Forwarded from DailyCVE
๐ด WhoDB, Critical DoS Vulnerability (#CVE-TBD)
https://dailycve.com/whodb-critical-dos-vulnerability-cve-tbd/
@DailyCVE
https://dailycve.com/whodb-critical-dos-vulnerability-cve-tbd/
@DailyCVE
DailyCVE
WhoDB, Critical DoS Vulnerability (CVE-TBD) - DailyCVE
2024-12-19 Platform: WhoDB Version: All versions up to v0.43.0 Vulnerability: Denial-of-Service (DoS) Severity: Critical Date: Not specified What Undercode Says: [โฆ]
Forwarded from DailyCVE
๐ต Astro, Source Map Disclosure (Low)
https://dailycve.com/astro-source-map-disclosure-low/
@Daily_CVE
https://dailycve.com/astro-source-map-disclosure-low/
@Daily_CVE
DailyCVE
Astro, Source Map Disclosure (Low) - DailyCVE
2024-12-19 Form: Platform: Astro Version: Server-output: 5.0.3 โ 5.0.6 Static-output: 4.16.17 or older & 5.0.7 or older Vulnerability: Source Map [โฆ]
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
A Generational Divide: Etiquette in the #Digital Age
https://undercodenews.com/a-generational-divide-etiquette-in-the-digital-age/
@Undercode_News
https://undercodenews.com/a-generational-divide-etiquette-in-the-digital-age/
@Undercode_News
UNDERCODE NEWS
A Generational Divide: Etiquette in the Digital Age - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆSSO (Single Sign-On) Explained.
SSO can be thought of as a master key to open all different locks. It allows a user to log in to different systems using a single set of credentials.
In a time where we are accessing more applications than ever before, this is a big help to mitigate password fatigue and streamlines user experience.
To fully understand the SSO process, ๐น๐ฒ๐โ๐ ๐๐ฎ๐ธ๐ฒ ๐ฎ ๐น๐ผ๐ผ๐ธ ๐ฎ๐ ๐ต๐ผ๐ ๐ฎ ๐๐๐ฒ๐ฟ ๐๐ผ๐๐น๐ฑ ๐น๐ผ๐ด ๐ถ๐ป๐๐ผ ๐๐ถ๐ป๐ธ๐ฒ๐ฑ๐๐ป ๐๐๐ถ๐ป๐ด ๐๐ผ๐ผ๐ด๐น๐ฒ ๐ฎ๐ ๐๐ต๐ฒ ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐ฝ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ:
๐ญ) ๐จ๐๐ฒ๐ฟ ๐ฟ๐ฒ๐พ๐๐ฒ๐๐๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐
First, the user would attempt to access the Service Provider (LinkedIn). At this point, a user would be presented with login options, and in this example, they would select "Sign in with Google".
๐ฎ) ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฟ๐ฒ๐พ๐๐ฒ๐๐
From here, the Service Provider (LinkedIn) will redirect the user to the Identity Provider (Google) with an authentication request.
๐ฏ) ๐๐ฑ๐ฃ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฐ๐๐ถ๐๐ฒ ๐๐ฒ๐๐๐ถ๐ผ๐ป
Once the Identity Provider (Google) has received the request, it will check for an active session. If it doesn't find one, authentication will be requested.
๐ฐ) ๐จ๐๐ฒ๐ฟ ๐๐๐ฏ๐บ๐ถ๐๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐
At this stage, the user will submit their login credentials (username and password) to the Identity Provider (IdP).
๐ฑ) ๐๐ฑ๐ฃ ๐๐ฒ๐ฟ๐ถ๐ณ๐ถ๐ฒ๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐
The Identity Provider will then verify the submitted credentials against its User Directory (database). If the credentials are correct, the IdP will create an authentication token or assertion.
๐ฒ) ๐๐ฑ๐ฃ ๐๐ฒ๐ป๐ฑ๐ ๐๐ผ๐ธ๐ฒ๐ป ๐๐ผ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ
Once the token or assertion has been created, the IdP sends it back to the Service Provider confirming the user's identity. The user is now authenticated and can access the Service Provier (LinkedIn).
