Segu-Info Channel
8.84K subscribers
178 photos
43 videos
8 files
5.61K links
Canal de Ciberseguridad de Segu-Info.
MΓ‘s info: https://blog.segu-info.com.ar
Download Telegram
Vulnerabilidad crΓ­tica en Laravel permite escalamiento de privilegios
https://blog.segu-info.com.ar/2024/11/vulnerabilidad-critica-en-laravel.html
πŸ”₯5
NSO Group utiliza Zero-Days de WhatsApp para instalar Pegasus y espionaje
https://blog.segu-info.com.ar/2024/11/nso-group-utiliza-zero-days-de-whatsapp.html
πŸ‘9
Zero-Day en FortiClient permite robo de credenciales de VPN
https://blog.segu-info.com.ar/2024/11/zero-day-en-forticlient-permite-robo-de.html
πŸ‘1
πŸ“Œ #OCSP Official Documentation

πŸ”—https://offensive-security.com/offsec/oscp-exam-structure/
πŸ”—https://offensive-security.com/metasploit-unleashed/
πŸ”—https://help.offensive-security.com/hc/en-us
πŸ”—https://help.offensive-security.com/hc/en-us/articles/360050473812
πŸ”—https://offensive-security.com/documentation/penetration-testing-with-kali.pdf
πŸ”—https://forums.offensive-security.com

πŸ“Œ OCSP Tools and Resources

πŸ”—https://falconspy.medium.com/unofficial-oscp-approved-tools-b2b4e889e707
πŸ”—https://reddit.com/r/oscp/comments/if1q5v/ive_made_a_list_of_reddit_topics_that_you_should/
πŸ”—https://github.com/Tib3rius/AutoRecon
πŸ”—https://hackingarticles.in/comprehensive-guide-to-autorecon/
πŸ”—https://github.com/21y4d/nmapAutomator
πŸ”—https://github.com/codingo/Reconnoitre

πŸ“ŒOSCP Guides

πŸ”—https://johnstawinski.com/2022/10/09/oscp-2023-study-guide-new-exam-format
πŸ”—https://johnjhacking.com/blog/oscp-reborn-2023/
πŸ”—https://sgtdede.gitbook.io/hacking/oscp-2022/guide-en
πŸ”—https://netsecfocus.com/oscp/2021/05/06/The_Journey_to_Try_Harder-_TJnull-s_Preparation_Guide_for_PEN-200_PWK_OSCP_2.0.html
πŸ”—https://hxrrvs.gitbook.io/oscp/
πŸ”—https://ninjasec.medium.com/efficiently-utilizing-autorecon-for-oscp-and-beyond-74c93a273a36
πŸ”—https://github.com/Shiva108/CTF-notes/tree/master/OSCP-Materials-master
πŸ”—https://github.com/Shiva108/CTF-notes/tree/master/Notes%20VA
πŸ”—https://github.com/Shiva108/CTF-notes/tree/master/Everything-OSCP
πŸ”—https://github.com/Shiva108/CTF-notes/blob/master/enum_oscp.html
πŸ”—https://github.com/Shiva108/CTF-notes/blob/master/how-to-oscp-final.md
πŸ”—https://github.com/Shiva108/CTF-notes/blob/master/Kali%20Linux%20Offensive%20Security%20Certified%20Professional%20Playbook.html
πŸ”—https://avasdream.engineer/assets/OSCP-Methodology.png
πŸ”—https://kali.training/lessons/introduction/
πŸ”—https://netsecfocus.com/oscp/2019/03/29/The_Journey_to_Try_Harder-_TJNulls_Preparation_Guide_for_PWK_OSCP.html
πŸ”—https://tripwire.com/state-of-security/security-awareness/oscp-journey/
πŸ”—https://411hall.github.io/OSCP-Preparation/
πŸ”—https://scund00r.com/all/oscp/2018/02/25/passing-oscp.html
πŸ”—https://abatchy.com/2017/03/how-to-prepare-for-pwkoscp-noob
πŸ”—https://niiconsulting.com/checkmate/2017/06/a-detail-guide-on-oscp-preparation-from-newbie-to-oscp/
πŸ”—https://johnjhacking.com/blog/the-oscp-preperation-guide-2020/
πŸ”—https://medium.com/@hakluke/haklukes-ultimate-oscp-guide-part-1-is-oscp-for-you-b57cbcce7440
πŸ”—https://sushant747.gitbooks.io/total-oscp-guide/content/
πŸ”—https://rana-khalil.gitbook.io/hack-the-box-oscp-preparation/my-oscp-journey-a-review

