Zero-Day: Navigating the Storm of CVE-2024–21893 in Ivanti Products
https://systemweakness.com/zero-day-navigating-the-storm-of-cve-2024-21893-in-ivanti-products-3b27078377e2?source=rss------bug_bounty-5
https://systemweakness.com/zero-day-navigating-the-storm-of-cve-2024-21893-in-ivanti-products-3b27078377e2?source=rss------bug_bounty-5
A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti UsersContinue reading on System Weakness » (https://systemweakness.com/zero-day-navigating-the-storm-of-cve-2024-21893-in-ivanti-products-3b27078377e2?source=rss------bug_bounty-5)
Zero-Day: Navigating the Storm of CVE-2024–21893 in Ivanti Products
A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti UsersContinue reading on System Weakness »
Read more...
A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti UsersContinue reading on System Weakness »
Read more...
Medium
Zero-Day: Navigating the Storm of CVE-2024–21893 in Ivanti Products
A Deep Dive into the High-Risk SSRF Vulnerability Affecting Ivanti Users
Collect Active Directory data with Adalanche
https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/
<!-- SC_OFF -->I recently discovered the Adalanche tool (https://youtu.be/PG2J0uILL1Q?si=9aNcoAMca4OTHCW5) and was quite amazed on how easy it is to get it running. I know it's not Bloodhound but still can present real attack paths. I blogged my experience and review on Adalanche and hope you will find this useful (https://lsecqt.github.io/Red-Teaming-Army/active-directory/enumeration/visualizing-acls-with-adalanche/) <!-- SC_ON --> submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://lsecqt.github.io/Red-Teaming-Army/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/)
https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/
<!-- SC_OFF -->I recently discovered the Adalanche tool (https://youtu.be/PG2J0uILL1Q?si=9aNcoAMca4OTHCW5) and was quite amazed on how easy it is to get it running. I know it's not Bloodhound but still can present real attack paths. I blogged my experience and review on Adalanche and hope you will find this useful (https://lsecqt.github.io/Red-Teaming-Army/active-directory/enumeration/visualizing-acls-with-adalanche/) <!-- SC_ON --> submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://lsecqt.github.io/Red-Teaming-Army/) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahqnjp/collect_active_directory_data_with_adalanche/)
Nemesis - An Offensive Data Enrichment Pipeline
http://www.kitploit.com/2024/02/nemesis-offensive-data-enrichment.html
http://www.kitploit.com/2024/02/nemesis-offensive-data-enrichment.html
Nemesis is an offensive data enrichment (https://www.kitploit.com/search/label/Enrichment) pipeline (https://www.kitploit.com/search/label/Pipeline) and operator support system. Built on Kubernetes (https://www.kitploit.com/search/label/Kubernetes) with scale in mind, our goal with Nemesis was to create a centralized data processing platform that ingests data produced during offensive security assessments. Nemesis aims to automate a number of repetitive tasks operators encounter on engagements, empower operators’ analytic capabilities and collective knowledge, and create structured and unstructured data stores of as much operational data as possible to help guide future research (https://www.kitploit.com/search/label/Research) and facilitate offensive data analysis.
Setup / Installation See the setup instructions (https://github.com/SpecterOps/Nemesis/blob/main/docs/setup.md). Contributing / Development Environment Setup See development.md (https://github.com/SpecterOps/Nemesis/blob/main/docs/development.md) Further Reading Post Name Publication Date Link Hacking With Your Nemesis Aug 9, 2023 https://posts.specterops.io/hacking-with-your-nemesis-7861f75fcab4 Challenges In Post-Exploitation (https://www.kitploit.com/search/label/Post-Exploitation) Workflows Aug 2, 2023 https://posts.specterops.io/challenges-in-post-exploitation-workflows-2b3469810fe9 On (Structured) Data Jul 26, 2023 https://posts.specterops.io/on-structured-data-707b7d9876c6 Acknowledgments Nemesis is built on large chunk of other people's work. Throughout the codebase we've provided citations, references, and applicable licenses for anything used or adapted from public sources. If we're forgotten proper credit anywhere, please let us know or submit a pull request! We also want to acknowledge Evan McBroom, Hope Walker, and Carlo Alcantara from SpecterOps for their help with the initial Nemesis concept and amazing feedback throughout the development process.
Download Nemesis (https://github.com/SpecterOps/Nemesis)
Setup / Installation See the setup instructions (https://github.com/SpecterOps/Nemesis/blob/main/docs/setup.md). Contributing / Development Environment Setup See development.md (https://github.com/SpecterOps/Nemesis/blob/main/docs/development.md) Further Reading Post Name Publication Date Link Hacking With Your Nemesis Aug 9, 2023 https://posts.specterops.io/hacking-with-your-nemesis-7861f75fcab4 Challenges In Post-Exploitation (https://www.kitploit.com/search/label/Post-Exploitation) Workflows Aug 2, 2023 https://posts.specterops.io/challenges-in-post-exploitation-workflows-2b3469810fe9 On (Structured) Data Jul 26, 2023 https://posts.specterops.io/on-structured-data-707b7d9876c6 Acknowledgments Nemesis is built on large chunk of other people's work. Throughout the codebase we've provided citations, references, and applicable licenses for anything used or adapted from public sources. If we're forgotten proper credit anywhere, please let us know or submit a pull request! We also want to acknowledge Evan McBroom, Hope Walker, and Carlo Alcantara from SpecterOps for their help with the initial Nemesis concept and amazing feedback throughout the development process.
