By living deeply in the present moment we can understand the past better and we can prepare for a better future
Top 10 Vulnerabilities of 2023:
1. CVE-2023-34362: MOVEit Vulnerability
2. CVE-2023-23397: MS Outlook PE
3. CVE-2023-43641: 1-Click RCE on GNOME
4. CVE-2023-28252: Windows CLFS PE
5. CVE-2023-2868: Barracuda ESG CI
6. CVE-2023-26360: Adobe ColdFusion
7. CVE-2023-4966: Citrix Bleed
8. CVE-2023-22952: SugarCRM RCE
9. CVE-2023-24880: Win Smart Screen Bypass
https://www.vicarius.io/vsociety/posts/windows-smartscreen-security-feature-bypass-cve-2023-24880
10. CVE-2022-42475:
FortiOS heap-based buffer overflow in sslvpnd
https://bishopfox.com/blog/exploit-cve-2022-42475
https://github.com/scrt/cve-2022-42475
—— Hackstack Security ——
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Follow Our Page On LinkedIn: https://www.linkedin.com/company/hackstack-security/
Follow Us On Instagram: https://www.instagram.com/hackstacksecurity/
Contact Us: https://hackstacksecure.com/contact
1. CVE-2023-34362: MOVEit Vulnerability
2. CVE-2023-23397: MS Outlook PE
3. CVE-2023-43641: 1-Click RCE on GNOME
4. CVE-2023-28252: Windows CLFS PE
5. CVE-2023-2868: Barracuda ESG CI
6. CVE-2023-26360: Adobe ColdFusion
7. CVE-2023-4966: Citrix Bleed
8. CVE-2023-22952: SugarCRM RCE
9. CVE-2023-24880: Win Smart Screen Bypass
https://www.vicarius.io/vsociety/posts/windows-smartscreen-security-feature-bypass-cve-2023-24880
10. CVE-2022-42475:
FortiOS heap-based buffer overflow in sslvpnd
https://bishopfox.com/blog/exploit-cve-2022-42475
https://github.com/scrt/cve-2022-42475
—— Hackstack Security ——
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Follow Our Page On LinkedIn: https://www.linkedin.com/company/hackstack-security/
Follow Us On Instagram: https://www.instagram.com/hackstacksecurity/
Contact Us: https://hackstacksecure.com/contact
www.vicarius.io
Windows SmartScreen Security Feature bypass (CVE-2023-24880) - vsociety
Are you looking for FREE cybersecurity certifications?
1. Vulnerability Management: https://lnkd.in/g64maMet
2. Global IT Asset Inventory: https://lnkd.in/gXR5bD5N
3. Scanning Strategies: https://lnkd.in/g6cQjQuh
4. Reporting Strategies: https://lnkd.in/gs6Vn-DA
5. Patch Management: https://lnkd.in/gnWVDCNp
6. Policy Compliance: https://lnkd.in/g5SXKncJ
7. PCI Compliance: https://lnkd.in/gZns6Xdf
8. Endpoint Detection & Response: https://lnkd.in/gw22Y__E
9. Vulnerability Management: https://lnkd.in/gYAFfAuT
10. Cloud Security Assessment & Response: https://lnkd.in/grrHivcW
11. API Fundamentals: https://lnkd.in/gngVxhbu
12. Cloud Agent: https://lnkd.in/gngVxhbu
13. Container Security: https://lnkd.in/gYNCGY8A
14. File Integrity Monitoring: https://lnkd.in/gYNCGY8A
15. Web Application Scanning: https://lnkd.in/ggpJ-vG6
Here are 15 FREE courses provided by the Qualys.
