Segu-Info Channel
8.84K subscribers
178 photos
43 videos
8 files
5.61K links
Canal de Ciberseguridad de Segu-Info.
Mรกs info: https://blog.segu-info.com.ar
Download Telegram
NSO Group utiliza Zero-Days de WhatsApp para instalar Pegasus y espionaje
https://blog.segu-info.com.ar/2024/11/nso-group-utiliza-zero-days-de-whatsapp.html
๐Ÿ‘9
Zero-Day en FortiClient permite robo de credenciales de VPN
https://blog.segu-info.com.ar/2024/11/zero-day-en-forticlient-permite-robo-de.html
๐Ÿ‘1
๐Ÿ“Œ #OCSP Official Documentation

๐Ÿ”—https://offensive-security.com/offsec/oscp-exam-structure/
๐Ÿ”—https://offensive-security.com/metasploit-unleashed/
๐Ÿ”—https://help.offensive-security.com/hc/en-us
๐Ÿ”—https://help.offensive-security.com/hc/en-us/articles/360050473812
๐Ÿ”—https://offensive-security.com/documentation/penetration-testing-with-kali.pdf
๐Ÿ”—https://forums.offensive-security.com

๐Ÿ“Œ OCSP Tools and Resources

๐Ÿ”—https://falconspy.medium.com/unofficial-oscp-approved-tools-b2b4e889e707
๐Ÿ”—https://reddit.com/r/oscp/comments/if1q5v/ive_made_a_list_of_reddit_topics_that_you_should/
๐Ÿ”—https://github.com/Tib3rius/AutoRecon
๐Ÿ”—https://hackingarticles.in/comprehensive-guide-to-autorecon/
๐Ÿ”—https://github.com/21y4d/nmapAutomator
๐Ÿ”—https://github.com/codingo/Reconnoitre

๐Ÿ“ŒOSCP Guides

๐Ÿ”—https://johnstawinski.com/2022/10/09/oscp-2023-study-guide-new-exam-format
๐Ÿ”—https://johnjhacking.com/blog/oscp-reborn-2023/
๐Ÿ”—https://sgtdede.gitbook.io/hacking/oscp-2022/guide-en
๐Ÿ”—https://netsecfocus.com/oscp/2021/05/06/The_Journey_to_Try_Harder-_TJnull-s_Preparation_Guide_for_PEN-200_PWK_OSCP_2.0.html
๐Ÿ”—https://hxrrvs.gitbook.io/oscp/
๐Ÿ”—https://ninjasec.medium.com/efficiently-utilizing-autorecon-for-oscp-and-beyond-74c93a273a36
๐Ÿ”—https://github.com/Shiva108/CTF-notes/tree/master/OSCP-Materials-master
๐Ÿ”—https://github.com/Shiva108/CTF-notes/tree/master/Notes%20VA
๐Ÿ”—https://github.com/Shiva108/CTF-notes/tree/master/Everything-OSCP
๐Ÿ”—https://github.com/Shiva108/CTF-notes/blob/master/enum_oscp.html
๐Ÿ”—https://github.com/Shiva108/CTF-notes/blob/master/how-to-oscp-final.md
๐Ÿ”—https://github.com/Shiva108/CTF-notes/blob/master/Kali%20Linux%20Offensive%20Security%20Certified%20Professional%20Playbook.html
๐Ÿ”—https://avasdream.engineer/assets/OSCP-Methodology.png
๐Ÿ”—https://kali.training/lessons/introduction/
๐Ÿ”—https://netsecfocus.com/oscp/2019/03/29/The_Journey_to_Try_Harder-_TJNulls_Preparation_Guide_for_PWK_OSCP.html
๐Ÿ”—https://tripwire.com/state-of-security/security-awareness/oscp-journey/
๐Ÿ”—https://411hall.github.io/OSCP-Preparation/
๐Ÿ”—https://scund00r.com/all/oscp/2018/02/25/passing-oscp.html
๐Ÿ”—https://abatchy.com/2017/03/how-to-prepare-for-pwkoscp-noob
๐Ÿ”—https://niiconsulting.com/checkmate/2017/06/a-detail-guide-on-oscp-preparation-from-newbie-to-oscp/
๐Ÿ”—https://johnjhacking.com/blog/the-oscp-preperation-guide-2020/
๐Ÿ”—https://medium.com/@hakluke/haklukes-ultimate-oscp-guide-part-1-is-oscp-for-you-b57cbcce7440
๐Ÿ”—https://sushant747.gitbooks.io/total-oscp-guide/content/
๐Ÿ”—https://rana-khalil.gitbook.io/hack-the-box-oscp-preparation/my-oscp-journey-a-review

