SMB3 Kernel Server (ksmbd) fuzzing and vulns
https://ift.tt/60sF7cH
Submitted January 07, 2025 at 09:15PM by nibblesec
via reddit https://ift.tt/jJcKe7T
https://ift.tt/60sF7cH
Submitted January 07, 2025 at 09:15PM by nibblesec
via reddit https://ift.tt/jJcKe7T
Scanning the Entire Internet on Port 80
https://ift.tt/1fqS23t
Submitted January 07, 2025 at 10:01PM by DaSapien
via reddit https://ift.tt/OPkW4ro
https://ift.tt/1fqS23t
Submitted January 07, 2025 at 10:01PM by DaSapien
via reddit https://ift.tt/OPkW4ro
RedHunt Labs
Open Port Chronicle: What Port 80 Revealed About The Internet (Wave 12)
Explore what Port 80 revealed about the internet in Project Resonance (Wave 12) and the insights gained from this key web traffic gateway.
SYN Spoof Scanner - a simple tool to perform SYN port scan with spoofed source IPs for offensive deception
https://ift.tt/cnOFNw4
Submitted January 08, 2025 at 02:02PM by eitot8
via reddit https://ift.tt/IwZBOHe
https://ift.tt/cnOFNw4
Submitted January 08, 2025 at 02:02PM by eitot8
via reddit https://ift.tt/IwZBOHe
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Help Net Security - A FOSS tool to analyse IOC
https://ift.tt/Re1ldvO
Submitted January 08, 2025 at 05:14PM by stan_frbd
via reddit https://ift.tt/cGqVLT7
https://ift.tt/Re1ldvO
Submitted January 08, 2025 at 05:14PM by stan_frbd
via reddit https://ift.tt/cGqVLT7
Help Net Security
Cyberbro: Open-source tool extracts IoCs and checks their reputation
Cyberbro is an open-source application that extracts IoCs from garbage input and checks their reputation using multiple services.
Backdooring Your Backdoors - Another $20 Domain, More Governments - watchTowr Labs
https://ift.tt/OESkp87
Submitted January 08, 2025 at 04:42PM by dx7r__
via reddit https://ift.tt/uLcQ4P1
https://ift.tt/OESkp87
Submitted January 08, 2025 at 04:42PM by dx7r__
via reddit https://ift.tt/uLcQ4P1
watchTowr Labs
Backdooring Your Backdoors - Another $20 Domain, More Governments
After the excitement of our .MOBI research, we were left twiddling our thumbs. As you may recall, in 2024, we demonstrated the impact of an unregistered domain when we subverted the TLS/SSL CA process for verifying domain ownership to give ourselves the ability…
Magic/Tragic Email Links: Don't make them the only option
https://ift.tt/MKj74SN
Submitted January 08, 2025 at 07:46PM by gepeto42
via reddit https://ift.tt/dTQvDmq
https://ift.tt/MKj74SN
Submitted January 08, 2025 at 07:46PM by gepeto42
via reddit https://ift.tt/dTQvDmq
Recyclebin.zip
Magic/Tragic Email Links: Don't make them the only option
Subnoscription websites now like to use magic email links for login. They are extremely annoying.
Top 10 web hacking techniques of 2024: nominations open
https://ift.tt/FPNMx2X
Submitted January 09, 2025 at 01:56PM by nibblesec
via reddit https://ift.tt/i9lcE0p
https://ift.tt/FPNMx2X
Submitted January 09, 2025 at 01:56PM by nibblesec
via reddit https://ift.tt/i9lcE0p
PortSwigger Research
Top 10 web hacking techniques of 2024: nominations open
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
Bypassing File Upload Restrictions To Exploit Client-Side Path Traversal (CSPT, CSPT2CSRF)
https://ift.tt/zsRUZSF
Submitted January 09, 2025 at 01:55PM by nibblesec
via reddit https://ift.tt/rGZFt4a
https://ift.tt/zsRUZSF
Submitted January 09, 2025 at 01:55PM by nibblesec
via reddit https://ift.tt/rGZFt4a
Abuse a time-based SQL injection by customizing SQLMAP
https://ift.tt/0UL1Cp3
Submitted January 09, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/aIcgYVj
https://ift.tt/0UL1Cp3
Submitted January 09, 2025 at 03:01PM by Hackmosphere
via reddit https://ift.tt/aIcgYVj
Hackmosphere
Time-based Blind SQL Injection et modification de SQLMAP
Time-based blind SQL injection : Découvrez comment cette faille se distingue par sa capacité à exfiltrer des données sans activer d'alerte.
