Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
The Maginot Line: Attacking the Boundary of DNS Caching Protection

https://www.usenix.org/system/files/usenixsecurity23-li-xiang.pdf
GPT based tool for understanding the tactics, techniques, and procedures (TTPs) used by threat actors

🔹 https://attackgen.streamlit.app/

Git - https://github.com/mrwadams/attackgen
Please open Telegram to view this post
VIEW IN TELEGRAM
Domain Audit - Wrapper around PowerView, Impacket, PowerUpSQL, BloodHound, Ldaprelayscan and Crackmapexec to automate the execution of enumeration and a lot of checks performed during a On-Prem Active Directory Penetrationtest

https://github.com/0xJs/domain_audit
Smart Bulbs can be Hacked to Hack into your Household

https://arxiv.org/pdf/2308.09019.pdf
Forwarded from Sys-Admin InfoSec
📢 OpenBLD.net DNS 🤬 H1 2023 Updates & News

What new we have in OpenBLD.net today:
🔹 New optimized DNS Fronted / Backend engines
🔹 Updated Geo Localized ecosystem
🔹 New integrated centralize Cactusd service
🔹 Optimized works with free video services (rezka, seasonwar), social networks and etc.
🔹 Integrated new Free SSL feature from ClouDNS
🔹 Testing Netdata (ML) Powered Anomaly Detection 🔩

What will updated:
🟡 🔴 On this month bld.sys-adm.in will be converted to ada.openbld.net
😎 Re-setup your browsers, devies and etc from *.sys-adm.in to ada.openbld.net

😎 Be yourself - be focused with OpenBLD.net DNS - https://lab.sys-adm.in ✌️
Please open Telegram to view this post
VIEW IN TELEGRAM
Bypass Two-Factor Authentication of Facebook Accounts ($25,300)

In this writeup, author will explain how did he discover a Two-Factor Authentication bypass in Facebook during Meta bug bounty Researchers conference in Seoul, South Korea, 2023..:

https://medium.com/@bazzounbassem/bypass-two-factor-authentication-of-facebook-accounts-25-300-7ae152d7836a
Visual recognize how data structures are used in our daily lives

🔹 list: keep your Twitter feeds
🔹 stack: support undo/redo of the word editor
🔹 queue: keep printer jobs, or send user actions in-game
🔹 heap: task scheduling
🔹 tree: keep the HTML document, or for AI decision
🔹 suffix tree: for searching string in a document
🔹 graph: for tracking friendship, or path finding
🔹 r-tree: for finding the nearest neighbor
🔹 vertex buffer: for sending data to GPU for rendering
Please open Telegram to view this post
VIEW IN TELEGRAM
FBI-CVE-2023-2868.pdf
1.1 MB
Suspected PRC Cyber ActorsContinue to Globally Exploit Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868)

As a part of the FBI investigation into the exploitation of CVE-2023-2868, a zero-day
vulnerability in Barracuda Network’s Email Security Gateway (ESG) appliances
Top-25-Penetration-Testing-Tools-(2023).pdf
203.3 KB
Penetration Testing Tools List with tool name and denoscriptions
Splunk EASM Worker

he EASM Worker is a REST API wrapper around open-source recon tools..:

https://github.com/gf13579/splunk_easm_worker
AttackSurfaceMapper

AttackSurfaceMapper (ASM) is a reconnaissance tool that uses a mixture of open source intelligence and active techniques to expand the attack surface of your target..:

🔸 https://github.com/superhedgy/AttackSurfaceMapper
Please open Telegram to view this post
VIEW IN TELEGRAM