Verify first-party Microsoft applications in sign-in reports https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in
Docs
Verify first-party Microsoft applications in sign-in reports
Describes how to verify first-party Microsoft applications in sign-in reports.
CVE-2023-24998: Apache Commons FileUpload and Tomcat DoS Flaw https://securityonline.info/cve-2023-24998-apache-commons-fileupload-and-tomcat-dos-flaw/
Cybersecurity News
CVE-2023-24998: Apache Commons FileUpload and Tomcat DoS Flaw
Apache Tomcat was vulnerable to Apache Commons FileUpload flaw CVE-2023-24998 as there was no limit to the number of request parts processed
👍1
Security Code Review With ChatGPT https://research.nccgroup.com/2023/02/09/security-code-review-with-chatgpt/
Vulnerability write-up - "Dangerous assumptions" https://www.codean.io/blog/vulnerability-write-up---%22dangerous-assumptions%22
Introduction to SSRF Exploitation: A Practical Tutorial for Ethical Hackers — StackZero https://infosecwriteups.com/introduction-to-ssrf-exploitation-a-practical-tutorial-for-ethical-hackers-stackzero-385c02bd28f2
Medium
Introduction to SSRF Exploitation: A Practical Tutorial for Ethical Hackers — StackZero
Introduction to SSRF covering its mechanics, techniques, and effective countermeasures to defend against such attacks.
The Stack Series: The X64 Stack https://offensivecraft.wordpress.com/2023/02/11/the-stack-series-the-x64-stack/
offensivecraft
The Stack Series: The X64 Stack
Overview of x64 stack static RSP On x64 CPU, RSP register serves as both frame pointer and stack pointer, all the stack references are performed based on RSP as a result both local variables and pa…
NtQueueApcThreadEx NTDLL Gadget Injection https://github.com/LloydLabs/ntqueueapcthreadex-ntdll-gadget-injection
GitHub
GitHub - LloydLabs/ntqueueapcthreadex-ntdll-gadget-injection: This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine…
This novel way of using NtQueueApcThreadEx by abusing the ApcRoutine and SystemArgument[0-3] parameters by passing a random pop r32; ret gadget can be used for stealthy code injection. - LloydLabs...
👍1
Cybercriminals stung as HIVE infrastructure shut down https://www.europol.europa.eu/media-press/newsroom/news/cybercriminals-stung-hive-infrastructure-shut-down
Europol
Cybercriminals stung as HIVE infrastructure shut down – Europol supported German, Dutch and US authorities to shut down the servers…
In the last year, HIVE ransomware has been identified as a major threat as it has been used to compromise and encrypt the data and computer systems of large IT and oil multinationals in the EU and the USA. Since June 2021, over 1 500 companies from over 80…
Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices https://binarly.io/posts/Multiple_Vulnerabilities_in_Qualcomm_and_Lenovo_ARM_based_Devices/index.html
Binarly
Multiple Vulnerabilities in Qualcomm and Lenovo ARM-based Devices | Binarly
Uncover the latest ARM device vulnerabilities affecting Qualcomm and Lenovo. BINARLY's detailed exploration of CVE-2022-3430 and CVE-2022-3431 issues.
Linux Kernel Exploitation Technique: Overwriting modprobe_path https://lkmidas.github.io/posts/20210223-linux-kernel-pwn-modprobe/
My cool site
Linux Kernel Exploitation Technique: Overwriting modprobe_path
A popular and powerful technique to exploit the Linux kernel through modprobe_path
Exploit Airlines that use T-Mobile for Free WiFi https://cylect.io/blog/cybr-2/exploit-airlines-to-get-free-wifi-airline-vulnerability-8
Havoc Across the Cyberspace https://www.zscaler.com/blogs/security-research/havoc-across-cyberspace
Zscaler
Havoc Across the Cyberspace | Blog | Zscaler
ThreatLabz observed a new campaign targeting a Government organization in which the threat actors utilized a new Command & Control (C2) framework named Havoc
The code that wasn’t there: Reading memory on an Android device by accident https://github.blog/2023-02-23-the-code-that-wasnt-there-reading-memory-on-an-android-device-by-accident/
The GitHub Blog
The code that wasn't there: Reading memory on an Android device by accident
CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space…
OpenEMR - Remote Code Execution in your Healthcare System https://www.sonarsource.com/blog/openemr-remote-code-execution-in-your-healthcare-system/
Hackers Using Trojanized macOS Apps to Deploy Evasive Cryptocurrency Mining Malware https://thehackernews.com/2023/02/hackers-using-trojanized-macos-apps-to.html
Phylum Discovers Aggressive Attack on PyPI Attempting to Deliver Rust Executable https://blog.phylum.io/phylum-discovers-another-attack-on-pypi
When an N-Day turns into a 0day. (Part 1 of 2) https://github.com/b1ack0wl/vulnerability-write-ups/blob/master/TP-Link/WR940N/112022/Part1.md
GitHub
vulnerability-write-ups/TP-Link/WR940N/112022/Part1.md at master · b1ack0wl/vulnerability-write-ups
This repo contains write ups of vulnerabilities I've found and exploits I've publicly developed. - b1ack0wl/vulnerability-write-ups
Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers https://securityintelligence.com/posts/direct-kernel-object-manipulation-attacks-etw-providers/
Security Intelligence
Direct Kernel Object Manipulation (DKOM) Attacks on ETW Providers
IBM Security X-Force Red offensive hackers analyze how attackers, with elevated privileges, can use their access to stage Windows Kernel post-exploitation capabilities.
Forwarding Traffic Through SSH https://www.blackhillsinfosec.com/forwarding-traffic-through-ssh/
Black Hills Information Security, Inc.
Forwarding Traffic Through SSH - Black Hills Information Security, Inc.
Fernando Panizza // This was meant to be an OpenSSH how-to blog, but since I had time, I decided to read the man pages (manual pages that you can access […]
👍2
IpGeo - Tool To Extract IP Addresses From Captured Network Traffic File https://www.kitploit.com/2023/02/ipgeo-tool-to-extract-ip-addresses-from.html
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.