spoofing_downloaded_filename.pdf
1.9 MB
Whitepaper
"Spoofing Downloaded Filename's Extension
in Chromium", 2021.
// This whitepaper illustrates exploitation of an insufficient data validation vulnerability in the Chromium framework (CVE-2021-21123)
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
"Spoofing Downloaded Filename's Extension
in Chromium", 2021.
// This whitepaper illustrates exploitation of an insufficient data validation vulnerability in the Chromium framework (CVE-2021-21123)
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
یه گله از فیلهای چینی که ۱۵ ماهه در حال سفرند، حدودا ۵۰۰ کیلومتر دورتر از زیستگاه طبیعی خودشون دارن استراحت میکنن.
تو این مدت یک تیم هشتنفره ۲۴ ساعته اینها رو تحت نظر داشتن و این تصویر ناب رو امروز منتشر کردن.
-تصاوير ناب-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
تو این مدت یک تیم هشتنفره ۲۴ ساعته اینها رو تحت نظر داشتن و این تصویر ناب رو امروز منتشر کردن.
-تصاوير ناب-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
گوگل پيرو حملات ساپلاي چي ن، يك فريمورك طراحي و پيشنهاد داده كه خوندنش خالي از لطف نيست🤓
Introducing SLSA, an End-to-End Framework for Supply Chain Integrity
https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html?m=1
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
Introducing SLSA, an End-to-End Framework for Supply Chain Integrity
https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html?m=1
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
Googleblog
Introducing SLSA, an End-to-End Framework for Supply Chain Integrity
Posted Kim Lewandowski, Google Open Source Security Team & Mark Lodato, Binary Authorization for Borg Team Supply chain integrity attacks—u...
پكيج هاي امنيت محور آژور ابري مايكروسافت
Waf
Fw
Siem
Edr
Policy
Compliance
Proxy
….
به شدت هيجان انگيزن، هم مطالب هم كار با اين ترند جذاب
پيشنهاد ميكنم يك نيم نگاهي داشته باشيد
امتحان اش هم براي ممبر هاي قديمي مايكرسافت ٤٥٪ كد تخفيف وچر صادر شده🤓
چرا كه نه
Protect data, apps, and infrastructure quickly with built-in security services in Azure that include unparalleled security intelligence to help identify rapidly evolving threats early—so you can respond quickly. ... Unify security management and enable advanced threat protection across hybrid cloud environments
https://azure.microsoft.com/en-us/overview/security/?cdn=disable
https://docs.microsoft.com/en-us/azure/security/fundamentals/overview
https://techcommunity.microsoft.com/t5/azure-sentinel/become-an-azure-sentinel-ninja-the-complete-level-400-training/ba-p/1246310
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
Waf
Fw
Siem
Edr
Policy
Compliance
Proxy
….
به شدت هيجان انگيزن، هم مطالب هم كار با اين ترند جذاب
پيشنهاد ميكنم يك نيم نگاهي داشته باشيد
امتحان اش هم براي ممبر هاي قديمي مايكرسافت ٤٥٪ كد تخفيف وچر صادر شده🤓
چرا كه نه
Protect data, apps, and infrastructure quickly with built-in security services in Azure that include unparalleled security intelligence to help identify rapidly evolving threats early—so you can respond quickly. ... Unify security management and enable advanced threat protection across hybrid cloud environments
https://azure.microsoft.com/en-us/overview/security/?cdn=disable
https://docs.microsoft.com/en-us/azure/security/fundamentals/overview
https://techcommunity.microsoft.com/t5/azure-sentinel/become-an-azure-sentinel-ninja-the-complete-level-400-training/ba-p/1246310
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.28
Web_Application_Penetration_Testing_E_Book__1624041422.pdf
13.3 MB
WEB APPLICATION PENETRATION TESTING
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
CHFI_v9_notes_1623959812.pdf
1.9 MB
CHFIv9 STUDY GUIDE
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Learn Azure in a Month of Lunches @MegaPack.pdf
3.8 MB
LEARN AZURE IN A MONTH OF LUNCHES
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Beginning Azure Functions.pdf
6.6 MB
Beginning Azure Functions
Building Scalable and Serverless Apps
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Building Scalable and Serverless Apps
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Azure Implementation.pdf
28.6 MB
Exam Ref 70-533 Implementing Microsoft Azure Infrastructure Solutions
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Microsoft Azure For Dummies @MegaPack.pdf
14.5 MB
Microsoft® Azure® For Dummies®
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Microsoft 365 Security Administration MS-500.pdf
34.1 MB
Microsoft 365 Security Administration: MS-500 Exam Guide
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Bypassing 2FA using OpenID Misconfiguration
https://youst.in/posts/bypassing-2fa-using-openid-misconfiguration
Threat Research
Old .NET Vulnerability #5: Security Transparent Compiled Expressions (CVE-2013-0073)
https://www.tiraniddo.dev/2020/05/old-net-vulnerability-5-security.html?m=1
Cloud Security
Kubernetes-based infrastructure for CTF competitions
https://github.com/google/kctf
Offensive security
Abusing PKI in Active Directory Environment😃
https://www.riskinsight-wavestone.com/en/2021/06/microsoft-adcs-abusing-pki-in-active-directory-environment/
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
https://youst.in/posts/bypassing-2fa-using-openid-misconfiguration
Threat Research
Old .NET Vulnerability #5: Security Transparent Compiled Expressions (CVE-2013-0073)
https://www.tiraniddo.dev/2020/05/old-net-vulnerability-5-security.html?m=1
Cloud Security
Kubernetes-based infrastructure for CTF competitions
https://github.com/google/kctf
Offensive security
Abusing PKI in Active Directory Environment😃
https://www.riskinsight-wavestone.com/en/2021/06/microsoft-adcs-abusing-pki-in-active-directory-environment/
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
www.tiraniddo.dev
Old .NET Vulnerability #5: Security Transparent Compiled Expressions (CVE-2013-0073)
It's been a long time since I wrote a blog post about my old .NET vulnerabilities. I was playing around with some .NET code and found an iss...