๐ณ) ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ด๐ฟ๐ฎ๐ป๐๐ฒ๐ฑ ๐๐๐ถ๐ป๐ด ๐ฒ๐ ๐ถ๐๐๐ถ๐ป๐ด ๐๐ฒ๐๐๐ถ๐ผ๐ป
Since the Identity Provider has established a session, when the user goes to access a different Service Provider (eg; GitHub), they won't need to re-enter their credentials. Future service providers will request authentication from the Identity Provider, recognize the existing session, and grant access to the user based on the previously authenticated session.
SSO workflows like the above operate on SSO protocols, which are a set of rules that govern how the IdP and SP communicate and trust each other. Common protocols include Security Assertion Markup Language (SAML), OpenID Connect, and OAuth.
๐ญ What's your favourite way to go about authentication? ๐ฌ
Ref: Nikki SiapnoNikki Siapno
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
SSO can be thought of as a master key to open all different locks. It allows a user to log in to different systems using a single set of credentials.
In a time where we are accessing more applications than ever before, this is a big help to mitigate password fatigue and streamlines user experience.
To fully understand the SSO process, ๐น๐ฒ๐โ๐ ๐๐ฎ๐ธ๐ฒ ๐ฎ ๐น๐ผ๐ผ๐ธ ๐ฎ๐ ๐ต๐ผ๐ ๐ฎ ๐๐๐ฒ๐ฟ ๐๐ผ๐๐น๐ฑ ๐น๐ผ๐ด ๐ถ๐ป๐๐ผ ๐๐ถ๐ป๐ธ๐ฒ๐ฑ๐๐ป ๐๐๐ถ๐ป๐ด ๐๐ผ๐ผ๐ด๐น๐ฒ ๐ฎ๐ ๐๐ต๐ฒ ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐ฝ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ:
๐ญ) ๐จ๐๐ฒ๐ฟ ๐ฟ๐ฒ๐พ๐๐ฒ๐๐๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐
First, the user would attempt to access the Service Provider (LinkedIn). At this point, a user would be presented with login options, and in this example, they would select "Sign in with Google".
๐ฎ) ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป ๐ฟ๐ฒ๐พ๐๐ฒ๐๐
From here, the Service Provider (LinkedIn) will redirect the user to the Identity Provider (Google) with an authentication request.
๐ฏ) ๐๐ฑ๐ฃ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐ ๐ณ๐ผ๐ฟ ๐ฎ๐ฐ๐๐ถ๐๐ฒ ๐๐ฒ๐๐๐ถ๐ผ๐ป
Once the Identity Provider (Google) has received the request, it will check for an active session. If it doesn't find one, authentication will be requested.
๐ฐ) ๐จ๐๐ฒ๐ฟ ๐๐๐ฏ๐บ๐ถ๐๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐
At this stage, the user will submit their login credentials (username and password) to the Identity Provider (IdP).
๐ฑ) ๐๐ฑ๐ฃ ๐๐ฒ๐ฟ๐ถ๐ณ๐ถ๐ฒ๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐
The Identity Provider will then verify the submitted credentials against its User Directory (database). If the credentials are correct, the IdP will create an authentication token or assertion.
๐ฒ) ๐๐ฑ๐ฃ ๐๐ฒ๐ป๐ฑ๐ ๐๐ผ๐ธ๐ฒ๐ป ๐๐ผ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ ๐ฃ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ฟ
Once the token or assertion has been created, the IdP sends it back to the Service Provider confirming the user's identity. The user is now authenticated and can access the Service Provier (LinkedIn).
๐ณ) ๐๐ฐ๐ฐ๐ฒ๐๐ ๐ด๐ฟ๐ฎ๐ป๐๐ฒ๐ฑ ๐๐๐ถ๐ป๐ด ๐ฒ๐ ๐ถ๐๐๐ถ๐ป๐ด ๐๐ฒ๐๐๐ถ๐ผ๐ป
Since the Identity Provider has established a session, when the user goes to access a different Service Provider (eg; GitHub), they won't need to re-enter their credentials. Future service providers will request authentication from the Identity Provider, recognize the existing session, and grant access to the user based on the previously authenticated session.
