How to Create Vulnerable-Looking Endpoints to Detect and Mislead Attackers
https://ift.tt/IV0U8Y9
Submitted January 16, 2025 at 10:29PM by utku1337
via reddit https://ift.tt/Qs8TcKD
https://ift.tt/IV0U8Y9
Submitted January 16, 2025 at 10:29PM by utku1337
via reddit https://ift.tt/Qs8TcKD
Utku Sen’s Substack
How to Create Vulnerable-Looking Endpoints to Detect and Mislead Attackers
BaitRoute is a web honeypot project that serves realistic, vulnerable-looking endpoints to detect vulnerability scans and mislead attackers by providing false positive results.
PoC for CVE-2025-0282 published (Ivanti Connect Secure stack bof)
https://ift.tt/VWJ3F49
Submitted January 16, 2025 at 10:23PM by Acceptable_Exit_9695
via reddit https://ift.tt/tIGxZEB
https://ift.tt/VWJ3F49
Submitted January 16, 2025 at 10:23PM by Acceptable_Exit_9695
via reddit https://ift.tt/tIGxZEB
AttackerKB
CVE-2025-0282 | AttackerKB
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gatewa…
Microsoft Configuration Manager (ConfigMgr / SCCM) 2403 Unauthenticated SQL injections (CVE-2024-43468)
https://ift.tt/KjruZdC
Submitted January 16, 2025 at 11:59PM by AlmondOffSec
via reddit https://ift.tt/eSZLkhR
https://ift.tt/KjruZdC
Submitted January 16, 2025 at 11:59PM by AlmondOffSec
via reddit https://ift.tt/eSZLkhR
Synacktiv
Microsoft Configuration Manager (ConfigMgr) 2403 Unauthenticated SQL injections
The Role of Emulators in OT Research
https://ift.tt/ekGw84y
Submitted January 17, 2025 at 12:56AM by derp6996
via reddit https://ift.tt/1Q8WSmx
https://ift.tt/ekGw84y
Submitted January 17, 2025 at 12:56AM by derp6996
via reddit https://ift.tt/1Q8WSmx
A publicly available OpenCTI connector for IoC analysis FOSS tool
https://ift.tt/qOPuInz
Submitted January 17, 2025 at 02:04AM by stan_frbd
via reddit https://ift.tt/Mrlm5jU
https://ift.tt/qOPuInz
Submitted January 17, 2025 at 02:04AM by stan_frbd
via reddit https://ift.tt/Mrlm5jU
Finding SSRFs in Azure DevOps
https://ift.tt/TMr8OJD
Submitted January 17, 2025 at 02:23PM by cbagdude
via reddit https://ift.tt/hHa3CuW
https://ift.tt/TMr8OJD
Submitted January 17, 2025 at 02:23PM by cbagdude
via reddit https://ift.tt/hHa3CuW
Binary Security AS
Finding SSRFs in Azure DevOps
Binary Security found three SSRF vulnerabilities in Azure DevOps that we reported to Microsoft. This blog post outlines the way we identified these vulnerabilities, and demonstrates exploitation techniques using DNS rebinding and CRLF injection.
Bypassing disk encryption on systems with automatic TPM2 unlock
https://ift.tt/DTzFu1B
Submitted January 17, 2025 at 02:13PM by moviuro
via reddit https://ift.tt/xXlEiAw
https://ift.tt/DTzFu1B
Submitted January 17, 2025 at 02:13PM by moviuro
via reddit https://ift.tt/xXlEiAw
oddlama.org
Bypassing disk encryption on systems with automatic TPM2
unlock | oddlama's blog
unlock | oddlama's blog
oddlama's personal web page and blog
Windows BitLocker -- Screwed without a Screwdriver
https://ift.tt/UByKj0n
Submitted January 19, 2025 at 11:38PM by Titokhan
via reddit https://ift.tt/XQAPz1p
https://ift.tt/UByKj0n
Submitted January 19, 2025 at 11:38PM by Titokhan
via reddit https://ift.tt/XQAPz1p
neodyme.io
Windows BitLocker -- Screwed without a Screwdriver
Breaking up-to-date Windows 11 BitLocker encryption -- on-device but software-only
Let’s talk about AI and end-to-end encryption
https://ift.tt/q56N1VH
Submitted January 20, 2025 at 09:45AM by feross
via reddit https://ift.tt/k0uNOMQ
https://ift.tt/q56N1VH
Submitted January 20, 2025 at 09:45AM by feross
via reddit https://ift.tt/k0uNOMQ
A Few Thoughts on Cryptographic Engineering
Let’s talk about AI and end-to-end encryption
Recently I came across a fantastic new paper by a group of NYU and Cornell researchers ennoscriptd “How to think about end-to-end encryption and AI.” I’m extremely grateful to see th…
Tear Down The Castle - Part 1 | dfir.ch
https://ift.tt/rBWaOsM
Submitted January 20, 2025 at 06:09PM by Capable_General_7219
via reddit https://ift.tt/uROLNI4
https://ift.tt/rBWaOsM
Submitted January 20, 2025 at 06:09PM by Capable_General_7219
via reddit https://ift.tt/uROLNI4
dfir.ch
Tear Down The Castle - Part 1 | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
Malware Analysis of Fake Banking Reward APK Targeting WhatsApp Users
https://ift.tt/x1T3L46
Submitted January 20, 2025 at 09:04PM by anuraggawande
via reddit https://ift.tt/oyrmb6O
https://ift.tt/x1T3L46
Submitted January 20, 2025 at 09:04PM by anuraggawande
via reddit https://ift.tt/oyrmb6O
Malware Analysis, Phishing, and Email Scams
Fake SBI Reward APK Targets Victims with Trojan via WhatsApp
Cybercriminals continue to exploit unsuspecting users through cleverly crafted phishing campaigns. Recently, I encountered a forwarded message in a WhatsApp group that immediately raised suspicion.…
The cost of false positives - how we became a target
https://ift.tt/xPY1LOS
Submitted January 20, 2025 at 09:32PM by unknownhad
via reddit https://ift.tt/ZVEMDBj
https://ift.tt/xPY1LOS
Submitted January 20, 2025 at 09:32PM by unknownhad
via reddit https://ift.tt/ZVEMDBj
cside
The cost of false positives - how we became a target
This week, we identified an intriguing use case involving the WP3[.]XYZ attack (link to our blog post). It sparked interest across the community and led to better detection rates on platforms like VirusTotal (VirusTotal link).
