Open Sesame: Escalating Open Redirect to RCE with Electron Code Review
Despite the fact that the article is 2020, it was interesting...
https://spaceraccoon.dev/open-sesame-escalating-open-redirect-to-rce-with-electron-code-review
Despite the fact that the article is 2020, it was interesting...
https://spaceraccoon.dev/open-sesame-escalating-open-redirect-to-rce-with-electron-code-review
spaceraccoon.dev
Open Sesame: Escalating Open Redirect to RCE with Electron Code Review
This blog post will go through my whitebox review of an unnamed Electron application from a bug bounty program. I will demonstrate how I escalated an open redirect into remote code execution with the help of some debugging. Code samples have been modified…
Package Analysis
This repo contains a few components to aid in the analysis of open source packages, in particular to look for malicious software:
https://github.com/ossf/package-analysis
This repo contains a few components to aid in the analysis of open source packages, in particular to look for malicious software:
https://github.com/ossf/package-analysis
GitHub
GitHub - ossf/package-analysis: Open Source Package Analysis
Open Source Package Analysis. Contribute to ossf/package-analysis development by creating an account on GitHub.
Forwarded from Sys-Admin InfoSec
/ Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
Newst updated document frim NIST
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf
Newst updated document frim NIST
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-161r1.pdf
RustDesk - Represented as remote control from anywhere
…Our protocol and client side are open source. You can use our public rendezvous/relay server, or self-hosting, or write your own server….
https://rustdesk.com/
…Our protocol and client side are open source. You can use our public rendezvous/relay server, or self-hosting, or write your own server….
https://rustdesk.com/
GitHub
GitHub - rustdesk/rustdesk: An open-source remote desktop application designed for self-hosting, as an alternative to TeamViewer.
An open-source remote desktop application designed for self-hosting, as an alternative to TeamViewer. - rustdesk/rustdesk
Recognize Digits Using ML in Elixir
https://fly.io/phoenix-files/recognize-digits-using-ml-in-elixir/
https://fly.io/phoenix-files/recognize-digits-using-ml-in-elixir/
Fly
Recognize digits using ML in Elixir
Machine learning allows you to solve once unimaginable problem. Elixir's support for machine learning through Nx and Axon let us do impressive thing while staying in our favorite language.
Forwarded from Sys-Admin InfoSec
BLD DNS Project Status Update (May 2022)
At the this Q2 2022, BLD has some good updates and news!
🪴 BLD Service updates
- Anti-flood Security Implementations and Improvements
- Optimized Debian based distros will change CentOS based
- Regex-supporting implementation
- New overlimits regulations and improvement performance
- Current month num of requests to BLD DNS 10M+ exceeded and the infrastructure withstood such a load, despite the minimal configuration of virtual servers 🥳
- BLD Project Site updates (Adaptive support for mobile devices, Multilingual support: EN, RU, BLD how to setup instructions: EN, RU )
🧩 New servers, resources and locations
At the last few months BLD infrastructure was updated:
- GoHost.kz - Nur-Sultan Server
- Unihost.kz - Almaty Server
- X-RDP - Monreal Server
🤝 BLD receive some supporting from:
- G-Core Labs - Cloud resources
- JetBrains - Open source license to BLD project
⚠️ Deprecation/Changing notises
- ! doh.sys-adm.in will be deprecated, please change your settings to bld.sys-adm.in
At the this Q2 2022, BLD has some good updates and news!