πŸ“Œ OCSP Essential Videos and Courses

πŸ”—TryHackMe Pentesting Course -https://tryhackme.com/path/outline/pentesting
πŸ”—TryHackMe Buffer Overflow Prep -https://tryhackme.com/room/bufferoverflowprep
πŸ”—Cyber Mentor: Buffer overflow - https://tcm-sec.com/buffer-overflows-made-easy/
πŸ”—Tiberius' Priv Esc Courses - https://udemy.com/course/linux-privilege-escalation/
πŸ”—TJNull's OSCP Prep - https://youtube.com/playlist?list=PLidcsTyj9JXK-fnabFLVEvHinQ14Jy5tf
πŸ”—Tiberius Buffer overflow - https://youtube.com/watch?v=1X2JGF_9JGM
πŸ”—Conda's OSCP Prep - https://youtube.com/playlist?list=PLDrNMcTNhhYqZU1ySROli7Oc08mxe1tZR

πŸ“Œ OCSP Practice Box List

πŸ”—TJNull's List - https://docs.google.com/spreadsheets/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/edit#gid=1839402159
πŸ”—HackTheBox List -https://docs.google.com/spreadsheets/d/1PVH3athOru-rHirsy30R1r8692R6J44W7uuHTrquqnk/edit#gid=1638926857https://hyd3.home.blog/2020/06/22/oscp-prep-hackthebox-list/
πŸ”—NoobSec List - https://docs.google.com/spreadsheets/d/1PVH3athOru-rHirsy30R1r8692R6J44W7uuHTrquqnk/edit#gid=1638926857
πŸ”—OSCP-like Boxes -https://nopresearcher.github.io/OSCP-Like-Boxes/

Referencias en Twitter: @s0cm0nkeysec @harshleenchawl2
πŸ‘7❀2
Vuelve a aparecer otro sitio FALSO (.org) de ARCA (ex AFIP) con una aplicaciΓ³n mΓ³vil APK.

https://x.com/SeguInfo/status/1858886643970707611
πŸ”₯3πŸ‘1
Correos electrΓ³nicos de phishing utilizan cada vez mΓ‘s archivos adjuntos SVG para evadir la detecciΓ³n
https://blog.segu-info.com.ar/2024/11/correos-electronicos-de-phishing.html
❀1πŸ”₯1πŸ‘1
AquΓ­ Elonmuss te enseΓ±a a hacerte millonario!
https://x.com/SeguInfo/status/1859024598530138143
😁6🀯3πŸ”₯1
πŸ”₯1
Sabotaje en el BΓ‘ltico: cables de datos cortados entre Finlandia y Alemania
https://blog.segu-info.com.ar/2024/11/sabotaje-en-el-baltico-cables-de-datos.html
πŸ”₯7
Nuevo Top 25 de errores de programaciΓ³n de MITRE.
Es muy triste esto! Hace 25 aΓ±os que venimos asΓ­.
Si programas y eres parte del problema, estudia programaciΓ³n segura o bΓΊscate otro trabajo.
πŸ‘9😁8🀯2
Recuerden que hace un par de aΓ±os publicamos de forma gratuita el curso de la #CertificaciΓ³n #CISSP completo

πŸ”—https://www.youtube.com/seguinfo
πŸ‘14❀6πŸ‘4
MITRE publica las 25 debilidades de software mΓ‘s peligrosas de 2024 (CWE)
https://blog.segu-info.com.ar/2024/11/mitre-publica-las-25-debilidades-de.html
πŸ‘4
Firewalls Palo Alto comprometidos por vulnerabilidad Zero-Day
https://blog.segu-info.com.ar/2024/11/firewalls-palo-alto-comprometidos-por.html
πŸ‘1πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
MΓ‘s info sobre #Quishing porque hay mucho humo. El cartel es el mismo, el QR es distinto.
El QR solo *no* hace nada!
Al escanearlo brinda un enlace. Si ingresas, lo que suceDÍA se vΓ© enπŸ“½ (solo si entras).
El comportamiento puede cambiar de acuerdo al enlace que te toque.

πŸ”—https://x.com/SeguInfo/status/1859740307241435575
πŸ‘11πŸ‘1
Forwarded from Alfonso MuΓ±oz
πŸ‘2
Fallo en el diseΓ±o de la VPN de Fortinet oculta ataques de fuerza bruta exitosos
https://blog.segu-info.com.ar/2024/11/fallo-en-el-diseno-de-la-vpn-de.html
🀬4πŸ”₯1