Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Zyxel NAS Under Attack

The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted HTTP POST request (CVE-2024-29973. NVD Last Modified 06/24/2024):

https://nvd.nist.gov/vuln/detail/CVE-2024-29973

Five new vulnerabilities found in Zyxel NAS devices (including code execution and privilege escalation)

Detailed research:

https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
red_hat_enterprise_linux_9_configuring_firewalls_and_packet_filters.pdf
629.7 KB
Configuring firewalls and packet filters

Managing the firewalld service, the nftables framework, and XDP packet filtering features (doc from RHEL 9)
Threat_Hunting_Framework.pdf
1 MB
THREAT HUNTING
FRAMEWORK
Vulnerabilities in VPN

- Paper presented at the Privacy Enhancing Technologies Symposium 2024
- PoC
OWASP_Vulnerability_Management_Guide.pdf
1.4 MB
OWASP Vulnerability Management Guide (OVMG)
Forwarded from Yevgeniy Goncharov
🦄 Йоу! Хорош спать. Поднимай взор на темы докладов Open SysConf'24

Во первых. Теперь каждый может внести лепту в создание сайта, исправлении ошибок на нем и так далее.
Во вторых. Мы имеем место и дату - 12 Октяря, 2024 года.

В третьихх. Мы имеем четрые крутых заявленых доклада:

1. Три системы, которые ты захочешь развернуть и настроить
2. Внедрение вредоносного кода в андроид приложения.
3. Open(Secure)Source
4. Синтез молекулярных единиц в микросервисах

Иди на сайт и регистрируйся, пока есть места.

Дев. сайт: https://sysconf-io.pages.dev/2024
IOT Cybersecurity Framework.pdf
3.8 MB
IOT Cyber Security Framework
How did Facebook intercept their competitor's encrypted mobile app traffic?

A technical investigation into information uncovered in a class action lawsuit that Facebook had intercepted encrypted traffic from user's devices running the Onavo Protect app in order to gain competitive insights...:

https://doubleagent.net/onavo-facebook-ssl-mitm-technical-analysis/

P.S. Thx for the link, dear subscriber ✌️
Unmasking the SMS Stealer: Targeting Several Countries with Deceptive Apps

One-time passwords (OTPs) are designed to add an extra layer of security to online accounts, and most enterprises have become very dependent upon them for controlling access to sensitive data and applications...

However, these passwords are just as valuable to attackers.

Mobile malware has become increasingly sophisticated, employing cunning tactics to steal these crucial codes and bypass their added protection to enable malicious infiltration to corporate networks and data...:

https://www.zimperium.com/blog/unmasking-the-sms-stealer-targeting-several-countries-with-deceptive-apps/