Information Security
@sec_nerd_en
408
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
408 subscribers
Information Security
https://github.com/cube0x0/noPac
GitHub
GitHub - cube0x0/noPac: CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.
CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter. - cube0x0/noPac
Information Security
https://www.veracode.com/blog/research/exploiting-jndi-injections-java
Veracode
Exploiting JNDI Injections in Java | Veracode
Application Security for the AI Era | Veracode
Information Security
https://revers.engineering/applied-re-accelerated-assembly-p1/
Reverse Engineering
Applied Reverse Engineering: Accelerated Assembly [P1] - Reverse Engineering
Part 1 of the x86_64 assembly crash course for people looking to learn how to reverse engineer, read assembly, and understand how exploits work.
Information Security
https://youst.in/posts/cache-poisoning-at-scale/
Information Security
https://und3rf10w.github.io/posts/2022/01/08/shlyuz-1-influences.html
Und3rf10w
Shlyuz Implant Framework: Part 1 - Influences
Overview I’m excited to finally discuss and share the Proof-of-Concept code for an implant framework I wrote called Shlyuz (шлюз). Shlyuz takes a number of design queues from the Assassin Implant developed by the Central Intelligence Agency as described in…
Information Security
https://github.com/gtworek/PSBits/tree/master/EnableAllParentPrivileges
GitHub
PSBits/EnableAllParentPrivileges at master · gtworek/PSBits
Simple (relatively) things allowing you to dig a bit deeper than usual. - gtworek/PSBits
Information Security
https://medium.com/@frycos/searching-for-deserialization-protection-bypasses-in-microsoft-exchange-cve-2022-21969-bfa38f63a62d
Medium
Searching for Deserialization Protection Bypasses in Microsoft Exchange (CVE-2022–21969)
This story begins with a series of fails, but why? That is because of my special relationship with the Microsoft Exchange codebase…
Information Security
https://codewhitesec.blogspot.com/2021/09/citrix-sharefile-rce-cve-2021-22941.html?m=1
Blogspot
CODE WHITE | Blog: RCE in Citrix ShareFile Storage Zones Controller (CVE-2021-22941) – A Walk-Through
Citrix ShareFile Storage Zones Controller uses a fork of the third party library NeatUpload. Versions before 5.11.20 are affected by a rela...
Information Security
https://omespino.com/write-up-private-bug-bounty-rce-in-ec2-instance-via-ssh-with-private-key-exposed-on-public-github-repository-xx000-usd/
Information Security
https://medium.com/@emil.lerner/leaking-uninitialized-memory-from-fastly-83327bcbee1f
Medium
A story of leaking uninitialized memory from Fastly
The post go through a QUIC (HTTP/3) implementation bug in the H2O webserver. The bug is interesting as it affected Fastly, a well-known…
Information Security
https://twitter.com/x86matthew/status/1489624392627859458
?
Twitter
x86matthew
EmbedExeLnk - Embedding an EXE inside a LNK with automatic execution x86matthew.com/view_post?id=e…
Information Security
https://twitter.com/ORCA6665/status/1489873971843579910
?
Twitter
ORCA666
Published a new Repo Today, first one on gitlab ;) combining more than more tech to bypass av products: u can check it here: #bypassav #shellcode #payload gitlab.com/ORCA666/3in1
Information Security
https://twitter.com/jifa/status/1489971006122909704
?
Twitter
Shahar Tal
Nearly tweetable exploit (BYOShellcode) for Cisco Anyconnect VPN unauth RCE (rwx stack ftw)
🔥
patched last week. Presented at @offensive_con by @FlashbackPwn
Information Security
https://twitter.com/garethheyes/status/1489614655043649536
?
Twitter
Gareth Heyes
Apparently if you swear at JavaScript you still get an alert(1): #!@*% alert(1)
Information Security
https://twitter.com/zapstiko/status/1489940900167913472
?
Twitter
Raihan
Company Sensitive Data in Internet Web Archive@3nc0d3dGuY cat subdomains.txt | waybackurls | tee waybackurls.txt | grep -E "\\.xls|\\.xlsx|\\.json|\\.pdf|\\.sql|\\.doc|\\.docx|\\.pptx" #cybersecurity #bugbounty #bugbountytips
Information Security
https://twitter.com/pentest_swissky/status/1490289166688657408
Twitter
Swissky @ Home
🛰
🛸
Decoding Cobalt Strike: Understanding Payloads decoded.avast.io/threatintel/de…
Information Security
https://www.ic3.gov/Media/News/2022/220204.pdf
Information Security
https://twitter.com/r3tr0sp3ct2019/status/1490455108722823173?s=19
Twitter
2019
DiceCTF Memory Hole: how to break V8 heap sandbox mem2019.github.io/jekyll/update/…
Information Security
https://twitter.com/steiner254/status/1490231867362193415
Twitter
Steiner254
Using Burp to test for IDOR #bugbounty #bugbountytips #cybersecuritytips portswigger.net/support/using-…
Information Security
https://twitter.com/rootsecdev/status/1490488240540893184
Twitter
rootsecdev
This is also me one of the most amazing references for attacking active directory that I’ve seen. Attacking Active Directory: 0 to 0.9 | zer1t0 zer1t0.gitlab.io/posts/attackin…