Practising Heap Exploitation: Using House Of Force Technique with Practicals
https://ift.tt/LGO5g4c
Submitted January 30, 2025 at 06:20PM by Altrntiv-to-security
via reddit https://ift.tt/DIQHvCS
https://ift.tt/LGO5g4c
Submitted January 30, 2025 at 06:20PM by Altrntiv-to-security
via reddit https://ift.tt/DIQHvCS
DarkRelay
Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique
Heap exploitation techniques like House of Force demonstrate the complexities and risks associated with memory management systems.
WebAssembly and security: a review
https://ift.tt/7goO3s9
Submitted January 30, 2025 at 07:40PM by daindragon2
via reddit https://ift.tt/LUb4CAf
https://ift.tt/7goO3s9
Submitted January 30, 2025 at 07:40PM by daindragon2
via reddit https://ift.tt/LUb4CAf
CVE-2024-46506: Unauthenticated RCE in NetAlertx
https://ift.tt/nwI187Z
Submitted January 30, 2025 at 11:21PM by hackers_and_builders
via reddit https://ift.tt/PjS4yAc
https://ift.tt/nwI187Z
Submitted January 30, 2025 at 11:21PM by hackers_and_builders
via reddit https://ift.tt/PjS4yAc
Rhino Security Labs
CVE-2024-46506: Unauthenticated RCE in NetAlertx
NetAlertX is an open-source Wi-Fi / Local Area Network (LAN) intruder detector that scans for devices connected to your network and alerts you if new and unknown devices are found.
The Slow Death of OCSP
https://ift.tt/XMUB1wn
Submitted January 31, 2025 at 01:06AM by ScottContini
via reddit https://ift.tt/OdQawIY
https://ift.tt/XMUB1wn
Submitted January 31, 2025 at 01:06AM by ScottContini
via reddit https://ift.tt/OdQawIY
CRLF injection via TryAddWithoutValidation in .NET
https://ift.tt/cHNiEeQ
Submitted January 31, 2025 at 02:24PM by cbagdude
via reddit https://ift.tt/SjJNHTk
https://ift.tt/cHNiEeQ
Submitted January 31, 2025 at 02:24PM by cbagdude
via reddit https://ift.tt/SjJNHTk
Binary Security AS
CRLF injection via TryAddWithoutValidation in .NET
Binary Security was awarded two CVEs (CVE-2024-45302 and CVE-2024-51501) for header injection vulnerabilities in the RestSharp and Refit .NET libraries. This blog post outlines the research which lead to discovering these vulnerabilities.
RCE (LAN) in Marvel Rivals
https://ift.tt/4ZsbzcY
Submitted January 31, 2025 at 04:36PM by shalzuth
via reddit https://ift.tt/EqzIcuo
https://ift.tt/4ZsbzcY
Submitted January 31, 2025 at 04:36PM by shalzuth
via reddit https://ift.tt/EqzIcuo
Shalzuth
Reverse Engineering: I Found a Game Exploit That Lets Hackers Take Over Your PC
Reverse Engineering: I discovered a serious Remote Code Execution (RCE) vulnerability in a popular game that could let attackers run code on your PC. Watch how I found it, reported it, and what you can do to stay safe.
Cisco Webex Connect - Unauthenticated access to all chats
https://ift.tt/c6TPsEW
Submitted January 31, 2025 at 04:06PM by albinowax
via reddit https://ift.tt/JgWzEI9
https://ift.tt/c6TPsEW
Submitted January 31, 2025 at 04:06PM by albinowax
via reddit https://ift.tt/JgWzEI9
Ophionsecurity
Live Chat Blog #2: Cisco Webex Connect - Access to millions of chats histories - Ophion Security Publications
In July 2024, we identified a vulnerability that resulted in access to millions of live customer support messages for organizations using Cisco Webex Connect.
SlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in Slack
https://ift.tt/EkfBvto
Submitted January 31, 2025 at 10:44PM by Rooftoptile2
via reddit https://ift.tt/AzBeSOf
https://ift.tt/EkfBvto
Submitted January 31, 2025 at 10:44PM by Rooftoptile2
via reddit https://ift.tt/AzBeSOf
Medium
SlackPirate Set Sails Again! Or: How to Send the Entire “Bee Movie” Script to Your Friends in Slack
TLDR: SlackPirate has been defunct for a few years due to a breaking change in how the Slack client interacts with the Slack API. It has a…
Everyone knows your location: tracking myself down through in-app ads
https://ift.tt/LG8SU0C
Submitted February 01, 2025 at 03:24PM by WesternBest
via reddit https://ift.tt/XAzUD1o
https://ift.tt/LG8SU0C
Submitted February 01, 2025 at 03:24PM by WesternBest
via reddit https://ift.tt/XAzUD1o
tim.sh
Everyone knows your location
How I tracked myself down using leaked location data in the in-app ads, and what I found along the way.
Speculation Attacks on Apple M3: SLAP and FLOP
https://ift.tt/pxAlyc8
Submitted February 02, 2025 at 06:19PM by alodiasaradith07
via reddit https://ift.tt/yGHrD2n
https://ift.tt/pxAlyc8
Submitted February 02, 2025 at 06:19PM by alodiasaradith07
via reddit https://ift.tt/yGHrD2n
predictors.fail
SLAP and FLOP
The SLAP and FLOP Address and Value Prediction Attacks
How Attackers Can Bypass OPA Gatekeeper in Kubernetes Due to Rego Flaws
https://ift.tt/SN73Huz
Submitted February 03, 2025 at 11:33PM by Pale_Fly_2673
via reddit https://ift.tt/UnvfYjy
https://ift.tt/SN73Huz
Submitted February 03, 2025 at 11:33PM by Pale_Fly_2673
via reddit https://ift.tt/UnvfYjy
Aqua
OPA Gatekeeper Bypass Reveals Risks in Kubernetes Policy Engines
Research on Kubernetes policy enforcement risks and how misconfigurations in seemingly secure rules like OPA Gatekeeper enable bypassing.