SSO workflows like the above operate on SSO protocols, which are a set of rules that govern how the IdP and SP communicate and trust each other. Common protocols include Security Assertion Markup Language (SAML), OpenID Connect, and OAuth.
๐ญ What's your favourite way to go about authentication? ๐ฌ
Ref: Nikki SiapnoNikki Siapno
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Ukrainian Cybercriminal Sentenced to Five Years in Prison for Raccoon Infostealer
https://undercodenews.com/ukrainian-cybercriminal-sentenced-to-five-years-in-prison-for-raccoon-infostealer/
@Undercode_News
https://undercodenews.com/ukrainian-cybercriminal-sentenced-to-five-years-in-prison-for-raccoon-infostealer/
@Undercode_News
UNDERCODE NEWS
Ukrainian Cybercriminal Sentenced to Five Years in Prison for Raccoon Infostealer - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE TESTING
google_hacking_dorks_basic.pdf
599 KB
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ค #Tesla Revs Up for Robotaxi Launch: Austin in the Driver's Seat?
https://undercodenews.com/tesla-revs-up-for-robotaxi-launch-austin-in-the-drivers-seat/
@Undercode_News
https://undercodenews.com/tesla-revs-up-for-robotaxi-launch-austin-in-the-drivers-seat/
@Undercode_News
UNDERCODE NEWS
Tesla Revs Up for Robotaxi Launch: Austin in the Driver's Seat? - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
UNDERCODE NEWS
AI and GDPR: A Balancing Act - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฆExtracting information remotely from Microsoft Remote Desktop Web Access (RDWA) with RDWAtool
๐ Microsoft Remote Desktop Web Access (RDWA) applications are often overlooked yet can be a treasure trove of information for attackers. RDWAtool is a Python-based all-in-one tool designed to analyze and test RDWA instances for vulnerabilities while extracting valuable insights.
๐ What can RDWAtool do?
1๏ธโฃ Extract useful Information in black box remotely:
- FQDN of the remote server to map the environment.
- Internal AD domain name derived from the FQDN.
- Remote Windows Server version for targeted exploitation.
In brute mode:
> Free <
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ Microsoft Remote Desktop Web Access (RDWA) applications are often overlooked yet can be a treasure trove of information for attackers. RDWAtool is a Python-based all-in-one tool designed to analyze and test RDWA instances for vulnerabilities while extracting valuable insights.
๐ What can RDWAtool do?
1๏ธโฃ Extract useful Information in black box remotely:
- FQDN of the remote server to map the environment.
- Internal AD domain name derived from the FQDN.
- Remote Windows Server version for targeted exploitation.
In spray mode:
rdwatool spray -tu https://rds.podalirius.net/RDWeb/Pages/en-US/login.aspx
In brute mode:
rdwatool brute -tu https://rds.podalirius.net/RDWeb/Pages/en-US/login.aspx
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Daring Duo Conduct Spacewalk: Upgrading the International Space Station
https://undercodenews.com/daring-duo-conduct-spacewalk-upgrading-the-international-space-station/
@Undercode_News
https://undercodenews.com/daring-duo-conduct-spacewalk-upgrading-the-international-space-station/
@Undercode_News
UNDERCODE NEWS
Daring Duo Conduct Spacewalk: Upgrading the International Space Station - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
#Samsung's 2025 TV Lineup Leaks Ahead of CES 2025 Launch
https://undercodenews.com/samsungs-2025-tv-lineup-leaks-ahead-of-ces-2025-launch/
@Undercode_News
https://undercodenews.com/samsungs-2025-tv-lineup-leaks-ahead-of-ces-2025-launch/
@Undercode_News
UNDERCODE NEWS
Samsung's 2025 TV Lineup Leaks Ahead of CES 2025 Launch - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
#Gemini API Competition: A Showcase of Innovation
https://undercodenews.com/gemini-api-competition-a-showcase-of-innovation/
@Undercode_News
https://undercodenews.com/gemini-api-competition-a-showcase-of-innovation/
@Undercode_News
UNDERCODE NEWS
Gemini API Competition: A Showcase of Innovation - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from Exploiting Crew (Pr1vAt3)
This media is not supported in your browser
VIEW IN TELEGRAM
Forwarded from Exploiting Crew (Pr1vAt3)
๐ฆ๐ฐ Cost Savings: SSE vs. SASE Simplified!
