New free, open, online, practical security class from Czech Technical University.
https://ift.tt/AXv2ND6
Submitted September 20, 2024 at 02:53AM by sebagarcia
via reddit https://ift.tt/H3YNG7j
https://ift.tt/AXv2ND6
Submitted September 20, 2024 at 02:53AM by sebagarcia
via reddit https://ift.tt/H3YNG7j
cybersecurity.bsy.fel.cvut.cz
Introduction to Security
Introduction to Security Class (BSY), FEL, Czech Technical University
Link-Write Attack: A sweet combination to attack extraction implementations
https://ift.tt/gha4YFt
Submitted September 20, 2024 at 03:30PM by 0x4a616e
via reddit https://ift.tt/LKnhDQg
https://ift.tt/gha4YFt
Submitted September 20, 2024 at 03:30PM by 0x4a616e
via reddit https://ift.tt/LKnhDQg
blog.nody.cc
Link-Write Attack: A sweet combination
I’ve recently been working on some exciting development projects, including a deep dive into archive extraction. During this work, I discovered some fascinating behaviours that I’m thrilled to share with you in the following sections.
A Journey From `sudo iptables` To Local Privilege Escalation - Shielder
https://ift.tt/vaiSy9Z
Submitted September 20, 2024 at 07:10PM by smaury
via reddit https://ift.tt/z1jyZMe
https://ift.tt/vaiSy9Z
Submitted September 20, 2024 at 07:10PM by smaury
via reddit https://ift.tt/z1jyZMe
Shielder
Shielder - A Journey From `sudo iptables` To Local Privilege Escalation
In this post, we demonstrate two techniques allowing a low privileged user to escalate their privileges to root in case they can run iptables and/or iptables-save as
Using YouTube to steal your files ($41337 bounty)
https://ift.tt/XdszDkO
Submitted September 21, 2024 at 01:54AM by AlmondOffSec
via reddit https://ift.tt/stJW9Ck
https://ift.tt/XdszDkO
Submitted September 21, 2024 at 01:54AM by AlmondOffSec
via reddit https://ift.tt/stJW9Ck
lyra's epic blog
Using YouTube to steal your files
A writeup of my $4133.70 Google Drive vulnerability chain.
Analysis of CVE-2024-20439 in Cisco Smart Licensing Utility
https://ift.tt/6U4nDeG
Submitted September 21, 2024 at 07:16AM by lightgrains
via reddit https://ift.tt/bPNuJv1
https://ift.tt/6U4nDeG
Submitted September 21, 2024 at 07:16AM by lightgrains
via reddit https://ift.tt/bPNuJv1
0-Click RCE in MediaTek Wi-Fi Chipsets — 4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways
https://ift.tt/cWaFyw4
Submitted September 21, 2024 at 11:49AM by MegaManSec2
via reddit https://ift.tt/GO8PMJq
https://ift.tt/cWaFyw4
Submitted September 21, 2024 at 11:49AM by MegaManSec2
via reddit https://ift.tt/GO8PMJq
hyprblog
4 exploits, 1 bug: exploiting CVE-2024-20017 4 different ways
a post going over 4 exploits for CVE-2024-20017, a remotely exploitable buffer overflow in a component of the MediaTek MT7622 SDK.
Published a handy tool to create tar/zip archives to exploit zipslip vulnerability
https://ift.tt/VLZonHz
Submitted September 20, 2024 at 03:34PM by 0x4a616e
via reddit https://ift.tt/uwPi0qe
https://ift.tt/VLZonHz
Submitted September 20, 2024 at 03:34PM by 0x4a616e
via reddit https://ift.tt/uwPi0qe
GitHub
GitHub - nodyhub/zipslipper: Create tar/zip archives that try to exploit zipslip vulnerability.