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
https://ift.tt/O3sXyxv
Submitted January 09, 2025 at 09:40PM by albinowax
via reddit https://ift.tt/fpmaE8N
https://ift.tt/O3sXyxv
Submitted January 09, 2025 at 09:40PM by albinowax
via reddit https://ift.tt/fpmaE8N
Orange Tsai
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
Do Secure-By-Design Pledges Come With Stickers? - Ivanti Connect Secure RCE (CVE-2025-0282) - watchTowr Labs
https://ift.tt/AkXehRK
Submitted January 10, 2025 at 07:05AM by dx7r__
via reddit https://ift.tt/Dsd54np
https://ift.tt/AkXehRK
Submitted January 10, 2025 at 07:05AM by dx7r__
via reddit https://ift.tt/Dsd54np
watchTowr Labs
Do Secure-By-Design Pledges Come With Stickers? - Ivanti Connect Secure RCE (CVE-2025-0282)
Did you have a good break? Have you had a chance to breathe? Wake up.
It’s 2025, and the chaos continues.
Haha, see what we did? We wrote the exact same thing in 2024 because 2024 was exactly the same.
As an industry, we are on GroundHog day -
It’s 2025, and the chaos continues.
Haha, see what we did? We wrote the exact same thing in 2024 because 2024 was exactly the same.
As an industry, we are on GroundHog day -
Exploiting SSTI in a Modern Spring Boot Application (3.3.4)
https://ift.tt/KwxzvGp
Submitted January 10, 2025 at 02:18PM by parzel
via reddit https://ift.tt/9ONDTJR
https://ift.tt/KwxzvGp
Submitted January 10, 2025 at 02:18PM by parzel
via reddit https://ift.tt/9ONDTJR
Modzero
Exploiting SSTI in a Modern Spring Boot Application (3.3.4) / modzero
How to jailbreak most/all LLMs using Assistant Prefill
https://ift.tt/iaTDkfg
Submitted January 10, 2025 at 08:53PM by Ok_Information1453
via reddit https://ift.tt/Q0MCHJn
https://ift.tt/iaTDkfg
Submitted January 10, 2025 at 08:53PM by Ok_Information1453
via reddit https://ift.tt/Q0MCHJn
Invicti
First Tokens: The Achilles’ Heel of LLMs
The Assistant Prefill feature available in many LLMs can open up models to jailbreaking, including the possibility of persistent prefills to bypass LLM safety alignments.
ACE up the sleeve: Hacking into Apple's new USB-C Controller
https://ift.tt/jRH3PGT
Submitted January 10, 2025 at 11:01PM by Titokhan
via reddit https://ift.tt/IrsTEPg
https://ift.tt/jRH3PGT
Submitted January 10, 2025 at 11:01PM by Titokhan
via reddit https://ift.tt/IrsTEPg
media.ccc.de
ACE up the sleeve:
With the iPhone 15 & iPhone 15 Pro, Apple switched their iPhone to USB-C and introduced a new USB-C controller: The ACE3, a powerful, ver...
Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit.
https://ift.tt/czW2fXb
Submitted January 11, 2025 at 06:02AM by LordAlfredo
via reddit https://ift.tt/gHhw7fW
https://ift.tt/czW2fXb
Submitted January 11, 2025 at 06:02AM by LordAlfredo
via reddit https://ift.tt/gHhw7fW
奇安信 X 实验室
Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit.