While most appreciated our…
While most appreciated our…
v0.1.0 released - Analyze IoC with OpenCTI, Threat fox and more #FOSS
https://cyberbro.net/
Submitted January 20, 2025 at 11:34PM by stan_frbd
via reddit https://ift.tt/tN0lRJ2
https://cyberbro.net/
Submitted January 20, 2025 at 11:34PM by stan_frbd
via reddit https://ift.tt/tN0lRJ2
Reddit
From the netsec community on Reddit: v0.1.0 released - Analyze IoC with OpenCTI, Threat fox and more #FOSS
Posted by stan_frbd - 5 votes and 0 comments
Reverse Engineering Call Of Duty Anti-Cheat
https://ift.tt/W6xndoq
Submitted January 21, 2025 at 03:33PM by AlmondOffSec
via reddit https://ift.tt/VpumwJ4
https://ift.tt/W6xndoq
Submitted January 21, 2025 at 03:33PM by AlmondOffSec
via reddit https://ift.tt/VpumwJ4
ssno
Reverse Engineering Call Of Duty Anti-Cheat
I’ve been reversing Black Ops Cold War for a while now, and I’ve finally decided to share my research regarding the user-mode anti-cheat inside the game. It’s not my intention to shame or promote cheating/bypassing of the anti-cheat, so I’ve redacted a few…
Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions
https://ift.tt/VcfK4U8
Submitted January 21, 2025 at 05:44PM by buherator
via reddit https://ift.tt/qm2r8Fu
https://ift.tt/VcfK4U8
Submitted January 21, 2025 at 05:44PM by buherator
via reddit https://ift.tt/qm2r8Fu
Silent Signal Techblog
Vulnerability Archeology: Stealing Passwords with IBM i Access Client Solutions
Because we can!
NaN Of Your Business - My Favorite Unintended CTF Solution
https://ift.tt/gHN7Uz0
Submitted January 21, 2025 at 08:50PM by mdulin2
via reddit https://ift.tt/eq2iIrS
https://ift.tt/gHN7Uz0
Submitted January 21, 2025 at 08:50PM by mdulin2
via reddit https://ift.tt/eq2iIrS
Strikeout Security Blog
NaN Of Your Business - My Favorite Unintended CTF Solution
Floats in C are weird. Floating point number rounding and NaN shenanigans to bypass security protections.
Next.js, cache, and chains: the stale elixir
https://ift.tt/UlQ1OIr
Submitted January 22, 2025 at 02:50PM by albinowax
via reddit https://ift.tt/2wncPT7
https://ift.tt/UlQ1OIr
Submitted January 22, 2025 at 02:50PM by albinowax
via reddit https://ift.tt/2wncPT7
Pivot into Azure DevOps using stolen sessions
https://ift.tt/cksmg1S
Submitted January 22, 2025 at 08:06PM by rikvduijn
via reddit https://ift.tt/8y1UKQJ
https://ift.tt/cksmg1S
Submitted January 22, 2025 at 08:06PM by rikvduijn
via reddit https://ift.tt/8y1UKQJ
Zolder - Applied Security Research
DevOps access is closer than you assume | Zolder - Applied Security Research
Azure DevOps is important to many organizations. Pivoting from a stolen session to DevOps access is closer than you think.
Testing Prompt Injection Attacks with promptmap2
https://ift.tt/mpHvtE1
Submitted January 22, 2025 at 08:45PM by utku1337
via reddit https://ift.tt/DfIbXlk
https://ift.tt/mpHvtE1
Submitted January 22, 2025 at 08:45PM by utku1337
via reddit https://ift.tt/DfIbXlk
Utku Sen’s Substack
Testing Prompt Injection Attacks with promptmap2
promptmap2 is a vulnerability scanning tool that automatically tests prompt injection attacks on your custom LLM applications
Stealing HttpOnly cookies with the cookie sandwich technique
https://ift.tt/QqsI6XY
Submitted January 23, 2025 at 12:03AM by AlmondOffSec
via reddit https://ift.tt/8Mfqm7o
https://ift.tt/QqsI6XY
Submitted January 23, 2025 at 12:03AM by AlmondOffSec
via reddit https://ift.tt/8Mfqm7o
PortSwigger Research
Stealing HttpOnly cookies with the cookie sandwich technique
In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
Attacks on Maven proxy repositories
https://ift.tt/wvrO2Jm
Submitted January 22, 2025 at 11:33PM by artsploit
via reddit https://ift.tt/Wkj2ziM
https://ift.tt/wvrO2Jm
Submitted January 22, 2025 at 11:33PM by artsploit
via reddit https://ift.tt/Wkj2ziM
The GitHub Blog
Attacks on Maven proxy repositories
Learn how specially crafted artifacts can be used to attack Maven repository managers. This post describes PoC exploits that can lead to pre-auth remote code execution and poisoning of the local artifacts in Sonatype Nexus and JFrog Artifactory.