Create tar/zip archives that try to exploit zipslip vulnerability. - nodyhub/zipslipper
Announcing Security Exception Program Pack 1.0
https://ift.tt/m7gScUw
Submitted September 22, 2024 at 05:27AM by SecTemplates
via reddit https://ift.tt/UnbO7hK
https://ift.tt/m7gScUw
Submitted September 22, 2024 at 05:27AM by SecTemplates
via reddit https://ift.tt/UnbO7hK
SecTemplates.com
Announcing the Security Exceptions program pack 1.0
Introduction Every company establishes processes to identify security vulnerabilities, prioritize them, develop solutions, and, in some cases, strategically accept risk either temporarily or permanently. Security exceptions are closely tied to vulnerability…
Decentralized Encrypted P2P Chat
https://ift.tt/6Tmhwij
Submitted September 22, 2024 at 11:24PM by Accurate-Screen8774
via reddit https://ift.tt/H8b9SFq
https://ift.tt/6Tmhwij
Submitted September 22, 2024 at 11:24PM by Accurate-Screen8774
via reddit https://ift.tt/H8b9SFq
Positive-Intentions
Introducing Decentralized Chat | positive-intentions
Are you tired of compromising your privacy and security when sharing files online? What if there was a way to transfer data that was not only secure and efficient but also put you in complete control? Imagine a file sharing solution that combines cutting…
Reverse Engineering a Kernel Driver chall (Live Hacking)
https://ift.tt/AfYpNUi
Submitted September 22, 2024 at 11:41PM by pwntheplanet
via reddit https://ift.tt/iJbZ1Tr
https://ift.tt/AfYpNUi
Submitted September 22, 2024 at 11:41PM by pwntheplanet
via reddit https://ift.tt/iJbZ1Tr
( ͡◕ _ ͡◕)👌
Reverse Engineering a Kernel Driver chall
What's inside the QR code menu at this cafe?
https://ift.tt/nxNBS4X
Submitted September 23, 2024 at 02:15PM by _vavkamil_
via reddit https://ift.tt/Zly3AwG
https://ift.tt/nxNBS4X
Submitted September 23, 2024 at 02:15PM by _vavkamil_
via reddit https://ift.tt/Zly3AwG
Pea Bee
What's inside the QR code menu at this cafe?
Let me scan it, what could possibly go wrong?
Open to Exploitation: The Security Risks of Unauthenticated Pager Networks
https://ift.tt/3kbohCV
Submitted September 23, 2024 at 01:39PM by vasiliborodin
via reddit https://ift.tt/GCrukZy
https://ift.tt/3kbohCV
Submitted September 23, 2024 at 01:39PM by vasiliborodin
via reddit https://ift.tt/GCrukZy
Open to Exploitation: The Security Risks of Unauthenticated Pager Networks
In a world increasingly reliant on secure digital communications, it’s surprising to learn that many countries, including those in critical sectors such as healthcare and industrial control systems (SCADA), still use outdated pager networks like POCSAG for…
Exploiting AMD atdcm64a.sys arbitrary pointer dereference - Part 1
https://ift.tt/W96tbNp
Submitted September 25, 2024 at 01:29PM by 0xdea
via reddit https://ift.tt/raI5Qyk
https://ift.tt/W96tbNp
Submitted September 25, 2024 at 01:29PM by 0xdea
via reddit https://ift.tt/raI5Qyk
hn security
Exploiting AMD atdcm64a.sys arbitrary pointer dereference - Part 1 - hn security
After attending the OST2 – Exp4011 […]
CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability Deep-Dive – Horizon3.ai
https://ift.tt/bCneE8d
Submitted September 25, 2024 at 04:03PM by scopedsecurity
via reddit https://ift.tt/Ngr72mX
https://ift.tt/bCneE8d
Submitted September 25, 2024 at 04:03PM by scopedsecurity
via reddit https://ift.tt/Ngr72mX
Horizon3.ai
CVE-2024-28987: SolarWinds Web Help Desk Hardcoded Credential Vulnerability Deep-Dive
CVE-2024-28987 SolarWinds Web Help Desk Hardcoded Credential Vulnerability Deep-Dive and Indicators of Compromise. This blog details a hardcoded credentials vulnerability which allows an unauthenticated attacker to read and modify all help desk tickets.