🪴 BLD Service updates
- Anti-flood Security Implementations and Improvements
- Optimized Debian based distros will change CentOS based
- Regex-supporting implementation
- New overlimits regulations and improvement performance
- Current month num of requests to BLD DNS 10M+ exceeded and the infrastructure withstood such a load, despite the minimal configuration of virtual servers 🥳
- BLD Project Site updates (Adaptive support for mobile devices, Multilingual support: EN, RU, BLD how to setup instructions: EN, RU )
🧩 New servers, resources and locations
At the last few months BLD infrastructure was updated:
- GoHost.kz - Nur-Sultan Server
- Unihost.kz - Almaty Server
- X-RDP - Monreal Server
🤝 BLD receive some supporting from:
- G-Core Labs - Cloud resources
- JetBrains - Open source license to BLD project
⚠️ Deprecation/Changing notises
- ! doh.sys-adm.in will be deprecated, please change your settings to bld.sys-adm.in
Security advisory: malicious crate rustdecimal
The Rust Security Response WG and the crates.io team were notified on 2022-05-02 of the existence of the malicious crate
https://blog.rust-lang.org/2022/05/10/malicious-crate-rustdecimal.html
The Rust Security Response WG and the crates.io team were notified on 2022-05-02 of the existence of the malicious crate
rustdecimal, which contained malware. The crate name was intentionally similar to the name of the popular rust_decimal crate, hoping that potential victims would misspell its name (an attack called "typosquatting”):https://blog.rust-lang.org/2022/05/10/malicious-crate-rustdecimal.html
GitHub
Possibly malicious package "rustdecimal" · Issue #514 · paupino/rust-decimal
Hi. I found this package: https://docs.rs/rustdecimal/latest/rustdecimal/ . It seems this is clone of your package created for malicious purposes
Forwarded from Sys-Admin InfoSec
Сегодня в Алматы состоится сходка нескольких ИТ-комьюнити с докладами и не только (Lenore Pub, 19:00)
Движуху двигают r0crewKZ совместно с SolveChat, будет куча докладов (и я там тоже буду)
1. Александр Ошлаков - "Пишем код в функциональном стиле. Как и главное Зачем"
2. Евгения Цыбренко - "Гибридные Криптобиржи: взгляд изнутри"
3. Thatskriptkid - "Решаем андроид крякми с помощью IDA"
4. novitoll - "gnuradio: Eins, zwei (G), Polizei, Drei (G), vier (G), Grenadier, Fünf (G)?"
5. Sh3lldon - Патчинг bin, elf и pe файлов с гидрой
6. sysadmin "Аваренесс о неявных превентивных сервисах"
Бесплатно, без стрима, без записи.
Не забываем подтягиваться в Lenore Pub к 19:00 ✌️
#free #meetup #ru
HR головного мозга или что не так с рынком поиска трудовых резервов
Периодически поглядываю на рынок труда, как с точки зрения работодателя, так и с точки зрения соискателя.
Последнее время, метаморфоза типов, видов, способов трудового взаимодействия претерпела значительные, но почему то не совсем видимые и даже порой неочевидные вещи (для вполне очевидных вещей) - для конечных пользователей рынка, будь то HR или соискатель.
Возможно нижесказанное, есть ни что иное, как субъективный взгляд со своей (моей) колокольни, но что действительно вырисовывается из общей картины хочется зафиксировать в этом артикле..:
- HR головного мозга
#ru #blog #reflections
Периодически поглядываю на рынок труда, как с точки зрения работодателя, так и с точки зрения соискателя.
Последнее время, метаморфоза типов, видов, способов трудового взаимодействия претерпела значительные, но почему то не совсем видимые и даже порой неочевидные вещи (для вполне очевидных вещей) - для конечных пользователей рынка, будь то HR или соискатель.
Возможно нижесказанное, есть ни что иное, как субъективный взгляд со своей (моей) колокольни, но что действительно вырисовывается из общей картины хочется зафиксировать в этом артикле..:
- HR головного мозга
#ru #blog #reflections
lab.sys-adm.in
Sys-Admin Laboratory
Open Sys-Admin BLD DNS - Focus on information for free with adblocking and implicit cybersecurity threat prevention.
An Introduction to SQL Commands for Beginners
https://www.analyticsvidhya.com/blog/2022/05/an-introduction-to-sql-commands-for-beginners/
https://www.analyticsvidhya.com/blog/2022/05/an-introduction-to-sql-commands-for-beginners/
Analytics Vidhya
Introduction to SQL Commands and Sub Languages
Step into the basics of SQL, starting with the various SQL commands and sub-languages, such as DDL, DCL, DML, and more.
