cKure Red
2.4K subscribers
70 photos
34 videos
21 files
451 links
The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Download Telegram
cKure Red pinned «RCE (remote account / vehicle takeover) using CRLF, chained bugs. Interesting thread. https://twitter.com/samwcyo/status/1597695281881296897»
GitHub dorks.
● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates.

This is not the official def. Will wait for researcher to share details.
cKure Red pinned «● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details.»
cKure Red
● Exclusive - Zero-Day: A critical security vulnerability has been identified in appviewx. It can be used to spoof certificates. This is not the official def. Will wait for researcher to share details.
Impact of the Zero-Day (mentioned here: https://t.me/ckuRED/231).

Enrollment: An adversary can issue a certificate from the CA and later use that for hosting fake websites that all the clients of that firm under attack will automatically trust.

Revocation: An adversary can bring down any website /application by just getting the public certificate of that application.

Optionally, if you have to plan big, discover all applications, download the public certificate, and at once revoke all.
Reverse shell with the XOR encryption for the communication between server/client, but now with C#.

https://twitter.com/zux0x3a/status/1609592330373455872

https://github.com/0xsp-SRD/0xsp.com/tree/main/rev_shell_xor_enc
● Goggle's answer to disinformation.

https://toolbox.google.com/factcheck/explorer
cKure Red pinned «A simple script as malware that will turn off the firewall, start an HTTP server, forward its port through 'ngrok' and send the URL of the server through a Telegram bot. https://github.com/usdchef/malvinci»
Privacy-Breach: United States 🇺🇸

The IRS has paid an Israeli 🇮🇱 company! 'Cobwebs Technologies' hundreds of thousands of dollars for an internet investigative tool that allows the IRS to conduct undercover investigations online, according to internal IRS documents obtained by Motherboard.

vice.com/en/article/xgynn4/company-helping-irs-go-undercover-cobwebs-technologies