safe-mail: A Docker service used by analysts to extract and inspect suspicious .MSG, .EML, and documents
Everyone, I would like to introduce a new utility for Security Analysts that I built called safe-mail. You can find the repository here: https://github.com/swimlane/safe-mail
safe-mail is a Docker service used by analysts to upload, extract, and inspect suspicious .MSG, .EML, and documents.
safe-mail has an API and a (limited) UI which allows a user to upload and retrieve artifacts generated by safe-mail.
safe-mail has the following features and functionality:
Message Features
• Upload EML and MSG mail messages as well as Microsoft Office documents themselves
• .MSG mail messages are Microsoft binary email format messages - typically from Microsoft Outlook clients
• Generates a PNG of the message itself named {filename}.png
• Extracts all embedded & attached images/attachments within the email message
• Provides a OCR text file of the generated mail message
• Generates a JSON file representing the mail message headers
Attachment/Document Features
• Extracts attachments of mail messages
• Generates an image & PDF of each attachment
• Attempts to extract any identified Macros within attachments and creates a JSON file representing the Macro code base
• PDF Documents will generate output from pdfid & pdfparser tools
• ZIP attachments will extract the zip and return any files within the zip
Enjoy! I hope this helps you all on a daily basis!
🗣[Unas](https://www.reddit.com/r/blueteamsec/comments/ftynlo/safemailadockerserviceusedbyanalyststo/)
🎖@malwr
Everyone, I would like to introduce a new utility for Security Analysts that I built called safe-mail. You can find the repository here: https://github.com/swimlane/safe-mail
safe-mail is a Docker service used by analysts to upload, extract, and inspect suspicious .MSG, .EML, and documents.
safe-mail can be used locally on your workstation or can be deployed for shared (or dedicated) use.safe-mail has an API and a (limited) UI which allows a user to upload and retrieve artifacts generated by safe-mail.
safe-mail has the following features and functionality:
Message Features
• Upload EML and MSG mail messages as well as Microsoft Office documents themselves
• .MSG mail messages are Microsoft binary email format messages - typically from Microsoft Outlook clients
• Generates a PNG of the message itself named {filename}.png
• Extracts all embedded & attached images/attachments within the email message
• Provides a OCR text file of the generated mail message
• Generates a JSON file representing the mail message headers
Attachment/Document Features
• Extracts attachments of mail messages
• Generates an image & PDF of each attachment
• Attempts to extract any identified Macros within attachments and creates a JSON file representing the Macro code base
• PDF Documents will generate output from pdfid & pdfparser tools
• ZIP attachments will extract the zip and return any files within the zip
Enjoy! I hope this helps you all on a daily basis!
🗣[Unas](https://www.reddit.com/r/blueteamsec/comments/ftynlo/safemailadockerserviceusedbyanalyststo/)
🎖@malwr
I discovered a vulnerability in Safari that allowed unauthorized websites to access your camera on iOS and macOS
🗣ga-vu
Nice write up and it's cool to see the Apple program finally paying out bounties to non-blessed researchers!
👤SirensToGo
Nice
👤morrislesterszyslak
And this is why I use an adblocker. Though recently, I have stepped up my game with a PiHole as well.
👤thatvhstapeguy
🎖@malwr
🗣ga-vu
Nice write up and it's cool to see the Apple program finally paying out bounties to non-blessed researchers!
👤SirensToGo
Nice
👤morrislesterszyslak
And this is why I use an adblocker. Though recently, I have stepped up my game with a PiHole as well.
👤thatvhstapeguy
🎖@malwr
Ryan Pickren
Webcam Hacking | Ryan Pickren
A vulnerability in Safari allowed hackers to access the iPhone and Macbook cameras. (CVE-2020-3852, CVE-2020-3864, CVE-2020-3865, CVE-2020-3885, CVE-2020-3887 & CVE-2020-9784)
A windows machine that has Cisco passwords hashes that we crack, spray on an smb share to validate user/pass combos and get user access . We then dump data from a running process and get root. It’s a fun machine
🗣lmakonem
🎖@malwr
🗣lmakonem
🎖@malwr
YouTube
HackTheBox - Heist | Noob To OSCP Episode #26
We will complete Heist, a Windows ctf machine from hackthebox for learning offensive cyber security skills. You will learn: 1) Enumerating windows 3) How to ...
TFW you-get-really-excited-you-patch-diffed-a-0day-used-in-the-wild-but-then-find-out-it-is-the-wrong-vuln
🗣cyberg0100
🎖@malwr
🗣cyberg0100
🎖@malwr
projectzero.google
TFW you-get-really-excited-you-patch-diffed-a-0day-used-in-the-wild-but-then-find-out-it-is-the-wrong-vuln
Posted by Maddie Stone, Project ZeroINTRODUCTIONI’m really interested in 0-days exploited i...
Research: Vulnerability analysis using the security news graph. Alternate way to score severity.
🗣isox_xx
Sounds similar to the VPR scoring method used by Tenable (Nessus).
👤Tryptic0nUK
🎖@malwr
🗣isox_xx
Sounds similar to the VPR scoring method used by Tenable (Nessus).
👤Tryptic0nUK
🎖@malwr
Vulners Blog
Hidden Threat – Vulnerability Analysis using the news graph
When you face to face a new vulnerability, what is the thought that comes first? Of course, respond as quickly as possible. However, speed is just one of the conditions for an effective fight again…
Common Ports to Remember (credits: packetlife.net)
🗣ATTACKERSA
This very same printout follows me from desk-to-desk. Very good reference point to the not-so-easy-to-remember ports.
👤native_rooted
All u need to know is 20,22,21,25,389,3389,80,53
👤Calvimn
What about WhatsApp?
👤wthinastix
🎖@malwr
🗣ATTACKERSA
This very same printout follows me from desk-to-desk. Very good reference point to the not-so-easy-to-remember ports.
👤native_rooted
All u need to know is 20,22,21,25,389,3389,80,53
👤Calvimn
What about WhatsApp?
👤wthinastix
🎖@malwr
Starting Fires by Hacking 3D Printers, pt 1
🗣FlyingTriangle
And this is why I bought a printer without wifi. Nothing is perfect, but it's one less attack vector.
👤digitaldude87
I’m not surprised that they companies don’t institute security from the very beginning.
👤macgeek89
👤ihave10felonies
🎖@malwr
🗣FlyingTriangle
And this is why I bought a printer without wifi. Nothing is perfect, but it's one less attack vector.
👤digitaldude87
I’m not surprised that they companies don’t institute security from the very beginning.
👤macgeek89
lp0 on fire all over again...👤ihave10felonies
🎖@malwr
Coalfire
Coalfire Blog
Resource covering the most important issues in IT security and compliance as well as insights on IT GRC issues that impact the industries that we serve.
Firefox 74.0.1 has been released
🗣danielsuarez369
Seems to be a security update for the most part: https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/
👤danielsuarez369
🎖@malwr
🗣danielsuarez369
Seems to be a security update for the most part: https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/
👤danielsuarez369
🎖@malwr
Mozilla
Firefox 74.0.1, See All New Features, Updates and Fixes
[PDF Bug Bounties With Bash | @TomNomNom](https://tomnomnom.com/talks/bug-bounties-with-bash-virsec.pdf)
🗣_vavkamil_
🎖@malwr
🗣_vavkamil_
🎖@malwr