Studying 0days: How we hacked Anki, the world's most popular flashcard app
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
https://ift.tt/09rZN8I
Submitted July 24, 2024 at 08:58PM by J_ake20o4
via reddit https://ift.tt/SKOtUru
Skii.dev
Studying 0days: How we hacked Anki, the world's most popular flashcard app
It took us 10 days to go from “We think this might be vulnerable” to full-blown remote code execution, including the 7 days we were both on holiday.
Anyone can Access Deleted and Private Repository Data on GitHub
https://ift.tt/SJQ3MnI
Submitted July 24, 2024 at 11:01PM by wifihack
via reddit https://ift.tt/uSCAyZI
https://ift.tt/SJQ3MnI
Submitted July 24, 2024 at 11:01PM by wifihack
via reddit https://ift.tt/uSCAyZI
Trufflesecurity
Anyone can Access Deleted and Private Repository Data on GitHub ◆ Truffle Security Co.
You can access data from deleted forks, deleted repositories and even private repositories on GitHub. And it is available forever. This is known by GitHub, and intentionally designed that way.
intercept network request from poker client
https://mitmproxy.org/
Submitted July 25, 2024 at 12:31AM by Heineken1384
via reddit https://ift.tt/uGZc9Sz
https://mitmproxy.org/
Submitted July 25, 2024 at 12:31AM by Heineken1384
via reddit https://ift.tt/uGZc9Sz
Reddit
From the netsec community on Reddit: intercept network request from poker client
Posted by Heineken1384 - No votes and 1 comment
Unfashionably secure: why we use isolated VMs
https://ift.tt/cBrCWnq
Submitted July 25, 2024 at 02:27PM by thinkst
via reddit https://ift.tt/XFTaG8x
https://ift.tt/cBrCWnq
Submitted July 25, 2024 at 02:27PM by thinkst
via reddit https://ift.tt/XFTaG8x
Thinkst Thoughts
Unfashionably secure: why we use isolated VMs
Would your rather observe an eclipse through a pair of new Ray-Bans, or a used Shade 12 welding helmet? Undoubtably the Aviators are more fashionable, but the permanent retinal damage sucks. Fetch …
go-exploit Goes Scanless
https://ift.tt/eNhaFMn
Submitted July 25, 2024 at 08:25PM by chicksdigthelongrun
via reddit https://ift.tt/erMlKC2
https://ift.tt/eNhaFMn
Submitted July 25, 2024 at 08:25PM by chicksdigthelongrun
via reddit https://ift.tt/erMlKC2
VulnCheck
VulnCheck go-exploit Goes Scanless - Blog - VulnCheck
Demonstrating the new scanless feature in the go-exploit exploit framework.
Think Twice Before Cheating: Escape From Tarkov Cheat Developer Steals User Data.
https://ift.tt/XNmkASM
Submitted July 25, 2024 at 08:07PM by jat0369
via reddit https://ift.tt/57qExv6
https://ift.tt/XNmkASM
Submitted July 25, 2024 at 08:07PM by jat0369
via reddit https://ift.tt/57qExv6
Cyberark
Double Dipping Cheat Developer Gets Caught Red-Handed
Following our post “A Brief History of Game Cheating,” it’s safe to say that cheats, no matter how lucrative or premium they might look, always carry a degree of danger. Today’s story revolves...
Guys, please give me some good autopsy tools. I want the whole history from the start, thanks.
http://Autopsy.com
Submitted July 26, 2024 at 12:00AM by Master_Mind_BigHead
via reddit https://ift.tt/vohiSEF
http://Autopsy.com
Submitted July 26, 2024 at 12:00AM by Master_Mind_BigHead
via reddit https://ift.tt/vohiSEF
Autopsy
Autopsy | Digital Forensics
Autopsy® is the premier end-to-end open source digital forensics platform. Built by Basis Technology with the core features you expect in commercial forensic tools, Autopsy is a fast, thorough, and efficient hard drive investigation solution that evolves…
PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem
https://ift.tt/yKrRg9p
Submitted July 26, 2024 at 02:36AM by LordAlfredo
via reddit https://ift.tt/AypfHYW
https://ift.tt/yKrRg9p
Submitted July 26, 2024 at 02:36AM by LordAlfredo
via reddit https://ift.tt/AypfHYW
www.binarly.io
PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystem
PKfail is a zero day disclosure detected by the Binarly REsearch Team and responsibly disclosed.
