Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Cvemap from ProjectDiscovery

Infomation in cvemap based on:
- Known Exploited Vulnerabilities Catalog (KEV)
- Exploit Prediction Scoring System (EPSS)
- Proofs of Concept (POCs)
- HackerOne CVE Discovery
- Nuclei Templates
- and more..

https://blog.projectdiscovery.io/announcing-cvemap-from-projectdiscovery/
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
🚀 zDNS Released with Big Updates and Features

Few month ago I stared develop from scratch zDNS service, now it's can:

- Restrict DNS queries by type like as A, AAAA, HTTPS, CNAME, MX, PTR..
- Balancing DNS traffic between upstream servers
- Providing Prometheus metrics
- DNS responses caching by custom TTL
- Has few working modes - Zero Trust, Allow/Blocking
- Has separated "Permanent" mode with additional custom upstream DNS servers
- Can load allow/block lists from local and remote through HTTP(S)
- Create/Delete custom users with different configs and hosts files
- and more...

New opportunities, features, looking forward, and info about of new OpenBLD.net Personal Usage Testing pre-relase see here:

https://openbld.net/blog/zdns-big-updates-and-features/
Please open Telegram to view this post
VIEW IN TELEGRAM
/ ExecIT - DLL Shellcode self-inyector/runner based on HWSyscalls, ideally thought to be executed with rundll32. May grant fileless execution if victim endpoint has access to attacker-controlled SMB share:

https://github.com/florylsk/ExecIT
/ runc: CVE-2024-21626: high severity container breakout attack

https://www.openwall.com/lists/oss-security/2024/01/31/6
Method for Decrypting Data Infected with Rhysida Ransomware

https://arxiv.org/pdf/2402.06440.pdf
/ CVE-2024-21413 - Expect Script POC

Microsoft Outlook Leak credentials & Remote Code Execution Vulnerability when chained with CVE-2023-21716 (through the preview panel) CVSS:3.1 9.8 / 8.5:

https://github.com/duy-31/CVE-2024-21413
/ Exploring AMD Platform Secure Boot

..dig deeper into the nitty gritty details of PSB, including a first glimpse of how it works under the hood, how it should be configured and, naturally, how various major vendors fail to do so.

https://labs.ioactive.com/2024/02/exploring-amd-platform-secure-boot.html
CrimsonEDR - EDR Attack Sumulator

CrimsonEDR is an open-source project engineered to identify specific malware patterns, offering a tool for honing skills in circumventing Endpoint Detection and Response (EDR). By leveraging diverse detection methods, it empowers users to deepen their understanding of security evasion tactics:

https://github.com/Helixo32/CrimsonEDR/tree/main