Automate Pentest Reporting with Faction
https://ift.tt/l7cqSux
Submitted November 22, 2024 at 02:30AM by ascetik
via reddit https://ift.tt/Eijqxmr
https://ift.tt/l7cqSux
Submitted November 22, 2024 at 02:30AM by ascetik
via reddit https://ift.tt/Eijqxmr
Medium
How to Automate Pentest Reporting Using Faction
Faction is an open-source security assessment collaboration framework designed to streamline and enhance your security workflows. With…
Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x
https://ift.tt/4bWthGD
Submitted November 22, 2024 at 10:06AM by Mempodipper
via reddit https://ift.tt/Yih8tqr
https://ift.tt/4bWthGD
Submitted November 22, 2024 at 10:06AM by Mempodipper
via reddit https://ift.tt/Yih8tqr
www.assetnote.io
Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x
Local file disclosure in Sitecore 8.x to 10.x that can lead to RCE (CVE-2024-46938) due to an order of operations bug within a handler responsible for reading local files.
Released My Longest Weekly Newsletter Yet - Feedback Appreciated!
https://ift.tt/FcSN9Qj
Submitted November 23, 2024 at 12:45AM by PacketsForward
via reddit https://ift.tt/A4sI5Pu
https://ift.tt/FcSN9Qj
Submitted November 23, 2024 at 12:45AM by PacketsForward
via reddit https://ift.tt/A4sI5Pu
Decrypt LOL
Newsletter 22 November 2024
Get the latest security insights, tech updates, and impactful tools reviewed in our November 22, 2024, newsletter.
Navigating the Leap: My Journey from Software Engineering to Offensive Security
https://ift.tt/aJZWMQY
Submitted November 23, 2024 at 02:29AM by andy-codes
via reddit https://ift.tt/rAbG8WV
https://ift.tt/aJZWMQY
Submitted November 23, 2024 at 02:29AM by andy-codes
via reddit https://ift.tt/rAbG8WV
OffSec
Navigating the Leap: My Journey from Software Engineering to Offensive Security | OffSec
A software engineer's journey into offensive security, sharing insights and tips for transitioning careers and thriving in the infosec field.
Prototype Pollution in NASAs Open MCT CVE-2023-45282
https://ift.tt/I2E0gyU
Submitted November 23, 2024 at 02:07AM by andy-codes
via reddit https://ift.tt/BtzdPYj
https://ift.tt/I2E0gyU
Submitted November 23, 2024 at 02:07AM by andy-codes
via reddit https://ift.tt/BtzdPYj
Visionspace
Prototype Pollution in NASAs Open MCT CVE-2023-45282
The Prototype Pollution vulnerability is specific to the JavaScript programming language. It enables an attacker to add or alter any properties of global object prototypes. Once the property is changed, the code that inherits it will use the injected property…
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
Volexity
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever worked. The investigation began when an alert from a custom…
Handling Cookies is a Minefield
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
grayduck.mn
April King — Handling Cookies is a Minefield
Discrepancies in how browsers and libraries handle HTTP cookies, and the problems caused by such things.
Breaking out of VRChat using a Unity bug
https://ift.tt/CQ9fBHu
Submitted November 24, 2024 at 11:07PM by khangaroooooooo
via reddit https://ift.tt/4DqVMBz
https://ift.tt/CQ9fBHu
Submitted November 24, 2024 at 11:07PM by khangaroooooooo
via reddit https://ift.tt/4DqVMBz
Khang's Stuff
Breaking out of VRChat using a Unity bug
Making Udon a bit too flexible.
