Information Security
@sec_nerd_en
420
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
420 subscribers
Information Security
https://medium.com/@yogeshtantak7788/how-i-was-able-to-delete-google-gallery-data-idor-53d2f303efff
Medium
How I was able to delete Google Gallery Data [IDOR]
Hi, This is Yogesh Tantak a Security Researcher from India. Today I am writing about a critical bug that I found in Google’s new Product…
Information Security
https://github.com/gloxec/CrossC2
GitHub
GitHub - gloxec/CrossC2: generate CobaltStrike's cross-platform payload
generate CobaltStrike's cross-platform payload. Contribute to gloxec/CrossC2 development by creating an account on GitHub.
Information Security
#msf
Information Security
https://github.com/jas502n/CVE-2020-2551
GitHub
GitHub - jas502n/CVE-2020-2551: Weblogic RCE with IIOP
Weblogic RCE with IIOP. Contribute to jas502n/CVE-2020-2551 development by creating an account on GitHub.
Information Security
https://github.com/alexellis/k3sup
GitHub
GitHub - alexellis/k3sup: bootstrap K3s over SSH in < 60s
🚀
bootstrap K3s over SSH in < 60s
🚀
. Contribute to alexellis/k3sup development by creating an account on GitHub.
Information Security
https://mjali.com/category/security/write-ups/
Mjali
Write-ups – Mjali
Posts about Write-ups written by Omar
Information Security
https://www.kitploit.com/2020/01/memhunter-live-hunting-of-code.html
KitPloit - PenTest & Hacking Tools
Memhunter - Live Hunting Of Code Injection Techniques
Information Security
https://github.com/trimstray/the-book-of-secret-knowledge
GitHub
GitHub - trimstray/the-book-of-secret-knowledge: A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners…
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. - trimstray/the-book-of-secret-knowledge
Information Security
https://github.com/charles2gan/GDA-android-reversing-Tool/wiki
GitHub
Home
the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy lea...
Information Security
https://pentestlab.blog/2018/05/08/nbns-spoofing/
Penetration Testing Lab
NBNS Spoofing
Netbios Name Service (NBT-NS) is used in Windows networks for communication between hosts. Systems will use this service when resolving names over LHOSTS and DNS fail. Abusing this service to perfo…
Information Security
https://github.com/sailay1996/awesome_windows_logical_bugs
GitHub
GitHub - sailay1996/awesome_windows_logical_bugs: collect for learning cases
collect for learning cases. Contribute to sailay1996/awesome_windows_logical_bugs development by creating an account on GitHub.
Information Security
https://ired.team/offensive-security/credential-access-and-credential-dumping/intercepting-logon-credentials-by-hooking-msv1_0-spacceptcredentials
www.ired.team
Intercepting Logon Credentials by Hooking msv1_0!SpAcceptCredentials | Red Team Notes
Hooking, Credential Stealing
Information Security
https://jlajara.gitlab.io/posts/2020/01/25/XSS_tag_event_analyzer.html
Information Security
https://www.cybereason.com/blog/dcom-lateral-movement-techniques
Cybereason
New lateral movement techniques abuse DCOM technology
The arsenal of lateral movement techniques was expanded with new methods that abuse the DCOM functionality of Windows applications.
Information Security
https://pentestlaboratories.com/2020/01/27/msbuild-without-msbuild/
Pentest Laboratories
MSBuild without MSBuild
MSBuild is a trusted Windows binary that is part of Microsoft .NET framework and can be utilized to build applications in environments where Visual Studio is not installed. From the perspective of …
Information Security
https://twitter.com/mrgretzky/status/1221809489608921090?s=20
Twitter
Kuba Gretzky
pwndrop - The new fast & fun way to set up an HTTP/WebDAV server for your payloads is coming! python -m SimpleHTTPServer may soon be retiring. Stay tuned! Here is a quick sneak peek: https://t.co/bzVV6E9oyT
Information Security
https://sid-500.com/2020/01/28/office-365-add-user-accounts-and-mailboxes-with-powershell/
SID-500.COM
Office 365: Add User Accounts and Mailboxes with PowerShell
More and more companies are moving to the cloud. Subscribing cloud services means less hardware maintenance, more comfort, and an “always-on” feeling. As an administrator, you have to g…
Information Security
https://blog.netspi.com/attacking-application-specific-sql-server-instances/
NetSPI Blog
Attacking Application Specific SQL Server Instances
This blog walks through how to quickly identify SQL Server instances used by 3rd party applications that are configured with default passwords using PowerUpSQL.
Information Security
https://www.netmeister.org/blog/ops-lessons.html
www.netmeister.org
(A few) Ops Lessons We All Learn The Hard Way
Ops is hard. What have learned so far?
Information Security
https://github.com/luxunator/weebmyip
GitHub
GitHub - luxunator/weebmyip: Website with an API to get information on IP addresses, and of course an anime girl to read you it
Website with an API to get information on IP addresses, and of course an anime girl to read you it - GitHub - luxunator/weebmyip: Website with an API to get information on IP addresses, and of cour...