dref
DNS Rebinding Exploitation Framework
https://github.com/mwrlabs/dref
Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html
Automated blind-xss search for Burp Suite.
https://github.com/wish-i-was/femida
DNS Rebinding Exploitation Framework
https://github.com/mwrlabs/dref
Not So Cozy: An Uncomfortable Examination of a Suspected APT29 Phishing Campaign
https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html
Automated blind-xss search for Burp Suite.
https://github.com/wish-i-was/femida
GitHub
GitHub - ReversecLabs/dref: DNS Rebinding Exploitation Framework
DNS Rebinding Exploitation Framework . Contribute to ReversecLabs/dref development by creating an account on GitHub.
APT28 / Sofacy – SedUploader under the Christmas tree
https://www.emanueledelucia.net/apt28-sofacy-seduploader-under-the-christmas-tree/
Modlishka
Modlishka. Reverse Proxy. Phishing NG.
https://github.com/drk1wi/Modlishka
Ping Power — ICMP Tunnel
https://medium.com/bugbountywriteup/ping-power-icmp-tunnel-31e2abb2aaea
Vidar and GandCrab: stealer and ransomware combo observed in the wild
https://blog.malwarebytes.com/threat-analysis/2019/01/vidar-gandcrab-stealer-and-ransomware-combo-observed-in-the-wild/
PVS-Studio and Bug Bounties on Free and Open Source Software
https://medium.com/@karpov2007/pvs-studio-and-bug-bounties-on-free-and-open-source-software-538f42ee2701
Pivot to the Cloud using Pass the Cookie
https://wunderwuzzi23.github.io/blog/passthecookie.html#CheatSheet
APT10 intrusion activities target Cloud-Computing Managed Service Providers worldwide
https://www.waterisac.org/system/files/articles/%28U%29%20FBI%20FLASH%20-%20%20Chinese%20APT10%20intrusion%20activities%20target%20-%2020190102.pdf
https://www.emanueledelucia.net/apt28-sofacy-seduploader-under-the-christmas-tree/
Modlishka
Modlishka. Reverse Proxy. Phishing NG.
https://github.com/drk1wi/Modlishka
Ping Power — ICMP Tunnel
https://medium.com/bugbountywriteup/ping-power-icmp-tunnel-31e2abb2aaea
Vidar and GandCrab: stealer and ransomware combo observed in the wild
https://blog.malwarebytes.com/threat-analysis/2019/01/vidar-gandcrab-stealer-and-ransomware-combo-observed-in-the-wild/
PVS-Studio and Bug Bounties on Free and Open Source Software
https://medium.com/@karpov2007/pvs-studio-and-bug-bounties-on-free-and-open-source-software-538f42ee2701
Pivot to the Cloud using Pass the Cookie
https://wunderwuzzi23.github.io/blog/passthecookie.html#CheatSheet
APT10 intrusion activities target Cloud-Computing Managed Service Providers worldwide
https://www.waterisac.org/system/files/articles/%28U%29%20FBI%20FLASH%20-%20%20Chinese%20APT10%20intrusion%20activities%20target%20-%2020190102.pdf
GitHub
GitHub - drk1wi/Modlishka: Modlishka. Reverse Proxy.
Modlishka. Reverse Proxy. . Contribute to drk1wi/Modlishka development by creating an account on GitHub.
𝕆𝕕𝕒𝕪Simpson🧫 (@0daySimpson) twitteó:
Don't let infosec distract you from hacking (https://twitter.com/0daySimpson/status/1081364172707790849?s=17)
Don't let infosec distract you from hacking (https://twitter.com/0daySimpson/status/1081364172707790849?s=17)
Twitter
𝕆𝕕𝕒𝕪Simpson🧫
Don't let infosec distract you from hacking
IOActive, Inc (@IOActive) twitteó:
Love to break things & travel? We are looking for driven consultants well versed in hardware/software security, as well as red team specialists, project managers, & business development managers to join our team. Visit https://t.co/x6y2sPEuc2 #cybersecurity #careers https://t.co/F6qkvHx9Rm (https://twitter.com/IOActive/status/1137401735536893953?s=17)
Love to break things & travel? We are looking for driven consultants well versed in hardware/software security, as well as red team specialists, project managers, & business development managers to join our team. Visit https://t.co/x6y2sPEuc2 #cybersecurity #careers https://t.co/F6qkvHx9Rm (https://twitter.com/IOActive/status/1137401735536893953?s=17)
Nicolas Krassas (@Dinosn) twitteó:
Userrecon - Find Usernames Across Over 75 Social Networks https://t.co/2jJJN5CDue (https://twitter.com/Dinosn/status/1137937183900176385?s=17)
Userrecon - Find Usernames Across Over 75 Social Networks https://t.co/2jJJN5CDue (https://twitter.com/Dinosn/status/1137937183900176385?s=17)
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
Ammar Amer (@cry__pto) twitteó:
Red Team Operations: Determining a Plan of Attack
https://t.co/6SoYqnNw35
Red-team tools
https://t.co/nE50Wd0OPs
Anatomy of a well-run red-team exercise
https://t.co/fdvTPiJB0Q
redteam-plan
https://t.co/85DEOGn6pO
#RedTeam #pentesting #hacking #infosec #cybersecurite (https://twitter.com/cry__pto/status/1135515713656037376?s=17)
Red Team Operations: Determining a Plan of Attack
https://t.co/6SoYqnNw35
Red-team tools
https://t.co/nE50Wd0OPs
Anatomy of a well-run red-team exercise
https://t.co/fdvTPiJB0Q
redteam-plan
https://t.co/85DEOGn6pO
#RedTeam #pentesting #hacking #infosec #cybersecurite (https://twitter.com/cry__pto/status/1135515713656037376?s=17)
Dell Cameron (@dellcam) twitteó:
NEW: A slew of U.S. govt websites are still redirecting users to porn a year after I first reported the problem. These .gov sites allowing unverified redirects are also very useful as phishing bait. (see https://t.co/iP3isXqqtM below) h/t @maassive
https://t.co/ntiFIULymj https://t.co/j9M36JBJZZ (https://twitter.com/dellcam/status/1138177268428300288?s=17)
NEW: A slew of U.S. govt websites are still redirecting users to porn a year after I first reported the problem. These .gov sites allowing unverified redirects are also very useful as phishing bait. (see https://t.co/iP3isXqqtM below) h/t @maassive
https://t.co/ntiFIULymj https://t.co/j9M36JBJZZ (https://twitter.com/dellcam/status/1138177268428300288?s=17)
Gizmodo
A Year Later, U.S. Government Websites Are Still Redirecting to Hardcore Porn
Dozens of U.S. government websites appear to contain a flaw enabling anyone to generate URLs with their domains that redirect users to external sites, a handy tool for criminals hoping to infect users with malware or fool them into surrendering personal information.