From Error to Entry: Cracking the Code of Password-Spraying Tools
https://ift.tt/iGaSLgB
Submitted March 19, 2024 at 10:35PM by oddvarmoe
via reddit https://ift.tt/ovd86tj
https://ift.tt/iGaSLgB
Submitted March 19, 2024 at 10:35PM by oddvarmoe
via reddit https://ift.tt/ovd86tj
TrustedSec
From Error to Entry: Cracking the Code of Password-Spraying Tools
Discover how to effectively onboard MFA for Office 365 users with MSOLSpray, and unlock remote access with our expert guide.
CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster
https://ift.tt/oY0Agz9
Submitted March 19, 2024 at 10:13PM by hackers_and_builders
via reddit https://ift.tt/W03rbsD
https://ift.tt/oY0Agz9
Submitted March 19, 2024 at 10:13PM by hackers_and_builders
via reddit https://ift.tt/W03rbsD
Rhino Security Labs
CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster
CVE-2024-1212 is an unauthenticated command injection found in Progress Kemp LoadMaster load balancer's administrator web interface by Rhino Security Labs.
New Short Episode Podcast ft. Insane Stories from Real Penetration Tests
https://www.youtube.com/watch?v=85tMZ_8m7wc&list=PLRQLxipnETnkricBrUexOIM6IUqApdVCe&index=2
Submitted March 19, 2024 at 10:43PM by hpo1n7
via reddit https://ift.tt/ymhYZcl
https://www.youtube.com/watch?v=85tMZ_8m7wc&list=PLRQLxipnETnkricBrUexOIM6IUqApdVCe&index=2
Submitted March 19, 2024 at 10:43PM by hpo1n7
via reddit https://ift.tt/ymhYZcl
YouTube
Episode 1: "Then we got arrested" ft. Matt Barnett
Zac Davis hosts War Stories, a podcast featuring stories from real life penetration testers. Zac covers their background, favorite tools, and stories that define their career.
Sponsored by Cyber Coffee. Real hackers need real caffeine.
www.sevnx.com/shop
Sponsored by Cyber Coffee. Real hackers need real caffeine.
www.sevnx.com/shop
How to Emulate a Ransomware Attack
https://ift.tt/c5IZoE1
Submitted March 20, 2024 at 03:21AM by pracsec
via reddit https://ift.tt/gC4OcUR
https://ift.tt/c5IZoE1
Submitted March 20, 2024 at 03:21AM by pracsec
via reddit https://ift.tt/gC4OcUR
Practical Security Analytics LLC
How to Emulate a Ransomware Attack
Overview Ransomware is here to stay and cyber security professionals need to be trained to prevent, detect, respond, and recover from ransomeware attacks. So, how do we do that in an ethical and re…
Open Source - Terminal based AI Powered Ethical Hacking Assistant.
https://ift.tt/qGVhexY
Submitted March 20, 2024 at 03:56AM by Civil_Alternative410
via reddit https://ift.tt/8wHlTap
https://ift.tt/qGVhexY
Submitted March 20, 2024 at 03:56AM by Civil_Alternative410
via reddit https://ift.tt/8wHlTap
GitHub
GitHub - berylliumsec/neutron: AI Powered Terminal Based Ethical Hacking Assistant
AI Powered Terminal Based Ethical Hacking Assistant - berylliumsec/neutron
Honeypots vs Canary Infra : Bringing Honeypots towards general adoption
https://ift.tt/WrbUz5x
Submitted March 20, 2024 at 06:23PM by tracebit
via reddit https://ift.tt/xUNbAoV
https://ift.tt/WrbUz5x
Submitted March 20, 2024 at 06:23PM by tracebit
via reddit https://ift.tt/xUNbAoV
Tracebit
Canary Infra: Bringing Honeypots towards general adoption | Tracebit
Laying out why we think 'Canary Infra' is a game changer for honeypots and intrusion detection.