Automatically secure your application with your personal Application Firewall using AppArmor and bifrost
https://ift.tt/YaFpuhO
Submitted July 26, 2024 at 01:18PM by noctarius2k
via reddit https://ift.tt/WAc9pt6
https://ift.tt/YaFpuhO
Submitted July 26, 2024 at 01:18PM by noctarius2k
via reddit https://ift.tt/WAc9pt6
simplyblock.io
Cloud Commute | simplyblock.io
Cloud Commute is your weekly 20 minute podcast, talking with guests about all things cloud, storage, security, Kubernetes, and others.
New OpenSecurityTraining2 mini-class: "Debuggers 1102: Introductory Ghidra"
https://ift.tt/kagszGn
Submitted July 26, 2024 at 08:24PM by OpenSecurityTraining
via reddit https://ift.tt/G0BD4wE
https://ift.tt/kagszGn
Submitted July 26, 2024 at 08:24PM by OpenSecurityTraining
via reddit https://ift.tt/G0BD4wE
p.ost2.fyi
Debuggers 1102: Introductory Ghidra
Basic introduction to Ghidra
Looking to hire someone to help me
http://www.roblox.com
Submitted July 27, 2024 at 06:14PM by sugxrkat
via reddit https://ift.tt/TFWHkzV
http://www.roblox.com
Submitted July 27, 2024 at 06:14PM by sugxrkat
via reddit https://ift.tt/TFWHkzV
Roblox
Roblox is ushering in the next generation of entertainment. Imagine, create, and play together with millions of people across an infinite variety of immersive, user-generated 3D worlds.
ARM's Memory Corruption Detection - Memory Tag Extensions(MTE) Bypassed In Real World Conditions - Google's V8 Engine/Sandbox and the Linux Kernel via Speculative Execution Attacks.
https://ift.tt/L6q3F72
Submitted July 28, 2024 at 12:31AM by AdrianTeri
via reddit https://ift.tt/kDhdtB4
https://ift.tt/L6q3F72
Submitted July 28, 2024 at 12:31AM by AdrianTeri
via reddit https://ift.tt/kDhdtB4
BunkerWeb - The open-source and next-gen Web Application Firewall (WAF)
https://ift.tt/tJwBLya
Submitted July 26, 2024 at 09:06PM by bunkerity
via reddit https://ift.tt/V5Nr2l7
https://ift.tt/tJwBLya
Submitted July 26, 2024 at 09:06PM by bunkerity
via reddit https://ift.tt/V5Nr2l7
GitHub
GitHub - bunkerity/bunkerweb: 🛡️ Open-source and next-generation Web Application Firewall (WAF)
🛡️ Open-source and next-generation Web Application Firewall (WAF) - bunkerity/bunkerweb
CVE-2021-4440: A Linux CNA Case Study
https://ift.tt/BVov7ys
Submitted July 28, 2024 at 08:02PM by sadyetfly11
via reddit https://ift.tt/TuFr3bx
https://ift.tt/BVov7ys
Submitted July 28, 2024 at 08:02PM by sadyetfly11
via reddit https://ift.tt/TuFr3bx
grsecurity.net
grsecurity - CVE-2021-4440: A Linux CNA Case Study
This blog serves as a case study into how the newly-formed Linux CNA (CVE Numbering Authority) has affected Linux kernel vulnerability management, through the mishandling of a vulnerability we reported this year in the upstream 5.10 LTS kernel.
Help required from security researchers and pentesters
https://ift.tt/9uADw7M
Submitted July 28, 2024 at 08:40PM by Saurabhjdsingh
via reddit https://ift.tt/WSqR5D9
https://ift.tt/9uADw7M
Submitted July 28, 2024 at 08:40PM by Saurabhjdsingh
via reddit https://ift.tt/WSqR5D9
Google Docs
Security researcher Feedback
hey! We would love to have your feedback on below questions.