Combining even more techniques to defeat EDR via DLL unhooking and AMSI bypass
Research article:
https://kymb0.github.io/malwaredev-defeat-edr-unhook/
Research article:
https://kymb0.github.io/malwaredev-defeat-edr-unhook/
kymBlog
Combining even more techniques to defeat EDR via DLL unhooking and AMSI bypass
Taking on an enterprise grade EDR for fun, profit, and learning
iPhone-never-sleep.pdf
1.2 MB
Evil Never Sleeps:
When Wireless Malware Stays On After Turning Off iPhones
When Wireless Malware Stays On After Turning Off iPhones
Auto PY to EXE (python: 3.6-3.10)
A .py to .exe converter using a simple graphical interface (demo)
https://github.com/brentvollebregt/auto-py-to-exe
A .py to .exe converter using a simple graphical interface (demo)
https://github.com/brentvollebregt/auto-py-to-exe
GradeJS - is an open-source project that allows you to analyze webpack production bundles without having access to the source code of a website. It detects a list of bundled NPM libraries and works even for minified or tree-shaken bundles:
https://github.com/fingerprintjs/gradejs
#sec #npm #node
https://github.com/fingerprintjs/gradejs
#sec #npm #node
GitHub
GitHub - gradejs/gradejs: GradeJS analyzes production Webpack bundles without having access to the source code of a website. Instantly…
GradeJS analyzes production Webpack bundles without having access to the source code of a website. Instantly see vulnerabilities, outdated packages, and more just by entering a web application URL....
Ads by Microsoft on DuckDuckGo Private Search
https://help.duckduckgo.com/duckduckgo-help-pages/company/ads-by-microsoft-on-duckduckgo-private-search/
https://help.duckduckgo.com/duckduckgo-help-pages/company/ads-by-microsoft-on-duckduckgo-private-search/
Duckduckgo
Ads By Microsoft on DuckDuckGo Private Search - DuckDuckGo Help Pages
DuckDuckGo doesn’t track you. That’s the DuckDuckGo privacy policy in a nutshell.
Рецепт борща. Рассуждение, Фантазия, Аналогия.
Рецепт борща. Фантазия на тему жизни. Во первых рецепт борща - у каждого он свой. Некоторое время назад в моей жизни появился термин "рецепт борща", термин родился недавно и как-то всплыл, когда я кому-то рассказывал про BLD проект.
Мое определение рецепта борща, классификация гостей и не только:
https://sys-adm.in/live/979-retsept-borshcha-rassuzhdenie-analogiya.html
Рецепт борща. Фантазия на тему жизни. Во первых рецепт борща - у каждого он свой. Некоторое время назад в моей жизни появился термин "рецепт борща", термин родился недавно и как-то всплыл, когда я кому-то рассказывал про BLD проект.
Мое определение рецепта борща, классификация гостей и не только:
https://sys-adm.in/live/979-retsept-borshcha-rassuzhdenie-analogiya.html
sys-adm.in
Рецепт борща. Фантазия - Аналогия. - Для сисадминов и не только
Sys-Adm.in - Сайт для сисадминов и не только. Здесь собраны различные материалы основанные на личной практике. Блог Евгения Гончарова.
v86 emulates an x86-compatible CPU and hardware. Machine code is translated to WebAssembly modules at runtime in order to achieve decent performance.
https://github.com/copy/v86
https://github.com/copy/v86
GitHub
GitHub - copy/v86: x86 PC emulator and x86-to-wasm JIT, running in the browser
x86 PC emulator and x86-to-wasm JIT, running in the browser - copy/v86
/ Zero to hero: save your org from cyber-attack with a zero trust model
simple conceptual
https://specopssoft.com/blog/zero-trust-model-save-your-org-from-cyber-attack/
simple conceptual
https://specopssoft.com/blog/zero-trust-model-save-your-org-from-cyber-attack/