Sys-Admin Up – Telegram
Sys-Admin Up
1.06K subscribers
132 photos
4 videos
127 files
2.23K links
InfoSec, Hacks, Perks, Tools, IT/IS Courses, CVE… Contains part of the news that was not included in the Sys-Admin & InfoSec Channel (@sysadm_in_channel)
Download Telegram
Cyber Incident Response Plan Guidance.pdf
1.9 MB
Cyber Incident Response Plan Guidance PDF
5GBaseChecker, a security analysis framework for the control plane protocols of 5G baseband.

https://github.com/SyNSec-den/5GBaseChecker
Microsoft Office Spoofing Vulnerability

Configuring the Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers policy setting provides the ability to allow, block, or audit outgoing NTLM traffic from a computer running Windows Server 2008, Windows Server 2008 R2, or later to any remote server running the Windows operating system..:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200
NIST_Incident_Response_Recommendations_and_Considerations_for_Cybersecurity.pdf
968.5 KB
Incident Response Recommendations for
Risk Management from NIST
MIFARE Classic: exposing the static encrypted nonce variant

https://eprint.iacr.org/2024/1275.pdf
Qilin ransomware caught stealing credentials stored in Google Chrome

Once the attacker reached the domain controller in question, they edited the default domain policy to introduce a logon-based Group Policy Object (GPO) containing two items. The first, a PowerShell noscript named IPScanner.ps1, was written to a temporary directory within the SYSVOL (SYStem VOLume) share (the shared NTFS directory located on each domain controller inside an Active Directory domain) on the specific domain controller involved. It contained a 19-line noscript that attempted to harvest credential data stored within the Chrome browser...:

https://news.sophos.com/en-us/2024/08/22/qilin-ransomware-caught-stealing-credentials-stored-in-google-chrome/
Cyber-Incodent-Response-Plan.pdf
671.2 KB
GUIDANCE*
DIR-846W : All H/W Revs. & All F/W Vers. : End-of-Life (EOL) / End-of-Service (EOS) : CVE-2024-41622/44340/44341/44342 Vulnerability Reports

RCE

https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411
EUCLEAK (Side-Channel Attack on the YubiKey 5 Series)

https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf
CompTIA Security+ Notes.pdf
1.5 MB
CompTIA Security+ SY0-601

- Attacks, Threats, and Vulnerabilities
- Architecture and Design
- Implementation
- Operations and Incident Response
- Governance, Risk, and Compliance