Blocking EDR Telemetry via PitM Network Filtering
https://ift.tt/oJgf6kT
Submitted July 23, 2024 at 02:02PM by eitot8
via reddit https://ift.tt/TcXg1Yp
https://ift.tt/oJgf6kT
Submitted July 23, 2024 at 02:02PM by eitot8
via reddit https://ift.tt/TcXg1Yp
GitHub
GitHub - TierZeroSecurity/edr_blocker: Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is…
Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination IP addresses are parsed based on the server name in TLS Cli...
CVE-2019-8805: Apple EndpointSecurity framework Privilege Escalation
https://ift.tt/d26Bs73
Submitted July 23, 2024 at 08:02PM by appsec1337
via reddit https://ift.tt/u41FabS
https://ift.tt/d26Bs73
Submitted July 23, 2024 at 08:02PM by appsec1337
via reddit https://ift.tt/u41FabS
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
CVE-2019-8805: Apple EndpointSecurity framework Privilege Escalation
CVE-2019-8805 is a privilege escalation vulnerability found in macOS Catalina 10.15 by Scott Knight. This vulnerability occurs through the Endpoint Security framework introduced in Catalina 10.15....
NO_WILDCARD: How we discovered the AWS Organization ID for any AWS Account
https://ift.tt/arcMH2Z
Submitted July 23, 2024 at 10:03PM by tracebit
via reddit https://ift.tt/iGucarQ
https://ift.tt/arcMH2Z
Submitted July 23, 2024 at 10:03PM by tracebit
via reddit https://ift.tt/iGucarQ
Tracebit
NO_WILDCARD: How I discovered the Organization ID of any AWS Account
Our latest research into VPC Endpoint Policy causes AWS to introduce significant changes!
Announcing the Bug Bounty program pack 1.0
https://ift.tt/5EWu1AB
Submitted July 24, 2024 at 05:04AM by SecTemplates
via reddit https://ift.tt/FNPSYTf
https://ift.tt/5EWu1AB
Submitted July 24, 2024 at 05:04AM by SecTemplates
via reddit https://ift.tt/FNPSYTf
SecTemplates.com
Announcing the Bug Bounty program pack 1.0
Introduction I have participated in, and built bug bounty programs at companies such as PayPal and Box and supported similar programs at several other companies. Below is part of a whiteboard session from 2012, conducted before launching PayPal's bug bounty…
Let’s Encrypt Intent to End OCSP Service
https://ift.tt/pVdE1kb
Submitted July 24, 2024 at 01:02AM by c0r0n3r
via reddit https://ift.tt/aq2oS9x
https://ift.tt/pVdE1kb
Submitted July 24, 2024 at 01:02AM by c0r0n3r
via reddit https://ift.tt/aq2oS9x
letsencrypt.org
Intent to End OCSP Service
Today we are announcing our intent to end Online Certificate Status Protocol (OCSP) support in favor of Certificate Revocation Lists (CRLs) as soon as possible. OCSP and CRLs are both mechanisms by which CAs can communicate certificate revocation information…
Gouge: Burp Suite extension to extract URLs from a webpage & all its JS files too.
https://ift.tt/761BKfN
Submitted July 23, 2024 at 12:01PM by Electronic_Village_8
via reddit https://ift.tt/1DKj7OU
https://ift.tt/761BKfN
Submitted July 23, 2024 at 12:01PM by Electronic_Village_8
via reddit https://ift.tt/1DKj7OU
GitHub
GitHub - mqst/gouge: Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different…
Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp Suite - mqst/gouge
Studying 0days: How we hacked Anki, the world's most popular flashcard app
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
Skii.dev
Studying 0days: How we hacked Anki, the world's most popular flashcard app
It took us 10 days to go from “We think this might be vulnerable” to full-blown remote code execution, including the 7 days we were both on holiday.