๐Ÿ“Œ OCSP Essential Videos and Courses

๐Ÿ”—TryHackMe Pentesting Course -https://tryhackme.com/path/outline/pentesting
๐Ÿ”—TryHackMe Buffer Overflow Prep -https://tryhackme.com/room/bufferoverflowprep
๐Ÿ”—Cyber Mentor: Buffer overflow - https://tcm-sec.com/buffer-overflows-made-easy/
๐Ÿ”—Tiberius' Priv Esc Courses - https://udemy.com/course/linux-privilege-escalation/
๐Ÿ”—TJNull's OSCP Prep - https://youtube.com/playlist?list=PLidcsTyj9JXK-fnabFLVEvHinQ14Jy5tf
๐Ÿ”—Tiberius Buffer overflow - https://youtube.com/watch?v=1X2JGF_9JGM
๐Ÿ”—Conda's OSCP Prep - https://youtube.com/playlist?list=PLDrNMcTNhhYqZU1ySROli7Oc08mxe1tZR

๐Ÿ“Œ OCSP Practice Box List

๐Ÿ”—TJNull's List - https://docs.google.com/spreadsheets/d/1dwSMIAPIam0PuRBkCiDI88pU3yzrqqHkDtBngUHNCw8/edit#gid=1839402159
๐Ÿ”—HackTheBox List -https://docs.google.com/spreadsheets/d/1PVH3athOru-rHirsy30R1r8692R6J44W7uuHTrquqnk/edit#gid=1638926857https://hyd3.home.blog/2020/06/22/oscp-prep-hackthebox-list/
๐Ÿ”—NoobSec List - https://docs.google.com/spreadsheets/d/1PVH3athOru-rHirsy30R1r8692R6J44W7uuHTrquqnk/edit#gid=1638926857
๐Ÿ”—OSCP-like Boxes -https://nopresearcher.github.io/OSCP-Like-Boxes/

Referencias en Twitter: @s0cm0nkeysec @harshleenchawl2
๐Ÿ‘7โค2
Vuelve a aparecer otro sitio FALSO (.org) de ARCA (ex AFIP) con una aplicaciรณn mรณvil APK.

https://x.com/SeguInfo/status/1858886643970707611
๐Ÿ”ฅ3๐Ÿ‘1
Correos electrรณnicos de phishing utilizan cada vez mรกs archivos adjuntos SVG para evadir la detecciรณn
https://blog.segu-info.com.ar/2024/11/correos-electronicos-de-phishing.html
โค1๐Ÿ”ฅ1๐Ÿ‘1
Aquรญ Elonmuss te enseรฑa a hacerte millonario!
https://x.com/SeguInfo/status/1859024598530138143
๐Ÿ˜6๐Ÿคฏ3๐Ÿ”ฅ1
๐Ÿ”ฅ1
Sabotaje en el Bรกltico: cables de datos cortados entre Finlandia y Alemania
https://blog.segu-info.com.ar/2024/11/sabotaje-en-el-baltico-cables-de-datos.html
๐Ÿ”ฅ7
Nuevo Top 25 de errores de programaciรณn de MITRE.
Es muy triste esto! Hace 25 aรฑos que venimos asรญ.
Si programas y eres parte del problema, estudia programaciรณn segura o bรบscate otro trabajo.
๐Ÿ‘9๐Ÿ˜8๐Ÿคฏ2
Recuerden que hace un par de aรฑos publicamos de forma gratuita el curso de la #Certificaciรณn #CISSP completo

๐Ÿ”—https://www.youtube.com/seguinfo
๐Ÿ‘14โค6๐Ÿ‘4
MITRE publica las 25 debilidades de software mรกs peligrosas de 2024 (CWE)
https://blog.segu-info.com.ar/2024/11/mitre-publica-las-25-debilidades-de.html
๐Ÿ‘4
Firewalls Palo Alto comprometidos por vulnerabilidad Zero-Day
https://blog.segu-info.com.ar/2024/11/firewalls-palo-alto-comprometidos-por.html
๐Ÿ‘1๐Ÿ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
Mรกs info sobre #Quishing porque hay mucho humo. El cartel es el mismo, el QR es distinto.
El QR solo *no* hace nada!
Al escanearlo brinda un enlace. Si ingresas, lo que suceDรA se vรฉ en๐Ÿ“ฝ (solo si entras).
El comportamiento puede cambiar de acuerdo al enlace que te toque.

๐Ÿ”—https://x.com/SeguInfo/status/1859740307241435575
๐Ÿ‘11๐Ÿ‘1
Forwarded from Alfonso Muรฑoz
๐Ÿ‘2
Fallo en el diseรฑo de la VPN de Fortinet oculta ataques de fuerza bruta exitosos
https://blog.segu-info.com.ar/2024/11/fallo-en-el-diseno-de-la-vpn-de.html
๐Ÿคฌ4๐Ÿ”ฅ1
Cross-site Scripting (XSS) es la debilidad mรกs comรบn de 2024 (ยฟNO TE DA VERGรœENZA?)
https://blog.segu-info.com.ar/2024/11/cross-site-scripting-xss-es-la.html
๐Ÿ‘2๐Ÿ‘Ž1
Si estas por Paranรก o la zona, venite (24, 25 y 26/11).

๐Ÿ”—https://linktr.ee/conertech

Desde la Laboratorio de Seguridad (LASI) de la Univ. Autรณnoma de Entre Rรญos vamos a presentar las investigaciones realizadas este aรฑo!

Sรญ, tambiรฉn hablaremos de inseguridad en IA.
๐Ÿ‘8โค6