■■□□□ #UnitedStates' #DoD
By cablej\_dds
https://hackerone.com/reports/496326
Disclosed at: 2020-05-11 16:47:33 UTC+0
Created at: 2019-02-15 01:56:00 UTC+0
By cablej\_dds
█████████ \- Insecure download cookie generation allows bypass of CAC authentication, access to deleted and locked files https://hackerone.com/reports/496326
Disclosed at: 2020-05-11 16:47:33 UTC+0
Created at: 2019-02-15 01:56:00 UTC+0
HackerOne
U.S. Dept Of Defense disclosed on HackerOne: █████████ - Insecure...
**Summary:**
To download a file, ████ directs users to `/ ██████████/Download.aspx` and sets a cookie authenticating the download. The cookie looks like...
To download a file, ████ directs users to `/ ██████████/Download.aspx` and sets a cookie authenticating the download. The cookie looks like...
■■■■□ Darknet Diaries: Psychological Operations aka #PsyOps aka Mind hacking.
#UnitedStates #military #propaganda #disinformation #fakenews
https://darknetdiaries.com/episode/65
#UnitedStates #military #propaganda #disinformation #fakenews
https://darknetdiaries.com/episode/65
Darknetdiaries
PSYOP – Darknet Diaries
PSYOP, or Psychological Operations, is something the US military has been doing to foreign audiences for decades. But what exactly is it? And what's the difference between white, gray, and black PS...
■■■□□ $3,000 #CodeQL query for finding #LDAP #Injection - #Github Security Lab - Hackerone
https://www.youtube.com/watch?v=qStzSfsEQGQ
https://www.youtube.com/watch?v=qStzSfsEQGQ
■■■■■ #XSS in #Facebook's login button.
https://portswigger.net/daily-swig/amp/xss-vulnerability-in-login-with-facebook-button-earns-20-000-bug-bounty
https://portswigger.net/daily-swig/amp/xss-vulnerability-in-login-with-facebook-button-earns-20-000-bug-bounty
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
■■■□□ Authentication Token Obtain and Replace (#ATOR) Burp Plugin: Fast and Reliable plugin to handle Complex Login Sequences
https://medium.com/@kashwathkumar/authentication-token-obtain-and-replace-ator-burp-plugin-fast-and-reliable-plugin-to-handle-b19e3621c6a7
https://medium.com/@kashwathkumar/authentication-token-obtain-and-replace-ator-burp-plugin-fast-and-reliable-plugin-to-handle-b19e3621c6a7
Medium
Authentication Token Obtain and Replace (ATOR) Burp Plugin: Fast and Reliable plugin to handle…
Problem Statement:
■■■■■ #United States' government Vote #FBI to Look at Your Web Browsing History Without a Warrant
#privacy #NSA
https://www.vice.com/amp/en_us/article/jgxxvk/senate-votes-to-allow-fbi-to-look-at-your-web-browsing-history-without-a-warrant
#privacy #NSA
https://www.vice.com/amp/en_us/article/jgxxvk/senate-votes-to-allow-fbi-to-look-at-your-web-browsing-history-without-a-warrant
VICE
Senate Votes to Allow FBI to Look at Your Web Browsing History Without a Warrant
Lawmakers voted down a measure that would prevent law enforcement from spying on Americans’ internet habits.
■■■□□ CVE-2020-1054 • Windows 10 x64 1909 • 10.0.18362.657 (WinBuild.160101.0800) • Out Of Bounds Write
Reported on 27-Feb-20 by Yoav Alon, Netanel Ben-Simon
https://cpr-zero.checkpoint.com/vulns/cprid-2153/
Reported on 27-Feb-20 by Yoav Alon, Netanel Ben-Simon
https://cpr-zero.checkpoint.com/vulns/cprid-2153/
CPR-Zero
CPR-Zero: Yoav Alon
Check Point Research Vulnerability Repository
■■■□□ Statistics: Windows commands misused by attackers
https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html
https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html
JPCERT/CC Eyes
Windows Commands Abused by Attackers - JPCERT/CC Eyes
Hello again, this is Shusei Tomonaga from the Analysis Center. In Windows OS, various commands (hereafter “Windows commands”) are installed by default. However, what is actually used by general users is just a small part of it. On the other...
■■■□□ Windows System Call Tables (NT/2000/XP/2003/Vista/2008/7/2012/8/10)
https://github.com/j00ru/windows-syscalls
https://github.com/j00ru/windows-syscalls
GitHub
GitHub - j00ru/windows-syscalls: Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11)
Windows System Call Tables (NT/2000/XP/2003/Vista/7/8/10/11) - j00ru/windows-syscalls
■■■□□ How To Scan #AWS's Entire IP Range to Recon SSL Certificates
https://www.daehee.com/scan-aws-ip-ssl-certificates/
https://www.daehee.com/scan-aws-ip-ssl-certificates/
■■■■□ Analysis of a Dridex Downloader with Locked Excel Macros.
https://security-soup.net/analysis-of-a-dridex-downloader-with-locked-excel-macros/
https://security-soup.net/analysis-of-a-dridex-downloader-with-locked-excel-macros/
Security Soup
Analysis of a Dridex Downloader with Locked Excel Macros
Summary I came across a fairly interesting Dridex maldoc the other day, and I figured it was worth doing a quick write-up on the obfuscation and anti-analysis techniques I saw. This was an Excel do…
■□□□□ Flipper Zero — Tamagotchi for Hacker. Fully opensource and customizable device for pentesters and geeks in Tamagotchi body It has built-in 315/433/866MHz transceiver to control and sniff stuff like garage door, car alarams, etc. 125kHz and iButton module to read/write and emulate proximity cards. Infrared transceiver to control any TV’s. Also compatible with Arduino IDE and PlatformIO so you can write your own firmware extentions.
https://flipperzero.one
https://flipperzero.one
Flipper
Flipper Zero — Portable Multi-tool Device for Geeks
Flipper Zero is a versatile multi-tool, based on ultra low power STM32 MCU for daily exploring of access control systems and radio protocols. Fully open source and customisable.