Ransomware Groups Exploiting Microsoft Teams
https://ift.tt/zsiD3yL
Submitted February 04, 2025 at 12:20AM by Willsec
via reddit https://ift.tt/vsQfamn
https://ift.tt/zsiD3yL
Submitted February 04, 2025 at 12:20AM by Willsec
via reddit https://ift.tt/vsQfamn
GoSecure
24/7 managed detection, response, and expert cybersecurity services - GoSecure
We provide around-the-clock threat detection and incident response, backed by expert consulting to keep your organization secure.
Masquerade the Windows "Program Files" path with Unicode "En Quad" character.
https://ift.tt/IuWdVAM
Submitted February 04, 2025 at 08:30AM by Cold-Dinosaur
via reddit https://ift.tt/zmVNtfQ
https://ift.tt/IuWdVAM
Submitted February 04, 2025 at 08:30AM by Cold-Dinosaur
via reddit https://ift.tt/zmVNtfQ
Zerosalarium
Path masquerading: Hide in plain sight
Utilizing the new technique of Path Masquerading to spoof malicious processes to closely resemble those of antivirus/EDR programs.
8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur - watchTowr Labs
https://ift.tt/0I3Dw2O
Submitted February 04, 2025 at 04:32PM by dx7r__
via reddit https://ift.tt/qujtXcz
https://ift.tt/0I3Dw2O
Submitted February 04, 2025 at 04:32PM by dx7r__
via reddit https://ift.tt/qujtXcz
watchTowr Labs
8 Million Requests Later, We Made The SolarWinds Supply Chain Attack Look Amateur
Surprise surprise, we've done it again. We've demonstrated an ability to compromise significantly sensitive networks, including governments, militaries, space agencies, cyber security companies, supply chains, software development systems and environments…
Collabfiltrator 4.0.1 Plugin released! New SQLi DNS exfiltration capabilities available in BurpSuite. Download it from the BApp Store.
https://ift.tt/uBdDoCL
Submitted February 04, 2025 at 08:31PM by logueadam
via reddit https://ift.tt/aA0K5CO
https://ift.tt/uBdDoCL
Submitted February 04, 2025 at 08:31PM by logueadam
via reddit https://ift.tt/aA0K5CO
Top 10 (new) web hacking techniques of 2024
https://ift.tt/BZarKLq
Submitted February 04, 2025 at 09:32PM by albinowax
via reddit https://ift.tt/3AoIjgY
https://ift.tt/BZarKLq
Submitted February 04, 2025 at 09:32PM by albinowax
via reddit https://ift.tt/3AoIjgY
PortSwigger Research
Top 10 web hacking techniques of 2024
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
Now live: Our Global InfoSec Salary Index for 2025 - with full dataset in the Public Domain :)
https://ift.tt/fADBOt7
Submitted February 04, 2025 at 10:02PM by infosec-jobs
via reddit https://ift.tt/CPUW8LI
https://ift.tt/fADBOt7
Submitted February 04, 2025 at 10:02PM by infosec-jobs
via reddit https://ift.tt/CPUW8LI
foo🦍
foo🦍 ~/all coding
The career platform for coders, builders, hackers and makers.
Replacing a Space Heater Firmware over WiFi
https://ift.tt/i7RTnxw
Submitted February 05, 2025 at 03:28AM by 907jessejones
via reddit https://ift.tt/vyNmlDQ
https://ift.tt/i7RTnxw
Submitted February 05, 2025 at 03:28AM by 907jessejones
via reddit https://ift.tt/vyNmlDQ
Include Security Research Blog
Replacing a Space Heater Firmware Over WiFi - Include Security Research Blog
Our team hacks space heater firmware updates over wifi in the latest Include Security blog post. We break down, literally and figuratively, each step of the attack to demonstrate how anonymous users on the same wireless network as an affected space heater…
How to prove false statements? (Part 1)
https://ift.tt/0iBGfRz
Submitted February 05, 2025 at 03:15AM by feross
via reddit https://ift.tt/kzmItLM
https://ift.tt/0iBGfRz
Submitted February 05, 2025 at 03:15AM by feross
via reddit https://ift.tt/kzmItLM
A Few Thoughts on Cryptographic Engineering
How to prove false statements? (Part 1)
Trigger warning: incredibly wonky theoretical cryptography post (written by a non-theorist)! Also, this will be in two parts. I plan to be back with some more thoughts on practical stuff, like clou…
How to prove false statements? (Part 1)
https://ift.tt/P4eLVtT
Submitted February 05, 2025 at 04:01AM by feross
via reddit https://ift.tt/QnAE07S
https://ift.tt/P4eLVtT
Submitted February 05, 2025 at 04:01AM by feross
via reddit https://ift.tt/QnAE07S
A Few Thoughts on Cryptographic Engineering
How to prove false statements? (Part 1)
Trigger warning: incredibly wonky theoretical cryptography post (written by a non-theorist)! Also, this will be in two parts. I plan to be back with some more thoughts on practical stuff, like clou…
Certificate Transparency is now enforced in Firefox on desktop platforms starting with version 135
https://ift.tt/suLqtiO
Submitted February 05, 2025 at 09:17AM by Soatok
via reddit https://ift.tt/hGObDqP
https://ift.tt/suLqtiO
Submitted February 05, 2025 at 09:17AM by Soatok
via reddit https://ift.tt/hGObDqP