How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review
https://ift.tt/rF6SPGk
Submitted November 25, 2024 at 08:53AM by ffyns
via reddit https://ift.tt/YnHL1qb
https://ift.tt/rF6SPGk
Submitted November 25, 2024 at 08:53AM by ffyns
via reddit https://ift.tt/YnHL1qb
Pentesterlab
How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review
Learn how JWT libraries prevent algorithm confusion attacks and key lessons for improving security code reviews through effective practices and safeguards. A must-read for code reviewers and security engineers
Ruby 3.4 Universal RCE Deserialization Gadget Chain / nastystereo.com
https://ift.tt/yeI4ksi
Submitted November 25, 2024 at 11:04AM by nastystereo
via reddit https://ift.tt/HkwULvz
https://ift.tt/yeI4ksi
Submitted November 25, 2024 at 11:04AM by nastystereo
via reddit https://ift.tt/HkwULvz
Windows - DPAPI Revisited for Chromium App-Bound encryption recent changes
https://ift.tt/J7O0wUB
Submitted November 26, 2024 at 01:38AM by clod81
via reddit https://ift.tt/35W4sGf
https://ift.tt/J7O0wUB
Submitted November 26, 2024 at 01:38AM by clod81
via reddit https://ift.tt/35W4sGf
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Attacking hypervisors - A practical case [Pwn2Own Vancouver 2024]
https://ift.tt/H74bxPv
Submitted November 26, 2024 at 01:10PM by buherator
via reddit https://ift.tt/7fbxPt0
https://ift.tt/H74bxPv
Submitted November 26, 2024 at 01:10PM by buherator
via reddit https://ift.tt/7fbxPt0
Reversetactics
REverse Tactics
Presentation on the vulnerability research conducted on VirtualBox for Pwn2Own Vancouver 2024.
Extending Burp Suite for fun and profit – The Montoya way – Part 8
https://ift.tt/VbkWBM5
Submitted November 26, 2024 at 02:52PM by 0xdea
via reddit https://ift.tt/vytxr0a
https://ift.tt/VbkWBM5
Submitted November 26, 2024 at 02:52PM by 0xdea
via reddit https://ift.tt/vytxr0a
HN Security
Extending Burp Suite for fun and profit – The Montoya way – Part 8 - HN Security
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs
https://ift.tt/KqMbLGl
Submitted November 26, 2024 at 04:15PM by Ok_Information1453
via reddit https://ift.tt/uPoVpix
https://ift.tt/KqMbLGl
Submitted November 26, 2024 at 04:15PM by Ok_Information1453
via reddit https://ift.tt/uPoVpix
Invicti
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs
Brainstorm is a new, smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery
Introducing NachoVPN: One VPN Server to Pwn Them All
https://ift.tt/jckGysH
Submitted November 26, 2024 at 08:01PM by AlmondOffSec
via reddit https://ift.tt/va3gUwR
https://ift.tt/jckGysH
Submitted November 26, 2024 at 08:01PM by AlmondOffSec
via reddit https://ift.tt/va3gUwR
Amberwolf
Introducing NachoVPN: One VPN Server to Pwn Them All
AmberWolf Security Research Blog
The Curious Case of nltest and LmOwfPassword/NtOwfPassword
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
Jonas Lieb
The Curious Case of nltest and LmOwfPassword/NtOwfPassword
I recently fiddled around with Window’s built-in command nltest and noticed that nltest /user:<username>, when executed as an Administrator, yields some interesting information about the requested user:
The two fields LmOwfPassword and NtOwfPassword spiked…
The two fields LmOwfPassword and NtOwfPassword spiked…
Hacking Barcodes for Fun & Profit...
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
Mobile scareware now mimics cracked smartphone screen as a result of a fake virus infection
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
Mobile Hacker
Smartphone scareware: cracked screen as a result of virus
This new technique mimics a cracked screen that is a result of a fake virus infection as visible in the video below
New PE Vulnerability in Windows OS!
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
SSD Secure Disclosure
SSD Advisory - ksthunk.sys Integer Overflow (PE) - SSD Secure Disclosure
Summary A vulnerability in the ksthunk.sys CKSAutomationThunk::ThunkEnableEventIrp allows a local attacker to exploit an Integer Overflow vulnerability which can then be used to gain elevated privileges in the Windows operating system. The exploit was successfully…
The hidden network report - How China unites state, corporate, and academic assets for offensive campaigns
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
Medium
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
Ghidra, developed by the NSA, is a powerful reverse engineering tool known for its versatility. One standout feature is its ability to…