Anyone can Access Deleted and Private Repository Data on GitHub
https://ift.tt/SJQ3MnI
Submitted July 24, 2024 at 11:01PM by wifihack
via reddit https://ift.tt/uSCAyZI
https://ift.tt/SJQ3MnI
Submitted July 24, 2024 at 11:01PM by wifihack
via reddit https://ift.tt/uSCAyZI
Trufflesecurity
Anyone can Access Deleted and Private Repository Data on GitHub ◆ Truffle Security Co.
You can access data from deleted forks, deleted repositories and even private repositories on GitHub. And it is available forever. This is known by GitHub, and intentionally designed that way.
intercept network request from poker client
https://mitmproxy.org/
Submitted July 25, 2024 at 12:31AM by Heineken1384
via reddit https://ift.tt/uGZc9Sz
https://mitmproxy.org/
Submitted July 25, 2024 at 12:31AM by Heineken1384
via reddit https://ift.tt/uGZc9Sz
Reddit
From the netsec community on Reddit: intercept network request from poker client
Posted by Heineken1384 - No votes and 1 comment
Unfashionably secure: why we use isolated VMs
https://ift.tt/cBrCWnq
Submitted July 25, 2024 at 02:27PM by thinkst
via reddit https://ift.tt/XFTaG8x
https://ift.tt/cBrCWnq
Submitted July 25, 2024 at 02:27PM by thinkst
via reddit https://ift.tt/XFTaG8x
Thinkst Thoughts
Unfashionably secure: why we use isolated VMs
Would your rather observe an eclipse through a pair of new Ray-Bans, or a used Shade 12 welding helmet? Undoubtably the Aviators are more fashionable, but the permanent retinal damage sucks. Fetch …
go-exploit Goes Scanless
https://ift.tt/eNhaFMn
Submitted July 25, 2024 at 08:25PM by chicksdigthelongrun
via reddit https://ift.tt/erMlKC2
https://ift.tt/eNhaFMn
Submitted July 25, 2024 at 08:25PM by chicksdigthelongrun
via reddit https://ift.tt/erMlKC2
VulnCheck
VulnCheck go-exploit Goes Scanless - Blog - VulnCheck
Demonstrating the new scanless feature in the go-exploit exploit framework.
Think Twice Before Cheating: Escape From Tarkov Cheat Developer Steals User Data.
https://ift.tt/XNmkASM
Submitted July 25, 2024 at 08:07PM by jat0369
via reddit https://ift.tt/57qExv6
https://ift.tt/XNmkASM
Submitted July 25, 2024 at 08:07PM by jat0369
via reddit https://ift.tt/57qExv6
Cyberark
Double Dipping Cheat Developer Gets Caught Red-Handed
Following our post “A Brief History of Game Cheating,” it’s safe to say that cheats, no matter how lucrative or premium they might look, always carry a degree of danger. Today’s story revolves...
Guys, please give me some good autopsy tools. I want the whole history from the start, thanks.
http://Autopsy.com
Submitted July 26, 2024 at 12:00AM by Master_Mind_BigHead
via reddit https://ift.tt/vohiSEF
http://Autopsy.com
Submitted July 26, 2024 at 12:00AM by Master_Mind_BigHead
via reddit https://ift.tt/vohiSEF
Autopsy
Autopsy | Digital Forensics
Autopsy® is the premier end-to-end open source digital forensics platform. Built by Basis Technology with the core features you expect in commercial forensic tools, Autopsy is a fast, thorough, and efficient hard drive investigation solution that evolves…
PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem
https://ift.tt/yKrRg9p
Submitted July 26, 2024 at 02:36AM by LordAlfredo
via reddit https://ift.tt/AypfHYW
https://ift.tt/yKrRg9p
Submitted July 26, 2024 at 02:36AM by LordAlfredo
via reddit https://ift.tt/AypfHYW
www.binarly.io
PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem
PKfail is a zero day disclosure detected by the Binarly REsearch Team and responsibly disclosed.