https://www.linkedin.com/posts/hackstack-security_cybersecurity-freecourses-infosec-activity-7154837232141402112-4kjb
—— Hackstack Security ——
@hackstacksecurity
Contact Us: https://hackstacksecure.com/contact/
1. Vulnerability Management: https://lnkd.in/g64maMet
2. Global IT Asset Inventory: https://lnkd.in/gXR5bD5N
3. Scanning Strategies: https://lnkd.in/g6cQjQuh
4. Reporting Strategies: https://lnkd.in/gs6Vn-DA
5. Patch Management: https://lnkd.in/gnWVDCNp
6. Policy Compliance: https://lnkd.in/g5SXKncJ
7. PCI Compliance: https://lnkd.in/gZns6Xdf
8. Endpoint Detection & Response: https://lnkd.in/gw22Y__E
9. Vulnerability Management: https://lnkd.in/gYAFfAuT
10. Cloud Security Assessment & Response: https://lnkd.in/grrHivcW
11. API Fundamentals: https://lnkd.in/gngVxhbu
12. Cloud Agent: https://lnkd.in/gngVxhbu
13. Container Security: https://lnkd.in/gYNCGY8A
14. File Integrity Monitoring: https://lnkd.in/gYNCGY8A
15. Web Application Scanning: https://lnkd.in/ggpJ-vG6
Here are 15 FREE courses provided by the Qualys.
https://www.linkedin.com/posts/hackstack-security_cybersecurity-freecourses-infosec-activity-7154837232141402112-4kjb
—— Hackstack Security ——
@hackstacksecurity
Contact Us: https://hackstacksecure.com/contact/
lnkd.in
LinkedIn
This link will take you to a page that’s not on LinkedIn
👍3
236 - Bypassing Chromecast Secure-Boot and Exploiting Factorio
https://dayzerosec.com/podcast/236.html
https://dayzerosec.com/podcast/236.html
dayzerosec
Bypassing Chromecast Secure-Boot and Exploiting Factorio
A bit of a game special this week, with a Counter-Strike: Global Offensive vulnerability and an exploit for Factorio. We also have a Linux kernel bug and a Chromecast secure-boot bypass with some hardware hacking mixed in.
🔥1
1. CVE-2023-5347, CVE-2023-5376:
Korenix JetNet Series Unauthenticated Access
https://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
2. CVE-2023-51252:
XSS vulnerability caused by file uploads in PublicCMS V4.0
https://github.com/sanluan/PublicCMS/issues/79
3. CVE-2023-50643:
Arbitrary code execution in MacOS Evernote
https://github.com/V3x0r/CVE-2023-50643
Korenix JetNet Series Unauthenticated Access
https://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
2. CVE-2023-51252:
XSS vulnerability caused by file uploads in PublicCMS V4.0
https://github.com/sanluan/PublicCMS/issues/79
3. CVE-2023-50643:
Arbitrary code execution in MacOS Evernote
https://github.com/V3x0r/CVE-2023-50643
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
PoC to takeover Android using another Android by exploiting critical Bluetooth vulnerability to install Metasploit without proper Bluetooth pairing (CVE-2023-45866). It still affects Android 10 and bellow.
https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
Mobile Hacker
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker
[update 2024-02-19] This vulnerability can be even used to remotely wipe data of targeted Android smartphone. Using this vulnerability it is possible to guess user lock screen PIN. After five incorrect PINs device is locked out for 30 seconds. This operation…
Finding XML Vulnerabilities in Code!
https://hackstacksecure.com/blogs/finding-xml-vulnerabilities-in-code
—— Hackstack Security ——
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
https://hackstacksecure.com/blogs/finding-xml-vulnerabilities-in-code
—— Hackstack Security ——
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
Hackstacksecure
Blogs (Finding XML Vulnerabilities in Code) • Hackstack Security
Top 10 Tools for Bug Bounty Hunting
Core Tools
1. Burp Suite:
The most essential tool for web application security testing. It offers a comprehensive suite of features for intercepting, modifying, and analyzing web traffic.