๐ Organizations leveraging Palo Alto Networks experience significant ROI through unified management and simplified operationsโall within a single pane of glass.
Streamline your security strategy while accelerating growth!
Whatโs the Difference?
๐ SSE (Security Service Edge):
Focuses on securing access to apps and data for remote and on-premises users.
Core features: SWG, CASB, and ZTNA for seamless, secure connectivity.
๐ SASE (Secure Access Service Edge):
Combines networking (SD-WAN) and security services in a single cloud-delivered solution.
Perfect for securing distributed users and sites with optimal performance.
Why Choose Palo Alto Networks?
โ๏ธ Unified platform for better visibility and control.
โ๏ธ Simplified operations with scalable solutions for all use cases.
โ๏ธ Future-ready security with proven innovation.
Letโs make security smarter, faster, and simplerโtogether!
Ref: Dhari A.Dhari A.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
๐ Organizations leveraging Palo Alto Networks experience significant ROI through unified management and simplified operationsโall within a single pane of glass.
Streamline your security strategy while accelerating growth!
Whatโs the Difference?
๐ SSE (Security Service Edge):
Focuses on securing access to apps and data for remote and on-premises users.
Core features: SWG, CASB, and ZTNA for seamless, secure connectivity.
๐ SASE (Secure Access Service Edge):
Combines networking (SD-WAN) and security services in a single cloud-delivered solution.
Perfect for securing distributed users and sites with optimal performance.
Why Choose Palo Alto Networks?
โ๏ธ Unified platform for better visibility and control.
โ๏ธ Simplified operations with scalable solutions for all use cases.
โ๏ธ Future-ready security with proven innovation.
Letโs make security smarter, faster, and simplerโtogether!
Ref: Dhari A.Dhari A.
@UndercodeCommunity
โ โ โ U๐๐ปโบ๐ซฤ๐ฌ๐โ โ โ โ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
๐ฑ Conquering Your Chaos: Top To-Do List Apps for #Android
https://undercodenews.com/conquering-your-chaos-top-to-do-list-apps-for-android/
@Undercode_News
https://undercodenews.com/conquering-your-chaos-top-to-do-list-apps-for-android/
@Undercode_News
UNDERCODE NEWS
Conquering Your Chaos: Top To-Do List Apps for Android - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
โก๏ธ The 5 Stages of #Digital Twin Development: A Comprehensive Guide
https://undercodenews.com/the-5-stages-of-digital-twin-development-a-comprehensive-guide/
@Undercode_News
https://undercodenews.com/the-5-stages-of-digital-twin-development-a-comprehensive-guide/
@Undercode_News
UNDERCODE NEWS
The 5 Stages of Digital Twin Development: A Comprehensive Guide - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE NEWS (Copyright & Fact Checker)
Lingering Trust? US Organizations Still Using Kaspersky Despite Ban
https://undercodenews.com/lingering-trust-us-organizations-still-using-kaspersky-despite-ban/
@Undercode_News
https://undercodenews.com/lingering-trust-us-organizations-still-using-kaspersky-despite-ban/
@Undercode_News
UNDERCODE NEWS
Lingering Trust? US Organizations Still Using Kaspersky Despite Ban - UNDERCODE NEWS
Undercode News was founded in order to provide the most useful information in the world of hacking and technology. Staffed 24/24 hours, seven days a week by a dedicated team in undercode around the world, so it can provide an environment of information andโฆ
Forwarded from UNDERCODE TESTING
Honeypot_full_+images.pdf
2.4 MB