CVE && PoC SearchBot
Bot helps to keep up to date with new CVEs and search new POC's
https://t.me/pocfather_bot
Bot helps to keep up to date with new CVEs and search new POC's
https://t.me/pocfather_bot
Telegram
π₯π CVE && PoC SearchBot
Bot helps to keep up to date with new CVEs and search new POC's
βοΈ @pocfather_contact
βοΈ @pocfather_contact
π4π₯1
This is a step-by-step guide to implementing a DevSecOps program for any size organization
#devsecops
https://github.com/6mile/DevSecOps-Playbook
#devsecops
https://github.com/6mile/DevSecOps-Playbook
GitHub
GitHub - 6mile/DevSecOps-Playbook: This is a step-by-step guide to implementing a DevSecOps program for any size organization
This is a step-by-step guide to implementing a DevSecOps program for any size organization - 6mile/DevSecOps-Playbook
π1
GCP Penetration Testing Notes
Part 1: https://0xd4y.com/2022/10/01/GCP-Penetration-Testing-Notes
Part 2: https://0xd4y.com/2022/10/24/GCP-Penetration-Testing-Notes-2
Part 1: https://0xd4y.com/2022/10/01/GCP-Penetration-Testing-Notes
Part 2: https://0xd4y.com/2022/10/24/GCP-Penetration-Testing-Notes-2
0Xd4Y
GCP Penetration Testing Notes
Notes I wrote while reading a blog post written about GCP penetration testing techniques and methodologies by Chris Moberly.
π4
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
https://breakdev.org/zip-motw-bug-analysis/
https://breakdev.org/zip-motw-bug-analysis/
BREAKDEV
Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049)
Windows ZIP extraction bug (CVE-2022-41049) lets attackers craft ZIP files, which evade warnings on attempts to execute packaged files, even if ZIP file was downloaded from the Internet.
π2
Pentesting AD Mindmap
https://orange-cyberdefense.github.io/ocd-mindmaps/img/pentest_ad_dark_2022_11.svg
https://orange-cyberdefense.github.io/ocd-mindmaps/img/pentest_ad_dark_2022_11.svg
π2
Chrome Browser Exploitation
Part 1 - Introduction to V8 and JavaScript Internals
https://jhalon.github.io/chrome-browser-exploitation-1
Part 2 - Introduction to Ignition, Sparkplug and JIT Compilation via TurboFan
https://jhalon.github.io/chrome-browser-exploitation-2
Part 1 - Introduction to V8 and JavaScript Internals
https://jhalon.github.io/chrome-browser-exploitation-1
Part 2 - Introduction to Ignition, Sparkplug and JIT Compilation via TurboFan
https://jhalon.github.io/chrome-browser-exploitation-2
Jack Hacks
Chrome Browser Exploitation, Part 1: Introduction to V8 and JavaScript Internals
Web browsers, our extensive gateway to the internet. Browsers today play a vital role in modern organizations as more and more software applications are delivered to users via a web browser in the form of web applications. Pretty much everything you mightβ¦
Linux PrivEsc - Linux Kernel Exploits
https://medium.com/@tinopreter/linux-privesc-linux-kernel-exploits-87c61faec696
https://medium.com/@tinopreter/linux-privesc-linux-kernel-exploits-87c61faec696
Medium
Linux PrivEscβββLinux Kernel Exploits
Given that the kernel runs in the privileged kernel space, any vulnerability in the kernel that allows us to run arbitrary code in a β¦
π1π1
Video about bypassing MS Defender using a common PowerShell payload generated from π‘πππ©π¬://π«ππ―π¬π‘ππ₯π₯π¬[.]ππ¨π¦
https://m.youtube.com/watch?v=3HddKylkRzM
https://m.youtube.com/watch?v=3HddKylkRzM
YouTube
Bypass MS Defender by modifying payloads
Connect with me / Support:
Github β‘ https://github.com/t3l3machus/
Twitter β‘ https://twitter.com/t3l3machus
Linkedin β‘ https://www.linkedin.com/in/panagiotis-chartas-a9b4a21a5/
Make sure to Subscribe for more!
Github β‘ https://github.com/t3l3machus/
Twitter β‘ https://twitter.com/t3l3machus
Linkedin β‘ https://www.linkedin.com/in/panagiotis-chartas-a9b4a21a5/
Make sure to Subscribe for more!
REcollapse - tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
https://github.com/0xacb/recollapse
https://github.com/0xacb/recollapse
GitHub
GitHub - 0xacb/recollapse: REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizationsβ¦
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications - 0xacb/recollapse
APT Groups and Operations
https://docs.google.com/spreadsheets/u/0/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/htmlview#
https://docs.google.com/spreadsheets/u/0/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/htmlview#
Defending_nginx.pdf
8.9 MB
"Defending against automatization using NGINX", 2022.
Nginx Bad Bot and User-Agent Blocker, Spam Referrer Blocker, Anti DDOS, Bad IP Blocker, Wordpress Theme Detector Blocker:
https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
#book #nginx
Nginx Bad Bot and User-Agent Blocker, Spam Referrer Blocker, Anti DDOS, Bad IP Blocker, Wordpress Theme Detector Blocker:
https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
#book #nginx
JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses
https://github.com/sinfulz/JustEvadeBro
https://github.com/sinfulz/JustEvadeBro
GitHub
GitHub - sinfulz/JustEvadeBro: JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses.
JustEvadeBro, a cheat sheet which will aid you through AMSI/AV evasion & bypasses. - sinfulz/JustEvadeBro
JavaScript Engine Exploitation Primitives
https://www.madstacks.dev/posts/V8-Exploitation-Series-Part-6/#writing-an-exploit
V8 Exploitation Series:
https://www.madstacks.dev/categories/v8-series
https://www.madstacks.dev/posts/V8-Exploitation-Series-Part-6/#writing-an-exploit
V8 Exploitation Series:
https://www.madstacks.dev/categories/v8-series
#Threat_Research
1. Android SharkBot Droppers on Google Play
https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs
2. Cryptonite Ransomware
https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware
1. Android SharkBot Droppers on Google Play
https://www.bitdefender.com/blog/labs/android-sharkbot-droppers-on-google-play-underlines-platforms-security-needs
2. Cryptonite Ransomware
https://www.fortinet.com/blog/threat-research/Ransomware-Roundup-Cryptonite-Ransomware
Bitdefender Labs
Android SharkBot Droppers on Google Play Underline Platform's Security Needs
A common theme we've noticed in the last few months consists of malicious apps distributed directly from the Google Play Store.