The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
https://ift.tt/YhKv3dx
Submitted November 23, 2024 at 03:25AM by cryptogram
via reddit https://ift.tt/r06aHBA
Volexity
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
In early February 2022, notably just ahead of the Russian invasion of Ukraine, Volexity made a discovery that led to one of the most fascinating and complex incident investigations Volexity had ever worked. The investigation began when an alert from a custom…
Handling Cookies is a Minefield
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
https://ift.tt/I2gLVbl
Submitted November 24, 2024 at 06:07AM by smaury
via reddit https://ift.tt/Hq2yIpn
grayduck.mn
April King — Handling Cookies is a Minefield
Discrepancies in how browsers and libraries handle HTTP cookies, and the problems caused by such things.
Breaking out of VRChat using a Unity bug
https://ift.tt/CQ9fBHu
Submitted November 24, 2024 at 11:07PM by khangaroooooooo
via reddit https://ift.tt/4DqVMBz
https://ift.tt/CQ9fBHu
Submitted November 24, 2024 at 11:07PM by khangaroooooooo
via reddit https://ift.tt/4DqVMBz
Khang's Stuff
Breaking out of VRChat using a Unity bug
Making Udon a bit too flexible.
How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review
https://ift.tt/rF6SPGk
Submitted November 25, 2024 at 08:53AM by ffyns
via reddit https://ift.tt/YnHL1qb
https://ift.tt/rF6SPGk
Submitted November 25, 2024 at 08:53AM by ffyns
via reddit https://ift.tt/YnHL1qb
Pentesterlab
How JWT Libraries Block Algorithm Confusion: Key Lessons for Code Review
Learn how JWT libraries prevent algorithm confusion attacks and key lessons for improving security code reviews through effective practices and safeguards. A must-read for code reviewers and security engineers
Ruby 3.4 Universal RCE Deserialization Gadget Chain / nastystereo.com
https://ift.tt/yeI4ksi
Submitted November 25, 2024 at 11:04AM by nastystereo
via reddit https://ift.tt/HkwULvz
https://ift.tt/yeI4ksi
Submitted November 25, 2024 at 11:04AM by nastystereo
via reddit https://ift.tt/HkwULvz
Windows - DPAPI Revisited for Chromium App-Bound encryption recent changes
https://ift.tt/J7O0wUB
Submitted November 26, 2024 at 01:38AM by clod81
via reddit https://ift.tt/35W4sGf
https://ift.tt/J7O0wUB
Submitted November 26, 2024 at 01:38AM by clod81
via reddit https://ift.tt/35W4sGf
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Attacking hypervisors - A practical case [Pwn2Own Vancouver 2024]
https://ift.tt/H74bxPv
Submitted November 26, 2024 at 01:10PM by buherator
via reddit https://ift.tt/7fbxPt0
https://ift.tt/H74bxPv
Submitted November 26, 2024 at 01:10PM by buherator
via reddit https://ift.tt/7fbxPt0
Reversetactics
REverse Tactics
Presentation on the vulnerability research conducted on VirtualBox for Pwn2Own Vancouver 2024.
Extending Burp Suite for fun and profit – The Montoya way – Part 8
https://ift.tt/VbkWBM5
Submitted November 26, 2024 at 02:52PM by 0xdea
via reddit https://ift.tt/vytxr0a
https://ift.tt/VbkWBM5
Submitted November 26, 2024 at 02:52PM by 0xdea
via reddit https://ift.tt/vytxr0a
HN Security
Extending Burp Suite for fun and profit – The Montoya way – Part 8 - HN Security
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs
https://ift.tt/KqMbLGl
Submitted November 26, 2024 at 04:15PM by Ok_Information1453
via reddit https://ift.tt/uPoVpix
https://ift.tt/KqMbLGl
Submitted November 26, 2024 at 04:15PM by Ok_Information1453
via reddit https://ift.tt/uPoVpix
Invicti
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs
Brainstorm is a new, smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery
Introducing NachoVPN: One VPN Server to Pwn Them All
https://ift.tt/jckGysH
Submitted November 26, 2024 at 08:01PM by AlmondOffSec
via reddit https://ift.tt/va3gUwR
https://ift.tt/jckGysH
Submitted November 26, 2024 at 08:01PM by AlmondOffSec
via reddit https://ift.tt/va3gUwR
Amberwolf
Introducing NachoVPN: One VPN Server to Pwn Them All
AmberWolf Security Research Blog
The Curious Case of nltest and LmOwfPassword/NtOwfPassword
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
Jonas Lieb
The Curious Case of nltest and LmOwfPassword/NtOwfPassword
I recently fiddled around with Window’s built-in command nltest and noticed that nltest /user:<username>, when executed as an Administrator, yields some interesting information about the requested user:
The two fields LmOwfPassword and NtOwfPassword spiked…
The two fields LmOwfPassword and NtOwfPassword spiked…
Hacking Barcodes for Fun & Profit...
