Information Security
@sec_nerd_en
416
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
416 subscribers
Information Security
https://ired.team/offensive-security/code-injection-process-injection/pe-injection-executing-pes-inside-remote-processes
www.ired.team
PE Injection: Executing PEs inside Remote Processes | Red Team Notes
Code Injection
Information Security
https://osandamalith.com/2019/10/12/bypassing-the-webarx-web-application-firewall-waf/
🔐
Blog of Osanda
Bypassing the WebARX Web Application Firewall (WAF) |
🔐
Blog of Osanda
WebARX is a web application firewall where you can protect your website from malicious attacks. As you can see it was mentioned in TheHackerNews as well and has good ratings if you do some Googling…
Information Security
https://medium.com/@rootxharsh_90844/vimeo-ssrf-with-code-execution-potential-68c774ba7c1e
Medium
Vimeo SSRF with code execution potential.
Recently i discovered a semi responded SSRF on Vimeo with code execution possibility. This blog post explains how i found & exploited it…
Information Security
https://medium.com/@theRaz0r/arbitrary-file-reading-in-next-js-2-4-1-34104c4e75e9
Medium
Arbitrary File Reading in Next.js < 2.4.1
Next.js is a quite popular (>13k stars on GitHub) framework for server-rendered React applications. It includes a NodeJS server which allows to render HTML pages dynamically. While digging into…
Information Security
https://www.youtube.com/watch?v=Jm42OidT3Ac
YouTube
NEW iOS 13.1.3 / 13.0 / 12.4.1 Remote JAILBREAK Safari LPE PoC RELEASED! (A12 Too)
▶
Enter the awesome iMyFone Halloween giveaway contest and get your iPhone 11 for FREE at this link*: http://bit.ly/2BKlKJI In this video, we're discussing @...
Information Security
https://pwnrip.com/windows-kernel-exploitation-part-1-stack-buffer-overflows/
Information Security
https://github.com/SpiderMate/Paper-on-Jenkins-Rce/
GitHub
SpiderMate/Paper-on-Jenkins-Rce
A detailed paper on Jenkins Pre-Auth RCE . Contribute to SpiderMate/Paper-on-Jenkins-Rce development by creating an account on GitHub.
Information Security
Information Security
Information Security
https://github.com/aaronhnatiw/race-the-web
GitHub
GitHub - TheHackerDev/race-the-web: Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous…
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline. - GitHub - TheHackerDev/race-the-web: Tests for race conditions in web app...
Information Security
#WAF
#ModSecurity
#RCE
#Payloads
Detection
#Bypass
;+$u+cat+/etc$u/passwd$u
;+$u+cat+/etc$u/passwd+\#
/???/??t+/???/??ss??
/?in/cat+/et?/passw?
Information Security
https://www.shelliscoming.com/2019/11/retro-shellcoding-for-current-threats.html
Shelliscoming
Retro shellcoding for current threats: rebinding sockets in Windows
In previous posts we saw two techniques to bypass firewalls through custom stagers to locate and reuse the connection socket; on the one ha...
Information Security
https://www.darknet.org.uk/2019/11/sooty-soc-analyst-all-in-one-cli-tool/
Darknet - Hacking Tools, Hacker News & Cyber Security
Sooty - SOC Analyst All-In-One CLI Tool
Sooty is a tool developed with the task of aiding a SOC analyst to automate parts of their workflow and speed up their process.
Information Security
https://securityonline.info/bypass-xss-filter
Penetration Testing
Everythings do to bypass XSS filter
Bypass XSS filter methodologies, techniques, tips. Cross Site Scripting (XSS) is a Web application attack in the data output to the page
Information Security
https://osandamalith.com/2018/02/11/mysql-udf-exploitation/
🔐
Blog of Osanda
MySQL UDF Exploitation |
🔐
Blog of Osanda
Overview In the real world, while I was pentesting a financial institute I came across a scenario where they had an internal intranet and it was using MySQL 5.7 64-bit as the backend database techn…
Information Security
https://twitter.com/PortSwiggerRes/status/1190187441124257792?s=19
Twitter
PortSwigger Research
Firefox mXSS <img id="<img src=1 onerror=alert(1)>"> based on @SecurityMB's work. Is triggered when you use something like template to read the innerHTML.
Information Security
https://medium.com/@D0rkerDevil/how-i-tookover-a-ldap-server-703209161001
Medium
How I Tookover a ldap server.
Intro
Information Security
https://nathandavison.com/blog/abusing-http-hop-by-hop-request-headers
Information Security
https://0xrick.github.io/hack-the-box/haystack/
Information Security
https://github.com/teknogeek/ssrf-sheriff
GitHub
GitHub - teknogeek/ssrf-sheriff: A simple SSRF-testing sheriff written in Go
A simple SSRF-testing sheriff written in Go. Contribute to teknogeek/ssrf-sheriff development by creating an account on GitHub.