BSidesSATX CFP is open
https://ift.tt/leN9GVq
Submitted March 04, 2024 at 11:22AM by SciaticNerd
via reddit https://ift.tt/QbgLBSD
https://ift.tt/leN9GVq
Submitted March 04, 2024 at 11:22AM by SciaticNerd
via reddit https://ift.tt/QbgLBSD
BSIDES SATX 2024
General information about BSides SATX 2023
HTTP 403 bypass tool
https://ift.tt/8GC1EUR
Submitted March 04, 2024 at 01:21PM by SmokeyShark_777
via reddit https://ift.tt/MkOezoF
https://ift.tt/8GC1EUR
Submitted March 04, 2024 at 01:21PM by SmokeyShark_777
via reddit https://ift.tt/MkOezoF
GitHub
GitHub - trap-bytes/403jump: HTTP 403 bypass tool
HTTP 403 bypass tool. Contribute to trap-bytes/403jump development by creating an account on GitHub.
Persistence – Visual Studio Code Extensions
https://ift.tt/r3xpOb2
Submitted March 04, 2024 at 07:30PM by netbiosX
via reddit https://ift.tt/vBfXE01
https://ift.tt/r3xpOb2
Submitted March 04, 2024 at 07:30PM by netbiosX
via reddit https://ift.tt/vBfXE01
Penetration Testing Lab
Persistence – Visual Studio Code Extensions
It is not uncommon developers or users responsible to write code (i.e. detection engineers using Sigma) to utilize Visual Studio Code as their code editor. The default capability of the product can…
Threat Brief: WordPress Exploit Leads to Godzilla Web Shell, Discovery & New CVE
https://ift.tt/0OrwcmY
Submitted March 04, 2024 at 07:15PM by TheDFIRReport
via reddit https://ift.tt/Vw1EWre
https://ift.tt/0OrwcmY
Submitted March 04, 2024 at 07:15PM by TheDFIRReport
via reddit https://ift.tt/Vw1EWre
The DFIR Report
Threat Brief: WordPress Plugin Exploit Leads to Godzilla Web Shell, Discovery & New CVE
Below is a recent Threat Brief that we shared with our customers. Each year, we produce over 20 detailed Threat Briefs, which follow a format similar to the below. Typically, these reports include …
On-Device Fraud on the rise: exposing a recent Copybara fraud campaign | Cleafy Labs
https://ift.tt/8PSjRAn
Submitted March 04, 2024 at 07:45PM by f3d_0x0
via reddit https://ift.tt/GLrPvtg
https://ift.tt/8PSjRAn
Submitted March 04, 2024 at 07:45PM by f3d_0x0
via reddit https://ift.tt/GLrPvtg
Cleafy
On-Device Fraud on the rise: exposing a recent Copybara fraud campaign | Cleafy Labs
Uncover the persistent threat of Account Takeover (ATO) and the emerging challenge of On-Device Fraud (ODF) in online banking. Learn how advanced Android banking trojans Copybara enable remote-controlled attacks and explore the tactics of threat actors, from…
Planes, Ferries and Automobiles – How I Hacked Free Travel Across Iceland
https://ift.tt/s1vgzmf
Submitted March 04, 2024 at 08:36PM by likezoidberg
via reddit https://ift.tt/4YD0cEh
https://ift.tt/s1vgzmf
Submitted March 04, 2024 at 08:36PM by likezoidberg
via reddit https://ift.tt/4YD0cEh
www.debug.is
Planes, Ferries and Automobiles - The Code Lab
Thoughts and experiments on software, security and better coding practises.
Have a look at the largest vulnerability database ever! Includes English translation of CNVD, CNNVD & BDU.
https://ift.tt/IL1qdXx
Submitted March 04, 2024 at 11:25PM by glatisantbeast
via reddit https://ift.tt/xBNiC8K
https://ift.tt/IL1qdXx
Submitted March 04, 2024 at 11:25PM by glatisantbeast
via reddit https://ift.tt/xBNiC8K
www.exploit.observer
The World's Largest Exploit & Vulnerability Database
Exploit Observer aggregates & interprets exploit/vulnerability data from all over the Internet. Consequently, it has evolved into The World's Largest Exploit & Vulnerability Intelligence Database and is freely accessible to all.
Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict
https://ift.tt/S479Jwr
Submitted March 04, 2024 at 10:54PM by Nervous--Astronomer
via reddit https://ift.tt/2TkdI8o
https://ift.tt/S479Jwr
Submitted March 04, 2024 at 10:54PM by Nervous--Astronomer
via reddit https://ift.tt/2TkdI8o
Smishing with EvilGophish
https://ift.tt/KrlenCA
Submitted March 05, 2024 at 03:40AM by meterpretersession1
via reddit https://ift.tt/ODrMYA6
https://ift.tt/KrlenCA
Submitted March 05, 2024 at 03:40AM by meterpretersession1
via reddit https://ift.tt/ODrMYA6
fin3ss3g0d's Blog -
Smishing with EvilGophish - fin3ss3g0d's Blog
Introduction to Smishing: Understanding SMS Phishing Tactics In the evolving landscape of cybersecurity threats, smishing—or SMS phishing—stands out as a formidable technique employed by adversaries to exploit human vulnerabilities. Smishing operates on a…
Reverse Engineering Protobuf Definitions From Compiled Binaries
https://ift.tt/8opc5P6
Submitted March 05, 2024 at 05:48AM by arkadiyt
via reddit https://ift.tt/dV7cigH
https://ift.tt/8opc5P6
Submitted March 05, 2024 at 05:48AM by arkadiyt
via reddit https://ift.tt/dV7cigH
Arkadiyt
Reverse Engineering Protobuf Definitions From Compiled Binaries
How to extract raw source protobuf definitions from compiled binaries, regardless of the target architecture
Relishing new Fickling features for securing ML systems
https://ift.tt/g4IAqV9
Submitted March 05, 2024 at 06:19AM by dummypatty
via reddit https://ift.tt/nVgKfBM
https://ift.tt/g4IAqV9
Submitted March 05, 2024 at 06:19AM by dummypatty
via reddit https://ift.tt/nVgKfBM
Trail of Bits Blog
Relishing new Fickling features for securing ML systems
By Suha S. Hussain We’ve added new features to Fickling to offer enhanced threat detection and analysis across a broad spectrum of machine learning (ML) workflows. Fickling is a decompiler, static …
Multiple vulnerabilities in RT-Thread RTOS
https://ift.tt/PZ7OYBf
Submitted March 05, 2024 at 04:08PM by 0xdea
via reddit https://ift.tt/F1MlI6k
https://ift.tt/PZ7OYBf
Submitted March 05, 2024 at 04:08PM by 0xdea
via reddit https://ift.tt/F1MlI6k
hn security
Multiple vulnerabilities in RT-Thread RTOS - hn security
“Security is in the mind of […]
Persistence – Explorer
https://ift.tt/8OScvW9
Submitted March 05, 2024 at 05:45PM by netbiosX
via reddit https://ift.tt/FL0HYvA
https://ift.tt/8OScvW9
Submitted March 05, 2024 at 05:45PM by netbiosX
via reddit https://ift.tt/FL0HYvA
Penetration Testing Lab
Persistence – Explorer
Windows File Explorer is the is the graphical file management utility for the Windows operating system and the default desktop environment. Windows explorer was introduced in Windows 95 and it is a…
Release alert - EMBA firmware security analyzer v1.4.0 - ICS testing Edt. is out now
https://ift.tt/phvqmJI
Submitted March 05, 2024 at 05:35PM by _m-1-k-3_
via reddit https://ift.tt/x01qMTt
https://ift.tt/phvqmJI
Submitted March 05, 2024 at 05:35PM by _m-1-k-3_
via reddit https://ift.tt/x01qMTt
GitHub
Release EMBA v1.4.0 - ICS testing Edt. · e-m-b-a/emba
As we do a lot of ICS/OT testing in our daily business, we thought this release should reflect our usual EMBA usage scenario. Welcome to another huge EMBA release with a lot new features: EMBA v1.4...