Automatically secure your application with your personal Application Firewall using AppArmor and bifrost
https://ift.tt/YaFpuhO
Submitted July 26, 2024 at 01:18PM by noctarius2k
via reddit https://ift.tt/WAc9pt6
https://ift.tt/YaFpuhO
Submitted July 26, 2024 at 01:18PM by noctarius2k
via reddit https://ift.tt/WAc9pt6
simplyblock.io
Cloud Commute | simplyblock.io
Cloud Commute is your weekly 20 minute podcast, talking with guests about all things cloud, storage, security, Kubernetes, and others.
New OpenSecurityTraining2 mini-class: "Debuggers 1102: Introductory Ghidra"
https://ift.tt/kagszGn
Submitted July 26, 2024 at 08:24PM by OpenSecurityTraining
via reddit https://ift.tt/G0BD4wE
https://ift.tt/kagszGn
Submitted July 26, 2024 at 08:24PM by OpenSecurityTraining
via reddit https://ift.tt/G0BD4wE
p.ost2.fyi
Debuggers 1102: Introductory Ghidra
Basic introduction to Ghidra
Looking to hire someone to help me
http://www.roblox.com
Submitted July 27, 2024 at 06:14PM by sugxrkat
via reddit https://ift.tt/TFWHkzV
http://www.roblox.com
Submitted July 27, 2024 at 06:14PM by sugxrkat
via reddit https://ift.tt/TFWHkzV
Roblox
Roblox is ushering in the next generation of entertainment. Imagine, create, and play together with millions of people across an infinite variety of immersive, user-generated 3D worlds.
ARM's Memory Corruption Detection - Memory Tag Extensions(MTE) Bypassed In Real World Conditions - Google's V8 Engine/Sandbox and the Linux Kernel via Speculative Execution Attacks.
https://ift.tt/L6q3F72
Submitted July 28, 2024 at 12:31AM by AdrianTeri
via reddit https://ift.tt/kDhdtB4
https://ift.tt/L6q3F72
Submitted July 28, 2024 at 12:31AM by AdrianTeri
via reddit https://ift.tt/kDhdtB4
BunkerWeb - The open-source and next-gen Web Application Firewall (WAF)
https://ift.tt/tJwBLya
Submitted July 26, 2024 at 09:06PM by bunkerity
via reddit https://ift.tt/V5Nr2l7
https://ift.tt/tJwBLya
Submitted July 26, 2024 at 09:06PM by bunkerity
via reddit https://ift.tt/V5Nr2l7
GitHub
GitHub - bunkerity/bunkerweb: 🛡️ Open-source and next-generation Web Application Firewall (WAF)
🛡️ Open-source and next-generation Web Application Firewall (WAF) - bunkerity/bunkerweb
CVE-2021-4440: A Linux CNA Case Study
https://ift.tt/BVov7ys
Submitted July 28, 2024 at 08:02PM by sadyetfly11
via reddit https://ift.tt/TuFr3bx
https://ift.tt/BVov7ys
Submitted July 28, 2024 at 08:02PM by sadyetfly11
via reddit https://ift.tt/TuFr3bx
grsecurity.net
grsecurity - CVE-2021-4440: A Linux CNA Case Study
This blog serves as a case study into how the newly-formed Linux CNA (CVE Numbering Authority) has affected Linux kernel vulnerability management, through the mishandling of a vulnerability we reported this year in the upstream 5.10 LTS kernel.
Help required from security researchers and pentesters
https://ift.tt/9uADw7M
Submitted July 28, 2024 at 08:40PM by Saurabhjdsingh
via reddit https://ift.tt/WSqR5D9
https://ift.tt/9uADw7M
Submitted July 28, 2024 at 08:40PM by Saurabhjdsingh
via reddit https://ift.tt/WSqR5D9
Google Docs
Security researcher Feedback
hey! We would love to have your feedback on below questions.