expanding_security_toolbox.pdf
2.3 MB
• How much visibility do we have into the various elements of the organization?
• What data points does my security team currently utilize to detect and respond to
incidents?
• Does my security team write their own detections? If so, do we utilize all the data points identified above?
• When we consider our risk exposure
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
• What data points does my security team currently utilize to detect and respond to
incidents?
• Does my security team write their own detections? If so, do we utilize all the data points identified above?
• When we consider our risk exposure
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
LockBit_Case_Report.pdf
3.4 MB
LockBit RaaS In-Depth Analysis
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
exploit
CVE-2020-11235:
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto / Compute / Connectivity / Consumer Electronics Connectivity /IOT / Industrial IOT / Mobile
https://github.com/PwnCast/CVE-2020-11235
CVE-2020-11238:
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto / Compute / Connectivity / Consumer Electronics Connectivity /IOT / Industrial IOT / Mobile
https://github.com/PwnCast/CVE-2020-11238
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
CVE-2020-11235:
Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto / Compute / Connectivity / Consumer Electronics Connectivity /IOT / Industrial IOT / Mobile
https://github.com/PwnCast/CVE-2020-11235
CVE-2020-11238:
Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto / Compute / Connectivity / Consumer Electronics Connectivity /IOT / Industrial IOT / Mobile
https://github.com/PwnCast/CVE-2020-11238
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Risk Responses - FUNNY WAY TO LEARN.
Drunk and Drive.
Risk Avoidance = Don’t drink and drive.
Risk Transfer = Drink and drive in taxi.
Risk mitigation = Drink very lightly and drive.
Residual risk = From above. You’ll drive normally but if police caught you. You’re stuck. Still damage is less as no accidents might take place.
Risk Rejection = Drink and Drive anyways.
😁😁😁😁😁😁😁😁😁😁😁😁
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
Drunk and Drive.
Risk Avoidance = Don’t drink and drive.
Risk Transfer = Drink and drive in taxi.
Risk mitigation = Drink very lightly and drive.
Residual risk = From above. You’ll drive normally but if police caught you. You’re stuck. Still damage is less as no accidents might take place.
Risk Rejection = Drink and Drive anyways.
😁😁😁😁😁😁😁😁😁😁😁😁
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
AZ-500: Microsoft Azure Security Technologies Practice Tests
5 complete practice tests & 3 case studies for Microsoft AZ-500 Certification Exam based on the latest syllabus
https://lnkd.in/dXDu2z4
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
5 complete practice tests & 3 case studies for Microsoft AZ-500 Certification Exam based on the latest syllabus
https://lnkd.in/dXDu2z4
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
The journey to Microsoft Certified: Azure Security Engineer Associate
https://lnkd.in/d7Ccy-m
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
#azure #cybersecurity #security #cloud #cloudsecurity #engineer #cyber #devops #aws
https://lnkd.in/d7Ccy-m
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
#azure #cybersecurity #security #cloud #cloudsecurity #engineer #cyber #devops #aws
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
یکی از آپدیتهای اخیر ویندوز 10
که گجت اخبار و آبوهوا را نمایش میدهد
باعث هنگ کردن ویندوز میشود
اگر این مشکل برای كاربران پیش آمد
روی تسکبار راست کلیک کنید
و از منوی News and interests
گزینهی Turn off را انتخاب نمایید
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
که گجت اخبار و آبوهوا را نمایش میدهد
باعث هنگ کردن ویندوز میشود
اگر این مشکل برای كاربران پیش آمد
روی تسکبار راست کلیک کنید
و از منوی News and interests
گزینهی Turn off را انتخاب نمایید
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
This media is not supported in your browser
VIEW IN TELEGRAM
چقدر
NDA
را از پيمانكاران و ….. جدي اخذ ميكنيد!؟
آيا nda شما در مراجع قضايي قابل پذيرش هست!؟حتما ضمانت اجراي و قانوني بودن آن و محكمه پسند بودن اين مستند را بررسي كنيد!؟
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29
NDA
را از پيمانكاران و ….. جدي اخذ ميكنيد!؟
آيا nda شما در مراجع قضايي قابل پذيرش هست!؟حتما ضمانت اجراي و قانوني بودن آن و محكمه پسند بودن اين مستند را بررسي كنيد!؟
-آگاهي رساني امنيت سايبري-
Up2date 4 Defence Today,
Secure Tomorrow
@CisoasaService
1400.03.29