Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
El repositorio PyPI hace que la seguridad 2FA sea obligatoria para proyectos críticos de Python
https://cdn-images-1.medium.com/max/1543/0*a03vhvqLPK5CHf-h
PUBLICADO EN 11 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
El repositorio PyPI hace que la seguridad 2FA sea obligatoria para proyectos críticos de Python
https://cdn-images-1.medium.com/max/1543/0*a03vhvqLPK5CHf-h
PUBLICADO EN 11 JULIO, 2022POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
El repositorio PyPI hace que la seguridad 2FA sea obligatoria para proyectos críticos de Python
PUBLICADO EN 11 JULIO, 2022POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Two Novel Crypto Wallet Exploits, Explained
https://cdn-images-1.medium.com/max/2600/1*-IaCCmTCh8g71EBcRYyxHQ.png
At the ‘Off the Chain’ Web3 security conference in San Francisco in June, Unciphered–a cryptocurrency asset recovery company–unveiled…
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Two Novel Crypto Wallet Exploits, Explained
https://cdn-images-1.medium.com/max/2600/1*-IaCCmTCh8g71EBcRYyxHQ.png
At the ‘Off the Chain’ Web3 security conference in San Francisco in June, Unciphered–a cryptocurrency asset recovery company–unveiled…
Continue reading on Immunefi »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Two Novel Crypto Wallet Exploits, Explained
At the ‘Off the Chain’ Web3 security conference in San Francisco in June, Unciphered–a cryptocurrency asset recovery company–unveiled three…
hacking: security in practice
RF hacking cheap security
What method(s) could be used to interfere with the video and audio of a small/inexpensive security camera system with no internet capabilities?
Note: this is something we think was done to us along with other things.
submitted by /u/Awkward-Divide736
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
RF hacking cheap security
What method(s) could be used to interfere with the video and audio of a small/inexpensive security camera system with no internet capabilities?
Note: this is something we think was done to us along with other things.
submitted by /u/Awkward-Divide736
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
RF hacking cheap security
What method(s) could be used to interfere with the video and audio of a small/inexpensive security camera system with no internet capabilities?...
hacking: security in practice
Getting into hacking for work
___________________________
@hacking_Attack
@Hacking_Video
Getting into hacking for work
___________________________
@hacking_Attack
@Hacking_Video
reddit
Getting into hacking for work
I’m a beginner and I want to get into hacking as a job. I wanted some advice from people who were able to get hacking jobs without certs, and also...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
the most badass song I've ever heard
submitted by /u/Relative-Raspberry64
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
the most badass song I've ever heard
submitted by /u/Relative-Raspberry64
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
the most badass song I've ever heard
Posted in r/hacking by u/Relative-Raspberry64 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
what do you think about mark zuckerberg?
https://external-preview.redd.it/UNQ-bH6eBV5s49kyUBQANbPshTP_lIz4AIBQiD6wJfw.jpg?width=320&crop=smart&auto=webp&s=c477fb83bec540f8a0a03cf214a3e57c604df4be submitted by /u/Relative-Raspberry64
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
what do you think about mark zuckerberg?
https://external-preview.redd.it/UNQ-bH6eBV5s49kyUBQANbPshTP_lIz4AIBQiD6wJfw.jpg?width=320&crop=smart&auto=webp&s=c477fb83bec540f8a0a03cf214a3e57c604df4be submitted by /u/Relative-Raspberry64
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
what do you think about mark zuckerberg?
Posted in r/hacking by u/Relative-Raspberry64 • 1 point and 0 comments
Hacking on a Private Program (Salseforce crm)
https://thinkermaruf.medium.com/hacking-on-a-private-program-salseforce-crm-12bfef43fcc7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://thinkermaruf.medium.com/hacking-on-a-private-program-salseforce-crm-12bfef43fcc7?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking on a Private Program (Salseforce crm)
I was hunting on a private program of HackerOne so lets call it developer.target.com i found a register option so i registered there after…
I was hunting on a private program of HackerOne so lets call it developer.target.com i found a register option so i registered there after…Continue reading on Medium » (https://thinkermaruf.medium.com/hacking-on-a-private-program-salseforce-crm-12bfef43fcc7?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking on a Private Program (Salseforce crm)
I was hunting on a private program of HackerOne so lets call it developer.target.com i found a register option so i registered there after…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Mutt mutt_decode_uuencoded() Memory Disclosure
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
In mutt_decode_uuencoded(), the line length is read from the untrusted uuencoded part without validation. This could result in including private memory in replys, for example fragments of other messages, passphrases or keys.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Mutt mutt_decode_uuencoded() Memory Disclosure
https://2.bp.blogspot.com/-weqZA-ftzQE/WWlvbeJCv3I/AAAAAAAAIPM/_poAex3uv6ENktRwTJkjqdNNBZYRKBnvQCLcBGAs/s1600/h74.png
In mutt_decode_uuencoded(), the line length is read from the untrusted uuencoded part without validation. This could result in including private memory in replys, for example fragments of other messages, passphrases or keys.
