!
https://ift.tt/WgD4Vim
Submitted February 08, 2024 at 01:51AM by mubix
via reddit https://ift.tt/usa95Lr
https://ift.tt/WgD4Vim
Submitted February 08, 2024 at 01:51AM by mubix
via reddit https://ift.tt/usa95Lr
Internet Archive
Shmoocon 2024 : ShmooCon : Free Download, Borrow, and Streaming : Internet Archive
ShmooCon 2024by Shmoo Group, various presentersThe videos in this collection are from ShmooCon 2024, which occurred on 12 - 14 January 2024, at the Washington...
Shellcode evasion using Wasm/Wat and Rust
https://ift.tt/muNstbg
Submitted February 08, 2024 at 03:26PM by flamedpt
via reddit https://ift.tt/mWJAwYx
https://ift.tt/muNstbg
Submitted February 08, 2024 at 03:26PM by flamedpt
via reddit https://ift.tt/mWJAwYx
Balwurk
Shellcode evasion using WebAssembly and Rust - Balwurk
Everyone in InfoSec knows Metasploit and the importance this tool has had on many professionals and in the field itself, either be it for awareness purposes, education, CTFs or actual live penetration tests, odds are the reader has encountered and used Metasploit…
New TOTOLINK vulnerability allows remote unauthenticated attackers to become authenticated due to a stack overflow vulnerability in the web interface!
https://ift.tt/8I4sBAd
Submitted February 08, 2024 at 04:03PM by Status_Resolve2971
via reddit https://ift.tt/CYR3Z1r
https://ift.tt/8I4sBAd
Submitted February 08, 2024 at 04:03PM by Status_Resolve2971
via reddit https://ift.tt/CYR3Z1r
SSD Secure Disclosure
SSD Advisory - TOTOLINK LR1200GB Auth Bypass - SSD Secure Disclosure
Summary A vulnerability in TOTOLINK LR1200GB allows remote unauthenticated attackers to become authenticated due to a stack overflow vulnerability in the web interface. Additional post-auth vulnerabilities in the product allow for command injection and their…