The Curious Case of nltest and LmOwfPassword/NtOwfPassword
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
https://ift.tt/fSZi47V
Submitted November 27, 2024 at 12:30AM by LeCherLich
via reddit https://ift.tt/wE2pxTK
Jonas Lieb
The Curious Case of nltest and LmOwfPassword/NtOwfPassword
I recently fiddled around with Window’s built-in command nltest and noticed that nltest /user:<username>, when executed as an Administrator, yields some interesting information about the requested user:
The two fields LmOwfPassword and NtOwfPassword spiked…
The two fields LmOwfPassword and NtOwfPassword spiked…
Hacking Barcodes for Fun & Profit...
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
https://ift.tt/f6NkWRK
Submitted November 27, 2024 at 01:04AM by eqarmada2
via reddit https://ift.tt/Tq5FV9l
Mobile scareware now mimics cracked smartphone screen as a result of a fake virus infection
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
https://ift.tt/mwKHhM3
Submitted November 27, 2024 at 02:14PM by barakadua131
via reddit https://ift.tt/lMcsJQB
Mobile Hacker
Smartphone scareware: cracked screen as a result of virus
This new technique mimics a cracked screen that is a result of a fake virus infection as visible in the video below
New PE Vulnerability in Windows OS!
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
https://ift.tt/6o4TqE3
Submitted November 27, 2024 at 03:40PM by Straight-Zombie-646
via reddit https://ift.tt/YFhsqXw
SSD Secure Disclosure
SSD Advisory - ksthunk.sys Integer Overflow (PE) - SSD Secure Disclosure
Summary A vulnerability in the ksthunk.sys CKSAutomationThunk::ThunkEnableEventIrp allows a local attacker to exploit an Integer Overflow vulnerability which can then be used to gain elevated privileges in the Windows operating system. The exploit was successfully…
The hidden network report - How China unites state, corporate, and academic assets for offensive campaigns
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
https://ift.tt/aEpxhwQ
Submitted November 27, 2024 at 09:05PM by intelw1zard
via reddit https://ift.tt/gsuw7QG
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
https://ift.tt/iG3ByfD
Submitted November 27, 2024 at 10:04PM by onlinereadme
via reddit https://ift.tt/NHXVa8T
Medium
Everyday Ghidra: Ghidra Data Types — Creating Custom GDTs From Windows Headers — Part 2
Ghidra, developed by the NSA, is a powerful reverse engineering tool known for its versatility. One standout feature is its ability to…
BusKill cables now available in a brick-and-mortar in #TheNetherlands 🇳🇱🧱
https://ift.tt/U4Efw8g
Submitted November 27, 2024 at 11:38PM by maltfield
via reddit https://ift.tt/w20qj1U
https://ift.tt/U4Efw8g
Submitted November 27, 2024 at 11:38PM by maltfield
via reddit https://ift.tt/w20qj1U
BusKill
BusKill available in-store (The Netherlands NovaCustom) - BusKill
Our USB Dead Man Switch can now be purchased in-person at NovaCustom's brick-and-mortar location in The Netherlands.
Cross-Site POST Requests Without a Content-Type Header
https://ift.tt/Id6aOxQ
Submitted November 28, 2024 at 04:46AM by AlmondOffSec
via reddit https://ift.tt/5CgzRHq
https://ift.tt/Id6aOxQ
Submitted November 28, 2024 at 04:46AM by AlmondOffSec
via reddit https://ift.tt/5CgzRHq
The Ultimate Handheld Hacking Device - My Experience with NetHunter
https://ift.tt/QRwL7Py
Submitted November 28, 2024 at 05:10AM by andy-codes
via reddit https://ift.tt/ZqgtQpa
https://ift.tt/QRwL7Py
Submitted November 28, 2024 at 05:10AM by andy-codes
via reddit https://ift.tt/ZqgtQpa
andy.codes
2024-11-27 - The Ultimate Handheld Hacking Device - My Experience with NetHunter - Andy's Cave
This page is a collection of my security research, and other infosec-related activities.
Analyzing APT36’s ElizaRAT: Evolution of Espionage Techniques
https://ift.tt/TiSLmw4
Submitted November 28, 2024 at 02:24PM by matbaylaw
via reddit https://ift.tt/HeWjMYv
https://ift.tt/TiSLmw4
Submitted November 28, 2024 at 02:24PM by matbaylaw
via reddit https://ift.tt/HeWjMYv
Introduction to Fuzzing Android Native Components
https://ift.tt/Mt9ZFHY
Submitted November 29, 2024 at 02:53AM by thewatcher_
via reddit https://ift.tt/4IeUStp
https://ift.tt/Mt9ZFHY
Submitted November 29, 2024 at 02:53AM by thewatcher_
via reddit https://ift.tt/4IeUStp
Conviso AppSec
Introduction to Fuzzing Android Native Components
Discover how fuzzing can identify critical vulnerabilities in native Android components, strengthening device security.