SHA-256 |
1a0da9d9e3bf42ea5367e18954311a408e444a40a4960bbf41e240bbab050a63Download
mutt: mutt_decode_uuencoded() can read the past the of the input line
In mutt_decode_uuencoded(), the line length is read from the untrusted uuencoded part without validation. This could result in including private memory in replys, for example fragments of other messages, passphrases or keys.
Reproduce with the following mbox, note that these are literal 0x9f bytes. This should show some uninitialized garbage in the message.
From taviso Thu Mar 31 16:53:55 2022
From: taviso
Subject: mutt_decode_uuencoded test
Content-Disposition: inline
Content-Transfer-Encoding: x-uuencode
Content-Type: text/plain
begin 644 test
<9f
M2&5L;&\\L\"@I)9B!Y;W4@87)E(')E861I;F
M='0L('1H92!N97AT(&QI;F4*
<9f
54&QE87-E(')E
`
end.
This bug is subject to a 90-day disclosure deadline. If a fix for this
issue is made available to users before the end of the 90-day deadline,
this bug report will become public 30 days after the fix was made
available. Otherwise, this bug report will become public at the deadline.
The scheduled deadline is YYYY-MM-DD.
Related CVE Numbers: CVE-2022-1328.
Found by: taviso@google.com
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Mutt mutt_decode_uuencoded() Memory Disclosure
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Xen TLB Flush Bypass
https://4.bp.blogspot.com/-d35B3EKAht8/WWlvR2pVnxI/AAAAAAAAINQ/QZoYmyhkrmYJUUDMjE8TBpD0ovVTkXuuACLcBGAs/s1600/h35.png
Xen's _get_page_type() contains an ABAC cmpxchg() race, where the code incorrectly assumes that if it reads a specific type_info value, and then later cmpxchg() succeeds, the type_info can't have changed in between.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Xen TLB Flush Bypass
https://4.bp.blogspot.com/-d35B3EKAht8/WWlvR2pVnxI/AAAAAAAAINQ/QZoYmyhkrmYJUUDMjE8TBpD0ovVTkXuuACLcBGAs/s1600/h35.png
Xen's _get_page_type() contains an ABAC cmpxchg() race, where the code incorrectly assumes that if it reads a specific type_info value, and then later cmpxchg() succeeds, the type_info can't have changed in between.
SHA-256 |
88fe91f31a1fa5b68860cd0112d829c44076320a17d995120f8a3d426cc59af7Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Xen TLB Flush Bypass
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Exploit Collector
Chrome PaintImage Deserialization Out-Of-Bounds Read
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
The code in cc::PaintImageReader::Read (cc::PaintImage*) does not properly check the incoming data when handling embedded image data, resulting in an out-of-bounds copy into the filter bitmap data.
SHA-256 |
Download
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Chrome PaintImage Deserialization Out-Of-Bounds Read
https://4.bp.blogspot.com/-rlkVZrkp7Nk/WWlvMMd1AsI/AAAAAAAAIMM/kgTZoxpDP8Ypbt5o2Ma3tAKenLk3_TLPQCLcBGAs/s1600/h18.png
The code in cc::PaintImageReader::Read (cc::PaintImage*) does not properly check the incoming data when handling embedded image data, resulting in an out-of-bounds copy into the filter bitmap data.
SHA-256 |
3442a632be9dec3260619421059a97062f1e5b5331769ad612a11a97ecf3ec9bDownload
Source:packetstormsecurity.com
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Chrome PaintImage Deserialization Out-Of-Bounds Read
Exploit Collector is the ultimate collection of public exploits and exploitable vulnerabilities. Remote/Local Exploits, Shellcode and 0days.