Executed vs Loaded: a new dimension for Application Security with eBPF
https://ift.tt/KO5D1dR
Submitted March 05, 2024 at 07:13PM by cov_id19
via reddit https://ift.tt/MkQiD2g
https://ift.tt/KO5D1dR
Submitted March 05, 2024 at 07:13PM by cov_id19
via reddit https://ift.tt/MkQiD2g
www.oligo.security
On Loaded vs. Executed Libraries During Runtime | Oligo Security
The Application Security domain has evolved significantly over the last decade. It’s no surprise then, that with this evolution, comes a jungle of tools that not only causes a lot of confusion, but also a lot of noise, and overlapping messages.
Spoofed DNS queries and IP TTL triangulation
https://ift.tt/pY8k6yZ
Submitted March 05, 2024 at 08:23PM by jtkchicago
via reddit https://ift.tt/XHwak4D
https://ift.tt/pY8k6yZ
Submitted March 05, 2024 at 08:23PM by jtkchicago
via reddit https://ift.tt/XHwak4D
Dataplane.org Newsletter
Destination-Adjacent Source Address Spoofing
With a Side of IP TTL-based Origin Triangulation
Smishing with EvilGophish
https://ift.tt/KrlenCA
Submitted March 05, 2024 at 09:02PM by fin3ss3g0d
via reddit https://ift.tt/C5RWXma
https://ift.tt/KrlenCA
Submitted March 05, 2024 at 09:02PM by fin3ss3g0d
via reddit https://ift.tt/C5RWXma
fin3ss3g0d's Blog -
Smishing with EvilGophish - fin3ss3g0d's Blog
Introduction to Smishing: Understanding SMS Phishing Tactics In the evolving landscape of cybersecurity threats, smishing—or SMS phishing—stands out as a formidable technique employed by adversaries to exploit human vulnerabilities. Smishing operates on a…
List of 39 Documented Windows Persistence Techniques
https://ift.tt/E8TAe4P
Submitted March 05, 2024 at 10:27PM by netbiosX
via reddit https://ift.tt/cb1Gxiw
https://ift.tt/E8TAe4P
Submitted March 05, 2024 at 10:27PM by netbiosX
via reddit https://ift.tt/cb1Gxiw
Penetration Testing Lab
Persistence
The following table contains all the techniques covered and whether or not administrator rights are needed to establish persistence. NoTechniqueMITRE IDAdministrator Rights1Registry Run KeysNo2Serv…
Bypassing CSP with Form Hijacking
https://ift.tt/LwWTpOi
Submitted March 06, 2024 at 12:37PM by qwerty0x41
via reddit https://ift.tt/Tamx1iZ
https://ift.tt/LwWTpOi
Submitted March 06, 2024 at 12:37PM by qwerty0x41
via reddit https://ift.tt/Tamx1iZ
PortSwigger Research
Using form hijacking to bypass CSP
In this post we'll show you how to bypass CSP by using an often overlooked technique that can enable password theft in a seemingly secure configuration. What is form hijacking? Form hijacking isn't re
Kali NetHunter now supports Bad Bluetooth HID attacks to inject keystrokes wirelessly
https://ift.tt/rMis5gV
Submitted March 06, 2024 at 03:31PM by barakadua131
via reddit https://ift.tt/KcUDf4X
https://ift.tt/rMis5gV
Submitted March 06, 2024 at 03:31PM by barakadua131
via reddit https://ift.tt/KcUDf4X
Mobile Hacker
Kali NetHunter now supports Bad Bluetooth HID attacks to inject keystrokes wirelessly
This technique allows to impersonate any Bluetooth device and inject keystrokes that allows an attacker to open unwanted website, install malware or lockout user from the smartphone. Further I will explain how Bad Bluetooth attacks work, how they can be carry…
Code injection on Android without ptrace
https://ift.tt/ikRou5W
Submitted March 06, 2024 at 11:34PM by ihavelotsofspac
via reddit https://ift.tt/VcDsCKP
https://ift.tt/ikRou5W
Submitted March 06, 2024 at 11:34PM by ihavelotsofspac
via reddit https://ift.tt/VcDsCKP
erfur's bits and pieces
Code injection on Android without ptrace