2. Nmap: A versatile network scanning tool used for discovering hosts, services, and vulnerabilities on a network.
3. FFUF: A fast web fuzzer that helps in discovering hidden directories, files, and parameters.
Intelligence Gathering
4. Amass: An open-source tool for conducting subdomain enumeration and asset discovery.
5. ReconFTW: Open-source reconnaissance tool for gathering information.
Vulnerability Scanning and Exploitation
6. Nuclei: A fast and lightweight vulnerability scanner for finding vulnerabilities using YAML-based templates.
7. SQLmap: A powerful penetration testing framework for SQL injection and database takeover.
8. WPScan: Specifically designed for WordPress vulnerability scanning.
Additional Tools:
9. Kali Linux: A Debian-based Linux distribution with a pre-installed set of penetration testing tools.
10. Wireshark: A packet analyzer for capturing and analyzing network traffic.
I know these are just few of them! Add more in the comments.
Core Tools
1. Burp Suite:
The most essential tool for web application security testing. It offers a comprehensive suite of features for intercepting, modifying, and analyzing web traffic.
2. Nmap: A versatile network scanning tool used for discovering hosts, services, and vulnerabilities on a network.
3. FFUF: A fast web fuzzer that helps in discovering hidden directories, files, and parameters.
Intelligence Gathering
4. Amass: An open-source tool for conducting subdomain enumeration and asset discovery.
5. ReconFTW: Open-source reconnaissance tool for gathering information.
Vulnerability Scanning and Exploitation
6. Nuclei: A fast and lightweight vulnerability scanner for finding vulnerabilities using YAML-based templates.
7. SQLmap: A powerful penetration testing framework for SQL injection and database takeover.
8. WPScan: Specifically designed for WordPress vulnerability scanning.
Additional Tools:
9. Kali Linux: A Debian-based Linux distribution with a pre-installed set of penetration testing tools.
10. Wireshark: A packet analyzer for capturing and analyzing network traffic.
I know these are just few of them! Add more in the comments.
Android Game Hacking: Increase money in Dude Theft Wars Shooting
https://8ksec.io/hacking-android-games/
https://8ksec.io/hacking-android-games/
8kSec
Hacking Android Games | 8kSec
Learn techniques for hacking Android games and understand the differences between app hacking and game hacking within the Android ecosystem.
The 5 Most Used Security Frameworks
1. ISO 27001:
- Leading in recognition, it offers a comprehensive approach to information security.
2. NIST Cybersecurity Framework:
- More common in the USA to manage cybersecurity risks.
3. CIS Controls:
- Simple and effective best practices for cybersecurity.
4. COBIT:
- Focuses on governance and management of enterprise IT.
5. PCI DSS:
- Essential for all organizations that process credit card transactions.
And Why Does ISO 27001 Certification Stand at the Top?
- Universal Recognition: ISO 27001 is globally recognized and respected.
- Flexibility: Suitable for companies of every size and industry.
- Risk Management: Provides a solid framework for managing security risks.
- Building Trust: Signals to customers and partners that their data is secure.
- Competitive Advantage: Can open the door to new business opportunities.
More: https://www.getronics.com/the-top-five-cyber-security-frameworks/
More: https://complianceforge.com/solutions/nist-csf
1. ISO 27001:
- Leading in recognition, it offers a comprehensive approach to information security.
2. NIST Cybersecurity Framework:
- More common in the USA to manage cybersecurity risks.
3. CIS Controls:
- Simple and effective best practices for cybersecurity.
4. COBIT:
- Focuses on governance and management of enterprise IT.
5. PCI DSS:
- Essential for all organizations that process credit card transactions.
And Why Does ISO 27001 Certification Stand at the Top?
- Universal Recognition: ISO 27001 is globally recognized and respected.
- Flexibility: Suitable for companies of every size and industry.
- Risk Management: Provides a solid framework for managing security risks.
- Building Trust: Signals to customers and partners that their data is secure.
- Competitive Advantage: Can open the door to new business opportunities.
More: https://www.getronics.com/the-top-five-cyber-security-frameworks/
More: https://complianceforge.com/solutions/nist-csf
Getronics
The top five cyber security frameworks
Cyber security frameworks provide an excellent basis for building your cyber strategy. These are five of the best frameworks to get started with.