Abusing the DHCP Administrators Group to Escalate Privileges in Windows Domains
https://ift.tt/WHeMz28
Submitted March 20, 2024 at 07:59PM by oridavid1231
via reddit https://ift.tt/q0j9Kk6
https://ift.tt/WHeMz28
Submitted March 20, 2024 at 07:59PM by oridavid1231
via reddit https://ift.tt/q0j9Kk6
Akamai
Abusing the DHCP Administrators Group to Escalate Privileges in Windows Domains | Akamai
A new malicious privilege escalation technique can be disastrous. In this post, get context and defensive measures against this threat.
Threat actors leverage document publishing sites for ongoing credential and session token theft
https://ift.tt/FPm5YRi
Submitted March 20, 2024 at 10:06PM by 8bit_zach
via reddit https://ift.tt/mZlYbh3
https://ift.tt/FPm5YRi
Submitted March 20, 2024 at 10:06PM by 8bit_zach
via reddit https://ift.tt/mZlYbh3
Cisco Talos Blog
Threat actors leverage document publishing sites for ongoing credential and session token theft
Talos IR has responded to several recent incidents in which threat actors used legitimate digital document publishing sites such as Publuu and Marq to host phishing documents as part of ongoing credential and session harvesting attacks.
One Line Backdoors in Classic ASP, Flask, Node.js, and PHP (FOSS Tool)
https://ift.tt/E14Ou6D
Submitted March 21, 2024 at 03:18AM by SkrilHexNukehul
via reddit https://ift.tt/cF2zp6X
https://ift.tt/E14Ou6D
Submitted March 21, 2024 at 03:18AM by SkrilHexNukehul
via reddit https://ift.tt/cF2zp6X
GitHub
GitHub - Geeoon/asploit: One line command and control backdoors for APIs and web applications.
One line command and control backdoors for APIs and web applications. - Geeoon/asploit
GitHub - riza/indextree: Generates the tree of the directory listing page.
https://ift.tt/bcFtVRL
Submitted March 21, 2024 at 01:49PM by rjz4
via reddit https://ift.tt/lwcaJgu
https://ift.tt/bcFtVRL
Submitted March 21, 2024 at 01:49PM by rjz4
via reddit https://ift.tt/lwcaJgu
GitHub
GitHub - riza/indextree: Generates the tree of the directory listing page.
Generates the tree of the directory listing page. Contribute to riza/indextree development by creating an account on GitHub.
OpenBSD RCE to be released at t2.fi
https://ift.tt/wRG598L
Submitted March 21, 2024 at 06:24PM by nextgens
via reddit https://ift.tt/dGYDV8U
https://ift.tt/wRG598L
Submitted March 21, 2024 at 06:24PM by nextgens
via reddit https://ift.tt/dGYDV8U
CVE-2023-48788: Fortinet FortiClientEMS SQL Injection Deep Dive and IOCs
https://ift.tt/pR5K0ht
Submitted March 21, 2024 at 06:14PM by scopedsecurity
via reddit https://ift.tt/C53ytGQ
https://ift.tt/pR5K0ht
Submitted March 21, 2024 at 06:14PM by scopedsecurity
via reddit https://ift.tt/C53ytGQ
Horizon3.ai
CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Deep Dive
CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Deep-Dive and Indicators of Compromise. This blog details the SQL injection which allows an unauthenticated attacker to access the FortiClient EMS server as SYSTEM to execute arbitrary commands.
Unsaflok: Master Keys for dormakaba Saflok Hotel Locks
https://unsaflok.com/
Submitted March 21, 2024 at 10:37PM by netsec_burn
via reddit https://ift.tt/4nLKMr1
https://unsaflok.com/
Submitted March 21, 2024 at 10:37PM by netsec_burn
via reddit https://ift.tt/4nLKMr1
Reddit
From the netsec community on Reddit: Unsaflok: Master Keys for dormakaba Saflok Hotel Locks
Posted by netsec_burn - 15 votes and 0 comments
Fake-SMS: A Malware Hunting Story
https://ift.tt/fZgHGSc
Submitted March 22, 2024 at 02:30AM by ssj_aleksa
via reddit https://ift.tt/NgMHmJD
https://ift.tt/fZgHGSc
Submitted March 22, 2024 at 02:30AM by ssj_aleksa
via reddit https://ift.tt/NgMHmJD
Medium
Fake-SMS: How Deep Does the Rabbit Hole Really Go?