A vulnerability in the Nortek Linear eMerge E3 allows remote unauthenticated attackers to cause the device to execute arbitrary commands
https://ift.tt/mKiD3tS
Submitted September 25, 2024 at 05:32PM by SSDisclosure
via reddit https://ift.tt/cWP1pGw
https://ift.tt/mKiD3tS
Submitted September 25, 2024 at 05:32PM by SSDisclosure
via reddit https://ift.tt/cWP1pGw
SSD Secure Disclosure
SSD Advisory - Nortek Linear eMerge E3 Pre-Auth RCE - SSD Secure Disclosure
Summary A vulnerability in the Nortek Linear eMerge E3 allows remote unauthenticated attackers to cause the device to execute arbitrary commands. Credit An independent security researcher working with SSD Secure Disclosure Vendor Response The vendor has been…
Critical Vulnerabilities in WatchGuard SSO Agent
https://ift.tt/W7rXsEh
Submitted September 25, 2024 at 04:56PM by RedTeamPentesting
via reddit https://ift.tt/9WKMzAa
https://ift.tt/W7rXsEh
Submitted September 25, 2024 at 04:56PM by RedTeamPentesting
via reddit https://ift.tt/9WKMzAa
www.redteam-pentesting.de
RedTeam Pentesting - WatchGuard SSO Protocol is Unencrypted and Unauthenticated
The protocol that is used by the WatchGuard Single Sign-On (SSO) agent to communicate with the respective client services is neither encrypted, nor authenticated. The unprotected information that is communicated is used to decide which firewall rules should…
Access data in Android app
https://ift.tt/9nqV7eN
Submitted September 25, 2024 at 06:22PM by y_reddit_huh
via reddit https://ift.tt/lIkd64t
https://ift.tt/9nqV7eN
Submitted September 25, 2024 at 06:22PM by y_reddit_huh
via reddit https://ift.tt/lIkd64t
Wikipedia
File:Instagram logo 2022.noscript
Original file (SVG file, nominally 1,000 × 1,000 pixels, file size: 9 KB)
New CVE! Nortek Linear eMerge E3 Pre-Auth RCE!
https://ift.tt/f8SZlGT
Submitted September 25, 2024 at 10:28PM by Straight-Zombie-646
via reddit https://ift.tt/IVhvUHr
https://ift.tt/f8SZlGT
Submitted September 25, 2024 at 10:28PM by Straight-Zombie-646
via reddit https://ift.tt/IVhvUHr
SSD Secure Disclosure
SSD Advisory - Nortek Linear eMerge E3 Pre-Auth RCE - SSD Secure Disclosure
Summary A vulnerability in the Nortek Linear eMerge E3 allows remote unauthenticated attackers to cause the device to execute arbitrary commands. Credit An independent security researcher working with SSD Secure Disclosure Vendor Response The vendor has been…
Subdomain search engine
https://ift.tt/5uJkIUZ
Submitted September 25, 2024 at 10:12PM by SomeoneIsSomeWhere
via reddit https://ift.tt/i0ePofp
https://ift.tt/5uJkIUZ
Submitted September 25, 2024 at 10:12PM by SomeoneIsSomeWhere
via reddit https://ift.tt/i0ePofp
Merklemap
Subdomain search engine | Merklemap
Uncover hidden subdomains: Boost your cybersecurity, validate digital assets, and supercharge your pen testing. Find every subdomain linked to any website.
CVE-2014-0160
https://ift.tt/KA6hlTZ
Submitted September 26, 2024 at 01:02AM by MrXcrypt
via reddit https://ift.tt/HijpZvq
https://ift.tt/KA6hlTZ
Submitted September 26, 2024 at 01:02AM by MrXcrypt
via reddit https://ift.tt/HijpZvq
Medium
Heartbleed — A deep dive into CVE-2014–0160
In this blog, we’ll dive into how Heartbleed works, the vulnerable code and how to exploit it.
Jorkle's OSCP Guide
https://ift.tt/JVmDqnj
Submitted September 26, 2024 at 02:14AM by jorkle0895
via reddit https://ift.tt/e5qI8tp
https://ift.tt/JVmDqnj
Submitted September 26, 2024 at 02:14AM by jorkle0895
via reddit https://ift.tt/e5qI8tp
The Weekly Jorkle
Jorkle's OSCP Guide
Introduction Hello Folks, Today I am providing an all-encompassing OSCP preparation guide containing the advice and resources I wish I had when I started this path towards the OSCP. If you have any questions relating to OSCP preparation or anything else,…