Trying to Exploit My Old Android Device, take 1
https://ift.tt/x6eHdvr
Submitted November 29, 2024 at 06:23AM by pwntheplanet
via reddit https://ift.tt/2BT8Z4t
https://ift.tt/x6eHdvr
Submitted November 29, 2024 at 06:23AM by pwntheplanet
via reddit https://ift.tt/2BT8Z4t
( ͡◕ _ ͡◕)👌
Android's CVE-2020-0238 (AccountTypePreferenceLoader)
Note: This is part of my @vr_progress journal. Also, subscribe to my new @SideQuest_256 channel and I might post videos about the Android journey too :D This is a story about how I wasted my weekend over a bug that was categorized as a High/EoP but then couldn’t…
Dissecting JA4H for improved Sliver C2 detections
https://ift.tt/oethDJH
Submitted November 29, 2024 at 02:57PM by zynth-
via reddit https://ift.tt/3RBZ8e4
https://ift.tt/oethDJH
Submitted November 29, 2024 at 02:57PM by zynth-
via reddit https://ift.tt/3RBZ8e4
Webscout Tech Blog
Dissecting JA4H for improved Sliver C2 detections
Background
On November 18, 2024, Palo Alto Networks announced the discovery of two critical vulnerabilities, CVE-2024-0012 and CVE-2024-9474, in the operating system that powers their firewall devices. The following day, watchTowr published a report detailing…
On November 18, 2024, Palo Alto Networks announced the discovery of two critical vulnerabilities, CVE-2024-0012 and CVE-2024-9474, in the operating system that powers their firewall devices. The following day, watchTowr published a report detailing…
Lights Out: software control of the webcam LED on ThinkPad X230 without physical access to the laptop
https://ift.tt/xY7w3GP
Submitted November 28, 2024 at 06:21PM by AlmondOffSec
via reddit https://ift.tt/HTu6ne2
https://ift.tt/xY7w3GP
Submitted November 28, 2024 at 06:21PM by AlmondOffSec
via reddit https://ift.tt/HTu6ne2
GitHub
GitHub - xairy/lights-out: Tools for controlling webcam LED on ThinkPad X230
Tools for controlling webcam LED on ThinkPad X230. Contribute to xairy/lights-out development by creating an account on GitHub.
MSSQL Identified as Vulnerable to Emoji String Exploitation
https://ift.tt/jhdJWX6
Submitted November 29, 2024 at 10:36PM by PacketsForward
via reddit https://ift.tt/19mdHS2
https://ift.tt/jhdJWX6
Submitted November 29, 2024 at 10:36PM by PacketsForward
via reddit https://ift.tt/19mdHS2
Decrypt LOL
MSSQL Identified as Vulnerable to Emoji String Exploitation
Microsoft SQL Server has been found to treat a goblin emoji as equivalent to an empty string, potentially leading to security vulnerabilities in applications that utilize it.
New TryHackMe Room: AI Security Fundamentals – Learn AI Security and Pentesting
https://ift.tt/2MV6D7q
Submitted November 30, 2024 at 12:08AM by Educational-Duck9827
via reddit https://ift.tt/KAyNxcs
https://ift.tt/2MV6D7q
Submitted November 30, 2024 at 12:08AM by Educational-Duck9827
via reddit https://ift.tt/KAyNxcs
TryHackMe
TryHackMe | Cyber Security Training
TryHackMe is a free online platform for learning cyber security, using hands-on exercises and labs, all through your browser!
The fascinating security model of dark web marketplaces
https://ift.tt/ZOP4Sre
Submitted December 01, 2024 at 10:34PM by upofadown
via reddit https://ift.tt/wYl10rZ
https://ift.tt/ZOP4Sre
Submitted December 01, 2024 at 10:34PM by upofadown
via reddit https://ift.tt/wYl10rZ
boehs.org
The Fascinating Security Model of Dark Web Marketplaces
Captchas, Monero, Scams and absolutely no JavaScript
Mystery google.com certificate issued by Brazilian CA
https://ift.tt/NVRTPfZ
Submitted December 02, 2024 at 05:09AM by riking27
via reddit https://ift.tt/8XJHjMd
https://ift.tt/NVRTPfZ
Submitted December 02, 2024 at 05:09AM by riking27
via reddit https://ift.tt/8XJHjMd
bugzilla.mozilla.org
1934361 - ICP-Brasil: Mis-issued certificate
UNCONFIRMED (nobody) in CA Program - CA Certificate Compliance. Last updated 2024-12-01.
Cybercriminals Use NFC Relay to Turn Stolen Credit Cards into Cash without a PIN
https://ift.tt/thmEVyg
Submitted December 02, 2024 at 05:26PM by barakadua131
via reddit https://ift.tt/XJBaf0r
https://ift.tt/thmEVyg
Submitted December 02, 2024 at 05:26PM by barakadua131
via reddit https://ift.tt/XJBaf0r
Mobile Hacker
Cybercriminals Use NFC Relay to Turn Stolen Credit Cards into Cash without a PIN Mobile Hacker
ThreatFabric has identified a new cash-out tactic that wasn’t seen before called “Ghost Tap”, which cybercriminals use to exploit stolen credit card details linked to mobile payment services like Google Pay and Apple Pay. This method involves relaying NFC…
Research: Automated attacks defeats secrets rotation
https://go.clut.ch/m7t
Submitted December 02, 2024 at 07:37PM by galchock
via reddit https://ift.tt/OcVmCK0
https://go.clut.ch/m7t
Submitted December 02, 2024 at 07:37PM by galchock
via reddit https://ift.tt/OcVmCK0
Clutch Security
Clutch - The Day We Unveiled the Secret Rotation Illusion
Learn how Clutch Security debunked the myth of secret rotation with evidence-based research, revealing how attackers exploit exposed Non-Human Identities in seconds. Discover why traditional practices fall short and how Zero Trust and ephemeral identities…
Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges
https://ift.tt/rc1FmBP
Submitted December 03, 2024 at 02:29AM by WiseTuna
via reddit https://ift.tt/E5scOKW
https://ift.tt/rc1FmBP
Submitted December 03, 2024 at 02:29AM by WiseTuna
via reddit https://ift.tt/E5scOKW
Boschko Security Blog
Breaking Down Adversarial Machine Learning Attacks Through AI/ML Red Team Challenges
Explore adversarial attacks on AI/ML models through hands-on challenges on Dreadnode’s Crucible CTF platform.