Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ pfSense Security: Sensing Code Vulnerabilities

Attackers can combine the vulnerabilities to execute arbitrary code on the pfSense appliance remotely. An attacker can trick an authenticated pfSense user into clicking on a maliciously crafted link containing an XSS payload that exploits the command injection vulnerability:

https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
📢 serversAwesome

In OpenBLD.net scoping activities, I created lite Go app - Awesome Servers Inventory Web App, which is a simple web app to manage your servers inventory. Ideal solution for small projects and infrastructures or IT ecosystems.

Features:

- Add new server
- Edit existing server
- Delete existing server
- Copy server IP details to clipboard
- Yaml config file
- Portable sqLite database
- One binary file to run the app

- https://github.com/m0zgen/serversAwesome
Please open Telegram to view this post
VIEW IN TELEGRAM
/ Exploiting JetBrains TeamCity CVE Globally

CISA warns:

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
Открытый практикум DevOps by Rebrain: Репликация postgresql

Детали

Время:

• 20 Декабря (Среда) 20:00 МСК.
Программа:

• Чем хорош posgresql?
• Что такое vacuum?
• Настройка физической репликации

Ведёт:

Андрей Буранов – Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.
/ OpenSSH 9.6 release contains a number of security fixes, includes MiTM "Terrain attack"fix:

https://www.openssh.com/releasenotes.html
/ Mozilla Foundation Security Advisory (with fixing RCE)

https://www.mozilla.org/en-US/security/advisories/mfsa2023-56/
📢 Открытый практикум DevOps by Rebrain: IT-Quiz

Регистрация

Время:

26 Декабря (Вторник) в 19:00 по МСК

Программа:

• Решаем 3 задачки в онлайн-формате
• Получаем подарки за выполнение заданий
• Проводим розыгрыш New Year Sale by Rebrain

Ведёт:

Василий Озеров – Co-Founder REBRAIN. Руководит международной командой в рамках своего агентства Fevlake. Более 8 лет Devops практик.
/ The Cashback Extension Killer - Fake Chrome netPlus VPN Extensions

C2 domain target communications - Kazakhstan, Ukraine, Russia, Belarus, Pakistan...

https://reasonlabs.com/research/the-cashback-extension-killer

P.S. C2 domains already sended to OpenBLD.net 😡
Please open Telegram to view this post
VIEW IN TELEGRAM
/ use-after-free vulnerability in the implementation in Linux kernel nf_tables

Openwall note: https://www.openwall.com/lists/oss-security/2023/12/22/6

Exploit prototype - https://www.openwall.com/lists/oss-security/2023/12/22/6/1
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
This media is not supported in your browser
VIEW IN TELEGRAM
🚀 Glad to present the new release zDNS v0.1.3! 🎉

Following Zero Trust practices, I recently wrote and am slowly beginning to introduce new “blackhole” functionality into the OpenBLD.net DNS ecosystem

zDNS is a DNS server that puts security and control over DNS queries at the center. With new functionality, zDNS now supports regular expressions in hosts.txt files, allowing more flexibility in configuring allowed queries. Now you can use the power of regular expressions to precisely control permissions, including subdomains and patterns.

Main features:

🛑 Denies all DNS queries by default.
Allows you to configure allowed requests through the hosts.txt file.
🔄 Uses balancing strategies to ensure reliable operation with DNS servers.
🛠Easily customizable via YAML configuration.
🔜 Prometheus metrics coming soon

Additional protection of your infrastructure or testing requests with zDNS is possible and may be useful to you! Download the latest version here and start using a DNS server with powerful customization options:

https://github.com/m0zgen/zdns/tree/dev

#zDNS #DNS #Security #Release #News
Let’s Get Ready to Rumble!!

Let the leap year 🎄 bring only high profits and high success!)) Peace ✌️
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
Open Thank You Message.

First of all, thanks to all users of the OpenBLD.net service. Thank you for trusting, service using, contributing and providing feedback.

Some companies, like the people in them, also trust the service and support it with system resources and OSS licenses, which allows the service to grow, be faster, and expand points of presence around the world.

Thanks everyone. I also wrote an Open Tnak You Letter in my blog post to everyone who supported.

Everyone who wants to support, add their logo or name to the project website, support the OpenBLD.net project and receive this benefits.

Peace to all ✌️