Overview
Countless noscript kiddies, dreaming of getting rich, rush into the DDoS black-market industry armed with Mirai source code, imagining they can make a fortune with botnets. Reality, however, is harsh—these individuals arrive full of ambition but…
Countless noscript kiddies, dreaming of getting rich, rush into the DDoS black-market industry armed with Mirai source code, imagining they can make a fortune with botnets. Reality, however, is harsh—these individuals arrive full of ambition but…
$2m laundered: the YouTube crypto tutorials’ huge scam (investigation)
https://ift.tt/Fn5pRof
Submitted January 12, 2025 at 02:03AM by WesternBest
via reddit https://ift.tt/NRty7ol
https://ift.tt/Fn5pRof
Submitted January 12, 2025 at 02:03AM by WesternBest
via reddit https://ift.tt/NRty7ol
Medium
$2m laundered: the YouTube crypto tutorials’ huge scam (investigation)
How 1 youtube video turned out to be a part of a million dollar scam scheme
Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282) - watchTowr Labs
https://ift.tt/8HvujdE
Submitted January 12, 2025 at 02:25PM by dx7r__
via reddit https://ift.tt/ohxFCDN
https://ift.tt/8HvujdE
Submitted January 12, 2025 at 02:25PM by dx7r__
via reddit https://ift.tt/ohxFCDN
watchTowr Labs
Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)
As we saw in our previous blogpost, we fully analyzed Ivanti’s most recent unauthenticated Remote Code Execution vulnerability in their Connect Secure (VPN) appliance. Specifically, we analyzed CVE-2025-0282.
Today, we’re going to walk through exploitation.…
Today, we’re going to walk through exploitation.…
Fireblocks Black Box Security Review
https://ift.tt/ku1EIqp
Submitted January 13, 2025 at 09:05PM by arrowflakes
via reddit https://ift.tt/nvxbMok
https://ift.tt/ku1EIqp
Submitted January 13, 2025 at 09:05PM by arrowflakes
via reddit https://ift.tt/nvxbMok
CoinFabrik
Fireblocks API Black Box Review | Findings Summary
Discover the new Fireblocks API Black Box review performed by CoinFabrik for a detailed analysis of its security and performance.
Threat actors exploit a probable 0-day in exposed management consoles of Fortinet FortiGate firewalls
https://ift.tt/qJBeHFX
Submitted January 14, 2025 at 03:30PM by liamnotrop
via reddit https://ift.tt/7SLVIvP
https://ift.tt/qJBeHFX
Submitted January 14, 2025 at 03:30PM by liamnotrop
via reddit https://ift.tt/7SLVIvP
Orangecyberdefense
0-day in exposed management consoles of Fortinet FortiGate firewalls
A recent campaign targeting FortiGate firewalls, where the devices’ management interfaces exposed to the Internet were compromised.
Over 5,000 WordPress sites caught in WP3.XYZ malware attack
https://ift.tt/A23YfaM
Submitted January 14, 2025 at 06:17PM by unknownhad
via reddit https://ift.tt/28uvcUn
https://ift.tt/A23YfaM
Submitted January 14, 2025 at 06:17PM by unknownhad
via reddit https://ift.tt/28uvcUn
cside
Over 5,000 WordPress sites caught in WP3[.]XYZ malware attack
We’ve uncovered a widespread malware campaign targeting WordPress websites, affecting over 5,000 sites globally.
The malicious domain: "https://wp3.xyz/plugin[.]php".
The malicious domain: "https://wp3.xyz/plugin[.]php".
Story of a Pentester Recruitment 2025
https://ift.tt/4VlcPiv
Submitted January 14, 2025 at 07:33PM by buherator
via reddit https://ift.tt/Gt4giUe
https://ift.tt/4VlcPiv
Submitted January 14, 2025 at 07:33PM by buherator
via reddit https://ift.tt/Gt4giUe
Silent Signal Techblog
Story of a Pentester Recruitment 2025
Because we can!