Comunidad Pen7esting
3.58K subscribers
510 photos
40 videos
142 files
5.08K links
Download Telegram
Official
DEF CON Main: https://www.twitch.tv/defconorg
DEF CON DCTV One: https://www.twitch.tv/defcon_dctv_one
DEF CON DCTV Two: https://www.twitch.tv/defcon_dctv_two
DEF CON DCTV Three: https://www.twitch.tv/defcon_dctv_three
DEF CON DCTV Four: https://www.twitch.tv/defcon_dctv_four
DEF CON DCTV Five: https://www.twitch.tv/defcon_dctv_five
DEF CON Music: https://www.twitch.tv/defcon_music

Villages
Adversary Village: https://www.twitch.tv/adversaryvillage
Aerospace Village: Videos are linked at https://aerospacevillage.org/events/upcoming-events/def-con-29/def-con-29-schedule/
AI Village: https://www.twitch.tv/aivillage
Appsec Village: Videos are linked at https://www.appsecvillage.com/events/dc-2021
B.I.C. (Blacks In Cybersecurity) Village: https://www.youtube.com/c/BlacksInCybersecurity
Bio Hacking Village: https://wishyouwerehere.villageb.io/defcon/event/bhv-2021-1_defcon/room4.html
Blue Team Village: https://twitch.tv/blueteamvillage
Car Hacking Village: https://www.carhackingvillage.com/defcon29
Career Hacking: https://www.youtube.com/CareerHackingVillage
Cloud Village: https://www.youtube.com/cloudvillage_dc
Crypto & Privacy Village: https://www.twitch.tv/cryptovillage
Hack the Sea Village: https://www.twitch.tv/h4ckthesea
Ham Radio Village: https://twitch.tv/hamradiovillage
ICS Village: https://www.youtube.com/channel/UCI_GT2-OMrsqqglv0JijHhw
IoT Village: https://www.twitch.tv/iotvillage
Lock Bypass Village: https://www.twitch.tv/bypassvillage
Packet Hacking Village: https://www.youtube.com/channel/UCnL9S5Wv_dNvO381slSA06w
Password Village: Videos are linked at https://passwordvillage.org/schedule.html
Payment Village: https://www.twitch.tv/paymentvillage
Recon Village: https://www.youtube.com/c/ReconVillage/live
Rogues Village: https://www.twitch.tv/roguesvillage
Social Engineering Village: https://www.twitch.tv/socialengineerllc
Voting Village: https://www.youtube.com/channel/UCnDevqsxt3sO8chqS5MGvwg
​bettercap

bettercap es una herramienta potente, fácilmente ampliable y portátil para los investigadores de seguridad.

Una solución "todo en uno" con todas las funciones que pueda necesitar para el reconocimiento y el ataque:
🔸Escaneo de redes Wi-Fi , ataque deautenticación , ataque de asociación PMKID sin cliente y captura automática del handshake del cliente WPA / WPA2.
🔸Escaneo de dispositivos Bluetooth Low Energy
🔸Escaneo de dispositivos inalámbricos de 2,4 GHz y ataque MouseJacking con inyección de tramas HID inalámbricas (con soporte DuckyScript).
🔸Detección y reconocimiento de nodos IP pasivos y activos en la red.
🔸Spoofs ARP, DNS y DHCPv6 para ataques MITM en redes IP.
🔸Servidores proxy a nivel de paquete, aplicaciones TCP y HTTP / HTTPS soportan completamente el scripting con plugins javascript fáciles de implementar.
🔸Potente sniffer de red para recopilar credenciales que también puede ser utilizado como un phaser de protocolo de red
🔸Un escáner de puertos muy rápido.
🔸Una interfaz web muy fácil de usar
y mucho más...

https://github.com/bettercap/bettercap

⚠️Este proyecto sólo debe utilizarse con fines de prueba o educativos.⚠️

Autor: https://www.bettercap.org/
📃 "La NSA publica una guía sobre la protección de las comunicaciones unificadas y los sistemas de voz y video sobre IP" https://www.enhacke.com/2021/06/18/la-nsa-publica-una-guia-sobre-la-proteccion-de-las-comunicaciones-unificadas-y-los-sistemas-de-voz-y-video-sobre-ip/
📃 "Guía NSA sobre la protección de las comunicaciones unificadas y los sistemas de voz y video sobre IP" https://blog.elhacker.net/2021/06/guia-nsa-sobre-la-proteccion-de-las-comunicaciones-unificadas-sistemas-video-sobre-ip-vvoip.html
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-stored-xss-TWwjVPdL?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Identity%20Services%20Engine%20Stored%20Cross-Site%20Scripting%20Vulnerabilities&vs_k=1

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user.
These vulnerabilities exist because the web-based management interface does not sufficiently validate user-supplied input. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker would need valid administrative credentials.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-stored-xss-TWwjVPdL


Security Impact Rating: Medium



CVE: CVE-2021-1603,CVE-2021-1604,CVE-2021-1605,CVE-2021-1606,CVE-2021-1607