Netsec – Telegram
Netsec
7.49K subscribers
22.5K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Bugcrowd LevelUp 0x03 2019 YouTube Playlist
https://www.youtube.com/playlist?list=PLIK9nm3mu-S61oMP7pie5d2t1Aah41Fji

Submitted January 24, 2019 at 12:28PM by Cabbage-Guy
via reddit http://bit.ly/2WmoTIK
Magento 2.2.6 / 2.1.15 RCE and local file read
http://bit.ly/2RcFudY

Submitted January 24, 2019 at 11:02PM by Blaklis
via reddit http://bit.ly/2FXGSPV
A brazilian academic researcher's BGP "research" triggered a bug in FRR twice (jan 8 and jan 23), knocking routers around the world offline
http://bit.ly/2DyC01Z

Submitted January 24, 2019 at 10:42PM by merreborn
via reddit http://bit.ly/2S9t5Ms
SSHtranger Things: OpenSSH scp arbitrary file write PoC (CVE-2019-6111)
Disclosure: https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtPoC Announcement: https://mobile.twitter.com/HyperionGray/status/1086011569417392129PoC Code: https://gist.github.com/mehaase/63e45c17bdbbd59e8e68d02ec58f4ca2Vulnerable versions of scp do not verify the filenames sent by the server, allowing a malicious server to overwrite unintended files. Scp also prints the server's stderr stream without any sanitization, allowing the server to send ANSI codes to cover up the transfer of the malicious file. This is unpatched in Ubuntu 18.04 LTS as well as other major distros. One user on Twitter says that it won't be fixed at all in RHEL 5/6.This demo shows a user requesting `file.txt` and the server sends `file.txt` followed by `exploit.txt`, then sends ANSI commands to move the cursor so that the transfer of `exploit.txt` is concealed.SSHtranger Things PoC DemoLet us know if you would be interested in a more detailed writeup!

Submitted January 23, 2019 at 11:37PM by hyperiongray
via reddit http://bit.ly/2FW0rrQ
Bash post-exploitation tool for Linux
http://bit.ly/2SEuqI5

Submitted January 24, 2019 at 09:53PM by bellthief
via reddit http://bit.ly/2RKNubr
A tool to find subdomains and interesting things like secrets hidden inside, external Javanoscript files of page, and Github.
http://bit.ly/2V085Xf

Submitted January 25, 2019 at 06:54PM by nsonaniya2010
via reddit http://bit.ly/2S6Jj9c
Magento – RCE & Local File Read with low privilege admin rights
http://bit.ly/2RcFudY

Submitted January 25, 2019 at 07:58PM by cbolat
via reddit http://bit.ly/2MvHqO4