Download Nemesis (https://github.com/SpecterOps/Nemesis)
A Story of an IDOR bug I found on a SaaS application
IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…Continue reading on Medium »
Read more...
IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…Continue reading on Medium »
Read more...
Medium
A Story of an IDOR bug I found on a SaaS application
IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…
A Story of an IDOR bug I found on a SaaS application
https://medium.com/@duncanochieng682/a-story-of-an-idor-bug-i-found-on-a-saas-application-28fa65907bfd?source=rss------bug_bounty-5
https://medium.com/@duncanochieng682/a-story-of-an-idor-bug-i-found-on-a-saas-application-28fa65907bfd?source=rss------bug_bounty-5
IDORs. If you’re reading this, it’s probably too late! Haha.. I’m just messing with you. If you’re reading this, you probably know a thing…Continue reading on Medium » (https://medium.com/@duncanochieng682/a-story-of-an-idor-bug-i-found-on-a-saas-application-28fa65907bfd?source=rss------bug_bounty-5)
Version Control History and Information Disclosure Vulnerabilities | 2024
Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan NagarajContinue reading on Medium »
Read more...
Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan NagarajContinue reading on Medium »
Read more...
Medium
Version Control History and Information Disclosure Vulnerabilities | 2024
Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan Nagaraj
Does anyone have any tips on how to make a successful Kickstarter campaign about a cybersecurity learning website? Sorry if this is the wrong subreddit...
https://www.reddit.com/r/redteamsec/comments/1ahx3d8/does_anyone_have_any_tips_on_how_to_make_a/
submitted by /u/are-on-reddit (https://www.reddit.com/user/are-on-reddit)
[link] (https://www.kickstarter.com/projects/pwner/pwnguide-your-guide-to-pwning-stuff) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahx3d8/does_anyone_have_any_tips_on_how_to_make_a/)
https://www.reddit.com/r/redteamsec/comments/1ahx3d8/does_anyone_have_any_tips_on_how_to_make_a/
submitted by /u/are-on-reddit (https://www.reddit.com/user/are-on-reddit)
[link] (https://www.kickstarter.com/projects/pwner/pwnguide-your-guide-to-pwning-stuff) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahx3d8/does_anyone_have_any_tips_on_how_to_make_a/)
Exactly 1 year to our open source product - API Discovery and Scanning
https://www.reddit.com/r/redteamsec/comments/1ahzdpl/exactly_1_year_to_our_open_source_product_api/
<!-- SC_OFF -->I feel proud of what we have built! <!-- SC_ON --> submitted by /u/Previous_Piano9488 (https://www.reddit.com/user/Previous_Piano9488)
[link] (https://github.com/akto-api-security/akto) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahzdpl/exactly_1_year_to_our_open_source_product_api/)
https://www.reddit.com/r/redteamsec/comments/1ahzdpl/exactly_1_year_to_our_open_source_product_api/
<!-- SC_OFF -->I feel proud of what we have built! <!-- SC_ON --> submitted by /u/Previous_Piano9488 (https://www.reddit.com/user/Previous_Piano9488)
[link] (https://github.com/akto-api-security/akto) [comments] (https://www.reddit.com/r/redteamsec/comments/1ahzdpl/exactly_1_year_to_our_open_source_product_api/)
Version Control History and Information Disclosure Vulnerabilities | 2024
https://cyberw1ng.medium.com/version-control-history-and-information-disclosure-vulnerabilities-2024-3649060333bb?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/version-control-history-and-information-disclosure-vulnerabilities-2024-3649060333bb?source=rss------bug_bounty-5
Virtually all websites are developed using some form of version control system, such as Git. Let’s Explore that | Karthikeyan NagarajContinue reading on Medium » (https://cyberw1ng.medium.com/version-control-history-and-information-disclosure-vulnerabilities-2024-3649060333bb?source=rss------bug_bounty-5)
This will change the way you hunt for bugs forever.
Common mistake that people make when they just learn about few web vulnerabilities is the actual approach to the target. There are a lot…Continue reading on Medium »
Read more...
Common mistake that people make when they just learn about few web vulnerabilities is the actual approach to the target. There are a lot…Continue reading on Medium »
Read more...
Medium
This will change the way you hunt for bugs.
Common mistake that people make when they just learn about few web vulnerabilities is the actual approach to the target. There are a lot…
This will change the way you hunt for bugs forever.
https://medium.com/@deadoverflow/this-will-change-the-way-you-hunt-for-bugs-forever-6111f59b4e8b?source=rss------bug_bounty-5
https://medium.com/@deadoverflow/this-will-change-the-way-you-hunt-for-bugs-forever-6111f59b4e8b?source=rss------bug_bounty-5