Todays's Bug Bounty Blogs #9
1)Stored XSS in LibreOffice
https://bunny0417.medium.com/stored-xss-in-libreoffice-ed4ad22e0f56
2)FIRST CTF Forensics
https://systemweakness.com/first-ctf-forensics-d0cb0ebf59b7
3)The “Filing Problem”: DoD Cyber Sentinel Challenge (May 2024 CTF Writeup)
https://medium.com/@sagemd/the-filing-problem-dod-cyber-sentinel-challenge-may-2024-ctf-writeup-2e3e1e5fb10b
4)CyberTalents Penetration Testing Internship Program 2024 [CTF]
https://medium.com/@Zero-Ray/cybertalents-penetration-testing-internship-program-2024-ctf-64167ecc51ff
5)Fixme1.py-Beginner PicoMini 2022
https://medium.com/@bridget4/fixme-py-beginner-picomini-2022-ab7222d848f5
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)Stored XSS in LibreOffice
https://bunny0417.medium.com/stored-xss-in-libreoffice-ed4ad22e0f56
2)FIRST CTF Forensics
https://systemweakness.com/first-ctf-forensics-d0cb0ebf59b7
3)The “Filing Problem”: DoD Cyber Sentinel Challenge (May 2024 CTF Writeup)
https://medium.com/@sagemd/the-filing-problem-dod-cyber-sentinel-challenge-may-2024-ctf-writeup-2e3e1e5fb10b
4)CyberTalents Penetration Testing Internship Program 2024 [CTF]
https://medium.com/@Zero-Ray/cybertalents-penetration-testing-internship-program-2024-ctf-64167ecc51ff
5)Fixme1.py-Beginner PicoMini 2022
https://medium.com/@bridget4/fixme-py-beginner-picomini-2022-ab7222d848f5
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Windows Malware Development
https://0xpat.github.io/Malware_development_part_1/
https://0xpat.github.io/Malware_development_part_2/
https://0xpat.github.io/Malware_development_part_3/
https://0xpat.github.io/Malware_development_part_4/
https://0xpat.github.io/Malware_development_part_5/
https://0xpat.github.io/Malware_development_part_6/
https://0xpat.github.io/Malware_development_part_7/
https://0xpat.github.io/Malware_development_part_8/
https://0xpat.github.io/Malware_development_part_9/
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
https://0xpat.github.io/Malware_development_part_1/
https://0xpat.github.io/Malware_development_part_2/
https://0xpat.github.io/Malware_development_part_3/
https://0xpat.github.io/Malware_development_part_4/
https://0xpat.github.io/Malware_development_part_5/
https://0xpat.github.io/Malware_development_part_6/
https://0xpat.github.io/Malware_development_part_7/
https://0xpat.github.io/Malware_development_part_8/
https://0xpat.github.io/Malware_development_part_9/
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
0xpat.github.io
Malware development part 1 - basics
Introduction
This is the first post of a series which regards development of malicious software. In this series we will explore and try to implement multiple techniques used by malicious applications to execute code, hide from defenses and persist.
Let’s…
This is the first post of a series which regards development of malicious software. In this series we will explore and try to implement multiple techniques used by malicious applications to execute code, hide from defenses and persist.
