Information Security
415 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
SQL injection, Oracle and full-width characters

https://bit.ly/2In4Xik


#sqli
#Oracle
a new metasploit post module for gathering information stored by #git. Pillage credentials, SSH keys, and locate internal git services for lateral moves.

https://bit.ly/2xFKIbe


#msf
ScriptBlock based functionnal AMSI bypass PoC tested today on a freshly updated #Windows10

https://pastebin.com/raw/iFVpKim5
https://github.com/kmkz/Pentesting/blob/master/Pentest-cheat-sheet
Local policies restrictions/Defender/#AMSI bypass using WMI and p0wnedShell + Meterpreter session

https://cobbr.io/ScriptBlock-Logging-Bypass.html
LoJax - the first-ever UEFI rootkit :
https://bit.ly/2R41IjF
#Formjacking attacks are on the rise, with the recent #Magecart attacks on several high-profile businesses. Symantec has blocked almost 250,000 formjacking attempts since mid-August.
symc.ly/2xBEBVw
"It's a smart time to be scared." #MrRobot
Linux Performance Tools. Large image https://i.imgur.com/I0tsWuV.jpg
This is how much 2018 has aged us all.

#fun
#Telegram Calling Feature Found Leaking both Your Private and Public IP Addresses

https://thehackernews.com/2018/09/hack-telegram-messenger.html