Lord Of The Ring0 - Part 4 | The call back home https://idov31.github.io/2023/02/24/lord-of-the-ring0-p4.html
Understanding the Context of Cyber Threats: Lessons from the Kimsuky Group Attack https://sp4rk.medium.com/understanding-the-context-of-cyber-threats-lessons-from-the-kimsuky-group-attack-3d026c5629bc
Medium
Understanding the Context of Cyber Threats: Lessons from the Kimsuky Group Attack
Kimsuky is the most active cyber threat actor who consistently targets North Korean-related institutions, companies, media, academia, and…
Acronis gets embarrassed by 'bored' hacker https://www.hackwatcher.com/p/acronis-gets-embarrassed-by-bored-hacker
Root Cause Analysis of the in the wild JIT bug (CVE-2022-42856) https://voidistaff.github.io/safari/2023/02/20/CVE-2022-42856.html
A New Vector For “Dirty” Arbitrary File Write to RCE https://blog.doyensec.com//2023/02/28/new-vector-for-dirty-arbitrary-file-write-2-rce.html
Doyensec
A New Vector For “Dirty” Arbitrary File Write to RCE
Arbitrary file write (AFW) vulnerabilities in web application uploads can be a powerful tool for an attacker, potentially allowing them to escalate their privileges and even achieve remote code execution (RCE) on the server. However, the specific tactics…
🔥1
DNSMonitor: Leveraging Apple's Network Extension Framework, this utility monitors DNS requests and responses https://objective-see.org/products/utilities.html#DNSMonitor
objective-see.org
Commandline Utilities
CLI utilities to facilate system monitoring and malware analysis.
👍1
Smart Contracts Security: Exploring Common Bugs https://playground.zero-defense.com/blog/smart-contracts-security/
Decoding BlazorPack https://sensepost.com/blog/2023/decoding-blazorpack/
Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol https://pierrekim.github.io/blog/2017-09-08-dlink-850l-mydlink-cloud-0days-vulnerabilities.html
CVE-2023-1112 - Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal https://github.com/Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal
GitHub
GitHub - Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal: Drag and Drop Multiple File Uploader PRO - Contact…
Drag and Drop Multiple File Uploader PRO - Contact Form 7 v5.0.6.1 Path Traversal (CVE-2023-1112) - Nickguitar/Drag-and-Drop-Multiple-File-Uploader-PRO-Path-Traversal
The Blitz Tutorial Lab on Fuzzing with AFL++ https://research.checkpoint.com/2023/the-blitz-tutorial-lab-on-fuzzing-with-afl/
🔥2👍1
PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749 https://mahaloz.re/2023/02/25/pwnagent-netgear.html
mahaloz.re
PwnAgent: A One-Click WAN-side RCE in Netgear RAX Routers with CVE-2023-24749
A breakdown of a bug SEFCOM T0 and I exploited to achieve a WAN-side RCE in some Netgear RAX routers for pwn2own 2022. The bug is a remotely accessible comma...
Akuvox Smart Intercom Vulnerabilities Leave Privacy Ajar https://claroty.com/team82/blog/akuvox-smart-intercom-vulnerabilities-leave-privacy-ajar
Claroty
Akuvox Smart Intercom Vulnerabilities Leave Privacy Ajar
Recovering a full PEM Private Key when half of it is redacted https://blog.cryptohack.org/twitter-secrets
CryptoHack
Recovering a full PEM Private Key when half of it is redacted
The @CryptoHack__ account was pinged today by ENOENT, with a CTF-like challenge found in the wild: Source tweet. Here’s a write-up covering how given a partially redacted PEM, the whole private key can be recovered.
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/
MDSec
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability - MDSec
Date: 14th March 2023 Today saw Microsoft patch an interesting vulnerability in Microsoft Outlook. The vulnerability is described as follows: Microsoft Office Outlook contains a privilege escalation vulnerability that allows...
👍1
How TikTok became public enemy no. 1 in the United States https://www.utahbusiness.com/how-tiktok-algorithm-became-national-security-risk-united-states/
Utah Business
How TikTok became a national security risk in the United States
Federal and local government officials, including Utah Gov. Spencer Cox, cite national security risk concerns.
iOS Mobile Application (i.e. .IPA) Vulnerability Assessment and Penetration Testing Walkthrough https://medium.com/@livelession/ios-mobile-application-i-e-ipa-vulnerability-assessment-and-penetration-testing-walkthrough-4e351484fdb9
Medium
iOS Mobile Application (i.e. .IPA) Vulnerability Assessment and Penetration Testing Walkthrough.
Hi Friends in this blog, I included step-by-step procedures from basics to the execution of test cases for iOS Application Security…
Multiple Internet to Baseband Remote Code Execution Vulnerabilities in Exynos Modems https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html
projectzero.google
Multiple Internet to Baseband Remote Code Execution Vulnerabilities in Exynos Modems
Posted by Tim Willis, Project Zero In late 2022 and early 2023, Project Zero reported eighteen ...
🔥1