Let’s…
Forwarded from 100xSecurity
Todays's Bug Bounty Blogs #10
1)“My Journey to Earning the First Bounty”
https://medium.com/@asharm.khan7/my-journey-to-earning-the-first-bounty-5314d1780f84
2)Git Exposure: How a Simple Oversight Led to a Critical Security Flaw
https://blog.lohigowda.in/git-exposure-led-to-critical-security-flaw
3)TryHackMe: Wireshark Basics
https://medium.com/@manish0x/tryhackme-wireshark-basics-d01a73297870
4)Day Four — DailyCTF Challenge Writeup
https://medium.com/@erichdryn/day-four-dailyctf-challenge-writeup-7bdba9f6310f
5)FixMe2.py - Beginner PicoMini 2022
https://medium.com/@bridget4/fixme2-py-beginner-picomini-2022-65b7256ced3b
6)Packet Operations with Wireshark
https://medium.com/@manish0x/packet-operations-with-wireshark-d1ef41b1dba9
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@thecybersecuritychannel
@HackstackSecurity
1)“My Journey to Earning the First Bounty”
https://medium.com/@asharm.khan7/my-journey-to-earning-the-first-bounty-5314d1780f84
2)Git Exposure: How a Simple Oversight Led to a Critical Security Flaw
https://blog.lohigowda.in/git-exposure-led-to-critical-security-flaw
3)TryHackMe: Wireshark Basics
https://medium.com/@manish0x/tryhackme-wireshark-basics-d01a73297870
4)Day Four — DailyCTF Challenge Writeup
https://medium.com/@erichdryn/day-four-dailyctf-challenge-writeup-7bdba9f6310f
5)FixMe2.py - Beginner PicoMini 2022
https://medium.com/@bridget4/fixme2-py-beginner-picomini-2022-65b7256ced3b
6)Packet Operations with Wireshark
https://medium.com/@manish0x/packet-operations-with-wireshark-d1ef41b1dba9
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@thecybersecuritychannel
@HackstackSecurity
Today's Bug Bounty Blogs #11
1)Account takeover on 8 years old public program
https://medium.com/@pranshux0x/account-takeover-on-8-years-old-public-program-c0c0a30cfdd2
2)New Reconnaissance Methodologies/Tools for Bug Bounty Hunting & Ethical Hacking
https://medium.com/@retr0x/new-reconnaissance-methodologies-tools-for-bug-bounty-hunting-ethical-hacking-be7ca14a7ae2
3)Beginners guide to solving Image Based CTF Challenges
https://blog.pannagkumaar.live/beginners-guide-to-solving-image-based-ctf-challenges-9e998a92167d
4)Matrix: 1 Vulnhub Walkthrough
https://medium.com/@z6157881/matrix-1-vulnhub-walkthrough-36f832d14f57
5)ROAD — CTF Full Walkthrough -TryHackMe
https://medium.com/@lidorrocah123/road-ctf-full-walkthrough-tryhackme-8ffb97d700f4
6)Headers? — DailyCTF Challenge Writeup
https://medium.com/@erichdryn/headers-dailyctf-challenge-writeup-a4d4e195e808
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
1)Account takeover on 8 years old public program
https://medium.com/@pranshux0x/account-takeover-on-8-years-old-public-program-c0c0a30cfdd2
2)New Reconnaissance Methodologies/Tools for Bug Bounty Hunting & Ethical Hacking
https://medium.com/@retr0x/new-reconnaissance-methodologies-tools-for-bug-bounty-hunting-ethical-hacking-be7ca14a7ae2
3)Beginners guide to solving Image Based CTF Challenges
https://blog.pannagkumaar.live/beginners-guide-to-solving-image-based-ctf-challenges-9e998a92167d
4)Matrix: 1 Vulnhub Walkthrough
https://medium.com/@z6157881/matrix-1-vulnhub-walkthrough-36f832d14f57
5)ROAD — CTF Full Walkthrough -TryHackMe
https://medium.com/@lidorrocah123/road-ctf-full-walkthrough-tryhackme-8ffb97d700f4
6)Headers? — DailyCTF Challenge Writeup
https://medium.com/@erichdryn/headers-dailyctf-challenge-writeup-a4d4e195e808
Join These Channels For More:
@TheCyberMonks
@HundredxSecurity
@HackstackSecurity
@thecybersecuritychannel
Free Cybersecurity Certifications in 2024
Those who are starting out in cybersecurity, these courses and certifications might help you a lot!
https://x.com/hetmehtaa/status/1826108930533253624
Those who are starting out in cybersecurity, these courses and certifications might help you a lot!
https://x.com/hetmehtaa/status/1826108930533253624
X (formerly Twitter)
Het Mehta (@hetmehtaa) on X
(Free) Cybersecurity Certifications in 2024
#Infosec Thread👇
#Infosec Thread👇