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
Mobile scareware now mimics cracked smartphone screen as a result of a fake virus infection
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
Mobile Hacker
Smartphone scareware: cracked screen as a result of virus
This new technique mimics a cracked screen that is a result of a fake virus infection as visible in the video below
New PE Vulnerability in Windows OS!
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
SSD Secure Disclosure
SSD Advisory - ksthunk.sys Integer Overflow (PE) - SSD Secure Disclosure
Summary A vulnerability in the ksthunk.sys CKSAutomationThunk::ThunkEnableEventIrp allows a local attacker to exploit an Integer Overflow vulnerability which can then be used to gain elevated privileges in the Windows operating system. The exploit was successfully…
The hidden network report - How China unites state, corporate, and academic assets for offensive campaigns
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
Medium
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
Ghidra, developed by the NSA, is a powerful reverse engineering tool known for its versatility. One standout feature is its ability to…
BusKill cables now available in a brick-and-mortar in #TheNetherlands 🇳🇱🧱
https://ift.tt/U4Efw8g
Submitted November 27, 2024 at 11:38PM by maltfield
via reddit https://ift.tt/w20qj1U
https://ift.tt/U4Efw8g
Submitted November 27, 2024 at 11:38PM by maltfield
via reddit https://ift.tt/w20qj1U
BusKill
BusKill available in-store (The Netherlands NovaCustom) - BusKill
Our USB Dead Man Switch can now be purchased in-person at NovaCustom's brick-and-mortar location in The Netherlands.
Cross-Site POST Requests Without a Content-Type Header
https://ift.tt/Id6aOxQ
Submitted November 28, 2024 at 04:46AM by AlmondOffSec
via reddit https://ift.tt/5CgzRHq
https://ift.tt/Id6aOxQ
Submitted November 28, 2024 at 04:46AM by AlmondOffSec
via reddit https://ift.tt/5CgzRHq
The Ultimate Handheld Hacking Device - My Experience with NetHunter
https://ift.tt/QRwL7Py
Submitted November 28, 2024 at 05:10AM by andy-codes
via reddit https://ift.tt/ZqgtQpa
https://ift.tt/QRwL7Py
Submitted November 28, 2024 at 05:10AM by andy-codes
via reddit https://ift.tt/ZqgtQpa
andy.codes
2024-11-27 - The Ultimate Handheld Hacking Device - My Experience with NetHunter - Andy's Cave
This page is a collection of my security research, and other infosec-related activities.
Analyzing APT36’s ElizaRAT: Evolution of Espionage Techniques
https://ift.tt/TiSLmw4
Submitted November 28, 2024 at 02:24PM by matbaylaw
via reddit https://ift.tt/HeWjMYv
https://ift.tt/TiSLmw4
Submitted November 28, 2024 at 02:24PM by matbaylaw
via reddit https://ift.tt/HeWjMYv
Introduction to Fuzzing Android Native Components
https://ift.tt/Mt9ZFHY
Submitted November 29, 2024 at 02:53AM by thewatcher_
via reddit https://ift.tt/4IeUStp
https://ift.tt/Mt9ZFHY
Submitted November 29, 2024 at 02:53AM by thewatcher_
via reddit https://ift.tt/4IeUStp
Conviso AppSec
Introduction to Fuzzing Android Native Components
Discover how fuzzing can identify critical vulnerabilities in native Android components, strengthening device security.