Tracking a Bad Actor Through the Maze of Obfuscated Malware Code
Side-Channel Attack on Apple M1 Chip Prefetcher (GoFetch)
https://gofetch.fail/
Submitted March 22, 2024 at 07:57AM by LordAlfredo
via reddit https://ift.tt/N32QGuO
https://gofetch.fail/
Submitted March 22, 2024 at 07:57AM by LordAlfredo
via reddit https://ift.tt/N32QGuO
gofetch.fail
GoFetch: Breaking Constant-Time Cryptographic Implementations Using Data Memory-Dependent Prefetchers
A new microarchitectural side-channel attack exploiting data memory-dependent prefetchers in Apple silicons.
We need product security community
https://ift.tt/QVZuGcF
Submitted March 22, 2024 at 12:23PM by samsbp97
via reddit https://ift.tt/ZXfvzB2
https://ift.tt/QVZuGcF
Submitted March 22, 2024 at 12:23PM by samsbp97
via reddit https://ift.tt/ZXfvzB2
Random Access Memory
We need Product Security Community
Gaps in information security communities for product security engineers
Bluetooth vulnerability allows unauthorized user to record and play audio on Bluetooth speaker without user awareness
https://ift.tt/exs5SH1
Submitted March 22, 2024 at 02:16PM by barakadua131
via reddit https://ift.tt/G4kSO1U
https://ift.tt/exs5SH1
Submitted March 22, 2024 at 02:16PM by barakadua131
via reddit https://ift.tt/G4kSO1U
Mobile Hacker
Bluetooth vulnerability allows unauthorized user to record and play audio on Bluetooth speakers
This critical security issue allows third party user to record audio from Bluetooth speaker with built-in microphone in vicinity, even when it is already paired and connected with another device. This can result in eavesdropping on private conversations using…
Tool to quickly extract all URLs and paths from web pages.
https://ift.tt/tyg1k6d
Submitted March 23, 2024 at 06:55PM by SmokeyShark_777
via reddit https://ift.tt/ZMqiN7k
https://ift.tt/tyg1k6d
Submitted March 23, 2024 at 06:55PM by SmokeyShark_777
via reddit https://ift.tt/ZMqiN7k
GitHub
GitHub - trap-bytes/gourlex: Gourlex is a simple tool that can be used to extract URLs and paths from web pages.
Gourlex is a simple tool that can be used to extract URLs and paths from web pages. - trap-bytes/gourlex
How to continue learning without any rewards.
http://tryhackme.com
Submitted March 23, 2024 at 08:31PM by ashuraj_143
via reddit https://ift.tt/KH4gesQ
http://tryhackme.com
Submitted March 23, 2024 at 08:31PM by ashuraj_143
via reddit https://ift.tt/KH4gesQ
TryHackMe
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
Basic noscript to generate reverse shell payloads, generally most used in ctf.
https://ift.tt/mfTZBx5
Submitted March 23, 2024 at 08:29PM by m0rg4
via reddit https://ift.tt/TdnNpHL
https://ift.tt/mfTZBx5
Submitted March 23, 2024 at 08:29PM by m0rg4
via reddit https://ift.tt/TdnNpHL
GitHub
GitHub - washingtonP1974/Rev-Shell: Basic noscript to generate reverse shell payloads, generally most used in ctf.
Basic noscript to generate reverse shell payloads, generally most used in ctf. - washingtonP1974/Rev-Shell
What are Honeypots, their Uses and how to set one up for networks
https://ift.tt/RcmhfCT
Submitted March 23, 2024 at 10:42PM by Altrntiv-to-security
via reddit https://ift.tt/yEZoke7
https://ift.tt/RcmhfCT
Submitted March 23, 2024 at 10:42PM by Altrntiv-to-security
via reddit https://ift.tt/yEZoke7
DarkRelay
What is a honeypot?
Honeypots is catfishing in the world of cybersecurity – no candlelit dinners, just firewalls and encrypted love letters to trap hackers!IntroductionIn the ever-evolving landscape of cybersecurity, staying one step ahead of malicious actors is not just a challenge…