SAML: How it Works, Vulnerabilities and Common Attacks
https://ift.tt/auHSgOs
Submitted July 29, 2024 at 12:46PM by sadyetfly11
via reddit https://ift.tt/PSnLOG9
https://ift.tt/auHSgOs
Submitted July 29, 2024 at 12:46PM by sadyetfly11
via reddit https://ift.tt/PSnLOG9
VAADATA - Ethical Hacking Services
SAML: How it Works, Vulnerabilities and Common Attacks
What is SAML (Security Assertion Markup Language)? This article explains how it works, its vulnerabilities, common attacks as well as security best practices.
Blind Trust and Broken Fixes: The Ongoing Battle with LogoFAIL Vulnerabilities
https://ift.tt/g8pOSt6
Submitted July 29, 2024 at 04:11PM by sadyetfly11
via reddit https://ift.tt/4Ucm58z
https://ift.tt/g8pOSt6
Submitted July 29, 2024 at 04:11PM by sadyetfly11
via reddit https://ift.tt/4Ucm58z
www.binarly.io
Blind Trust and Broken Fixes: The Ongoing Battle with LogoFAIL Vulnerabilities
6 months after LogoFAIL disclosure, several downstream vulnerabilities remain unfixed and hundreds of insecure devices are still in the field. Read full research and analysis.
“EchoSpoofing” — A Massive Phishing Campaign Exploiting Proofpoint’s Email Protection to Dispatch Millions of Perfectly Spoofed Emails
https://ift.tt/txMWKHO
Submitted July 29, 2024 at 06:43PM by inntenoff
via reddit https://ift.tt/3tzE8Vd
https://ift.tt/txMWKHO
Submitted July 29, 2024 at 06:43PM by inntenoff
via reddit https://ift.tt/3tzE8Vd
Medium
“EchoSpoofing” — A Massive Phishing Campaign Exploiting Proofpoint’s Email Protection to Dispatch Millions of Perfectly Spoofed…
By Nati Tal (Head of Guardio Labs)
I recently got infected by a virus can anyone tell me if any of these listining ports are sus? i need to know that im 100% clean
https://ift.tt/ZplnM67
Submitted July 29, 2024 at 09:05PM by swify08
via reddit https://ift.tt/QvhLkNr
https://ift.tt/ZplnM67
Submitted July 29, 2024 at 09:05PM by swify08
via reddit https://ift.tt/QvhLkNr
Google Docs
here is the list
here is the list Image
PID
Address
Port
Protocol
Firewall Status svchost.exe (netsvcs -p)
3492
IPv4 unspecified
53
UDP
Allowed, restricted svchost.exe (netsvcs -p)
3492
172.25.16.1
67
UDP
Allowed, restricted svchost.exe (netsvcs -p)
3492
172.25.16.1
68
UDP…
PID
Address
Port
Protocol
Firewall Status svchost.exe (netsvcs -p)
3492
IPv4 unspecified
53
UDP
Allowed, restricted svchost.exe (netsvcs -p)
3492
172.25.16.1
67
UDP
Allowed, restricted svchost.exe (netsvcs -p)
3492
172.25.16.1
68
UDP…
Turning Outlook into a C2 client with a single registry value and the release of a new C2 framework
https://ift.tt/03bPqsw
Submitted July 29, 2024 at 11:58PM by oddvarmoe
via reddit https://ift.tt/49rWiMR
https://ift.tt/03bPqsw
Submitted July 29, 2024 at 11:58PM by oddvarmoe
via reddit https://ift.tt/49rWiMR
TrustedSec
Specula - Turning Outlook Into a C2 With One Registry Change
Engineering Learnings from the CrowdStrike Falcon Outage
https://ift.tt/9WQmNrX
Submitted July 30, 2024 at 08:24AM by mazen160
via reddit https://ift.tt/lqcXLMk
https://ift.tt/9WQmNrX
Submitted July 30, 2024 at 08:24AM by mazen160
via reddit https://ift.tt/lqcXLMk
Mazin Ahmed
Engineering Learnings from the CrowdStrike Falcon Outage