Information Security
@sec_nerd_en
408
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
408 subscribers
Information Security
https://offensi.com/2020/08/18/how-to-contact-google-sre-dropping-a-shell-in-cloud-sql/
Offensi
How to contact Google SRE: Dropping a shell in cloud SQL
Note: The vulnerabilities that are discussed in this post were patched quickly and properly by Google. We support responsible disclosure. The research that resulted in this post was done by me and …
Information Security
https://github.com/s0md3v/Parth
GitHub
GitHub - s0md3v/Parth: Heuristic Vulnerable Parameter Scanner
Heuristic Vulnerable Parameter Scanner. Contribute to s0md3v/Parth development by creating an account on GitHub.
Information Security
https://github.com/BlackFan/content-type-research
GitHub
GitHub - BlackFan/content-type-research: Content-Type Research
Content-Type Research. Contribute to BlackFan/content-type-research development by creating an account on GitHub.
Information Security
https://nickbloor.co.uk/2020/08/21/x-cart-5/
NickstaDB
X-Cart 5 <= 5.4.0.12/5.4.1.7 Unauthenticated RCE via File Write
This one was a fun little hack. Versions 5.4.1.7 and below, and 5.4.0.12 and below of the X-Cart PHP ecommerce platform are affected by an unauthenticated vulnerability that allows an attacker to c…
Information Security
https://www.blackhat.com/presentations/bh-dc-08/McFeters-Rios-Carter/Presentation/bh-dc-08-mcfeters-rios-carter.pdf
Information Security
https://www.secjuice.com/xss-arithmetic-operators-chaining-bypass-sanitization/
Information Security
https://github.com/jaeles-project/jaeles
GitHub
GitHub - jaeles-project/jaeles: The Swiss Army knife for automated Web Application Testing
The Swiss Army knife for automated Web Application Testing - jaeles-project/jaeles
Information Security
https://swarm.ptsecurity.com/grafana-6-4-3-arbitrary-file-read/
PT SWARM
Grafana 6.4.3 Arbitrary File Read
An article about an Arbitrary File Read vulnerability (CVE-2019-19499) in Grafana
Information Security
https://medium.com/@bamalkaranbamal/how-to-spot-and-exploit-postmessage-vulnerablities-329079d307cc
Medium
How to spot and exploit postMessage vulnerablities?
Here is a primer on finding and creating POCs for bugs found with postMessage javascript function
Information Security
https://www.hackerone.com/blog/Top-Firewall-Misconfigurations-that-Lead-to-Easy-Exploitations
HackerOne
Top Firewall Misconfigurations that Lead to Easy Exploitations by Attackers
Network security should be a major focus for companies moving to the cloud. Cloud networks are exposed to the Internet and companies don’t have direct control of the hardware running them. When not configured correctly, networks in the cloud could be attacked…
Information Security
https://github.com/GoSecure/dtd-finder/blob/698fd678f26395e1c7c097525f7182aecad0cd5f/list/xxe_payloads.md
GitHub
dtd-finder/list/xxe_payloads.md at 698fd678f26395e1c7c097525f7182aecad0cd5f · GoSecure/dtd-finder
List DTDs and generate XXE payloads using those local DTDs. - GoSecure/dtd-finder
Information Security
https://twitter.com/juwilie1337/status/1301099882304942086
Twitter
juwilie
If you want your own Burp Collaborator, but with more protocols and web panel here it is https://t.co/jUZj6VWAy7
Information Security
https://lab.wallarm.com/340-weak-jwt-secrets-you-should-check-in-your-code/
Wallarm
☝️
340 weak JWT secrets you should check in your code
340 weak JWT secrets you should check in your code. Don't leave your web app's authentication exposed to hackers. Review this list
Information Security
https://prookl.dev/uncategorized/writing-a-burp-extension/
Prookl
Writing A Burp Extension, Prookl
I recently took a Black Hat course by MDSec called
Information Security
https://github.com/summitt/Burp-Non-HTTP-Extension
GitHub
GitHub - summitt/Nope-Proxy: TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.
TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite. - summitt/Nope-Proxy
Information Security
https://securitylab.github.com/advisories/GHSL-2020-027-netflix-conductor
GitHub Security Lab
GHSL-2020-027: Server-Side Template Injection in Netflix Conductor
A Server-Side Template Injection was identified in Netflix Conductor enabling attackers to inject arbitrary Java EL expressions, leading to a pre-auth Remote Code Execution (RCE) vulnerability.
Information Security
https://x64sec.sh/custom-dll-injection-with-cobalt-strike/
Information Security
https://github.com/Nalen98/AngryGhidra
GitHub
GitHub - Nalen98/AngryGhidra: Use angr in Ghidra
Use angr in Ghidra. Contribute to Nalen98/AngryGhidra development by creating an account on GitHub.
Information Security
https://hardik05.wordpress.com/2020/09/05/fuzzing-with-hongfuzz-fuzzing-a-simple-c-program/
Hardik05's Blog
[Fuzzing with hongfuzz] Fuzzing a simple C program
Video post by @hardik05.
Information Security
https://github.com/b1ack0wl/linux_mint_poc
GitHub
GitHub - b1ack0wl/linux_mint_poc
Contribute to b1ack0wl/linux_mint_poc development by creating an account on GitHub.