Forwarded from tpx Security ⠠⠵
Empire v2.3 is out. Please see the changelog for details https://github.com/EmpireProject/Empire/blob/master/changelog
GitHub
EmpireProject/Empire
Empire is a PowerShell and Python post-exploitation agent.
SQL Injection Tutorial
https://myhacker.net/2017/10/sql-injection-tutorial-sql-injection-cheat-sheet/
https://myhacker.net/2017/10/sql-injection-tutorial-sql-injection-cheat-sheet/
We Take Security Seriously, Do You?
SQL Injection Tutorial - Sql Injection cheat sheet - We Take Security Seriously, Do You?
SQL Injection Tutorial – Sql Injection cheat sheet . SQL injection allows us to remotely pull down all the tables, login usernames and admin accounts for a website. The most powerful tool for SQL injection is SQLMAP, which we can use on Windows and Kali…
Scripts to generate Office documents with DDE payloads
#redteam #pentesting
https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
#redteam #pentesting
https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
GitHub
GitHub - 0xdeadbeefJERKY/Office-DDE-Payloads: Collection of scripts and templates to generate Office documents embedded with the…
Collection of scripts and templates to generate Office documents embedded with the DDE, macro-less command execution technique. - 0xdeadbeefJERKY/Office-DDE-Payloads
Backdoor account found in #Oracle "Identity Manager". Severity score: 10/10
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html&elqTrackId=aa04438ad8784f0095c9f18737e5f459&elqTrack=true?elq_mid=92218&sh=0807181713171213162209290407151726&cmid=SPPT160711P00036C0001
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html&elqTrackId=aa04438ad8784f0095c9f18737e5f459&elqTrack=true?elq_mid=92218&sh=0807181713171213162209290407151726&cmid=SPPT160711P00036C0001
Some Powershell Malicious Code, (Tue, Oct 31st)
https://isc.sans.edu/diary/rss/22988
https://isc.sans.edu/diary/rss/22988
SANS Internet Storm Center
InfoSec Handlers Diary Blog - Internet Storm Center Diary 2017-10-31
SANS Internet Storm Center - A global cooperative cyber threat / internet security monitor and alert system. Featuring daily handler diaries with summarizing and analyzing new threats to networks and internet security events.
Win10 + PowerShell v5 remembers 4096 commands history stored in a plain text file in the profile of each user
https://t.co/kLADMKF3Gm
https://t.co/kLADMKF3Gm
Woshub
PowerShell Commands History | Windows OS Hub
One of the main drawbacks of Powershell command prompt compared to bash was the inability to keep a history of executed commands. The command history could be
Lista de Threat Intelligence dominios maliciosos en formato DNS y SNORT para sinkhole dns o para tu ids. Disfruta
https://t.co/zZSkdr5cVz
https://t.co/zZSkdr5cVz
GitHub
kinomakino/Threat-Intelligence-Data
Threat-Intelligence-Data - Snort_rules detection bad actors.
Ejecución remota de código en Hewlett Packard Enterprise Intelligent Management Center #HPE
https://t.co/K4hAf7ktRH
https://t.co/K4hAf7ktRH
CERTSI
Ejecución remota de código en Hewlett Packard Enterprise Intelligent Management Center
Se ha identificado una vulnerabilidad de ejecución remota de código en Hewlett Packard Enterprise Intelligent Management Center (iMC).
PowerShell: How to automatically backup the netlogon debug log
https://social.technet.microsoft.com/wiki/contents/articles/11937.powershell-how-to-automatically-backup-the-netlogon-debug-log.aspx
https://social.technet.microsoft.com/wiki/contents/articles/11937.powershell-how-to-automatically-backup-the-netlogon-debug-log.aspx
Microsoft
PowerShell: How to automatically backup the netlogon debug log - TechNet Articles - United States (English) - TechNet Wiki
Technical articles, content and resources for IT Professionals working in Microsoft technologies
Forwarded from Una al día
unCAPTCHA rompe hasta 450 captchas en cerca de 5 segundos y medio.
http://unaaldia.hispasec.com/2017/10/uncaptcha-rompe-hasta-450-captchas-en.html
http://unaaldia.hispasec.com/2017/10/uncaptcha-rompe-hasta-450-captchas-en.html
Hispasec
unCAPTCHA rompe hasta 450 captchas en cerca de 5 segundos y medio.
Boletín de noticias de seguridad informática unaaldia, ofrecido por Hispasec
#BadRabbit lo ha vuelto a hacer. Descubra cómo reaccionar ante la NUEVA CAMPAÑA DE RANSOMWARE DE GRAN ESCALA
https://t.co/IfAF0MvHEn
https://t.co/IfAF0MvHEn
Talosintelligence
Threat Spotlight: Follow the Bad Rabbit
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
#Oracle
username: OIMINTERNAL
pwd: (single space character)
https://docs.oracle.com/cd/E40329_01/admin.1112/e27149/appdefaultusr.htm#OMADM5326
username: OIMINTERNAL
pwd: (single space character)
https://docs.oracle.com/cd/E40329_01/admin.1112/e27149/appdefaultusr.htm#OMADM5326
APPLE PATCHES KRACK VULNERABILITY IN IOS 11.1
https://threatpost.com/apple-patches-krack-vulnerability-in-ios-11-1/128707/
https://threatpost.com/apple-patches-krack-vulnerability-in-ios-11-1/128707/
Threatpost | The first stop for security news
Apple Patches KRACK Vulnerability in iOS 11.1
Apple has patched the KRACK vulnerability in iOS and elsewhere in its product line, closing a key re-installation vulnerability in the WPA2 protocol implemented used by its software.
Python-based backdoor trojan controlled through
pastebin[.]com,
https://t.co/jQ6tOVGNV9[.]com and
notes[.]io
https://news.drweb.com/show/?i=11528&lng=en
https://vms.drweb.com/virus/?i=15822968&lng=en
pastebin[.]com,
https://t.co/jQ6tOVGNV9[.]com and
notes[.]io
https://news.drweb.com/show/?i=11528&lng=en
https://vms.drweb.com/virus/?i=15822968&lng=en
WordPress Releases Security Update
https://t.co/qy7krNVcJc
https://t.co/qy7krNVcJc
www.us-cert.gov
WordPress Releases Security Update
WordPress versions prior to 4.8.3 are affected by a vulnerability. A remote attacker could exploit this vulnerability to obtain sensitive information.US-CERT encourages users and administrators to review the WordPress Security Release and upgrade to WordPress…
Nearly undetectable #Microsoft Office #exploit installs #malware without an email attachment
https://t.co/1weMpbtzWD
https://t.co/1weMpbtzWD
TechRepublic
Nearly undetectable Microsoft Office exploit installs malware without an email attachment
Security firm Sophos uncovered a zero day exploit that targets a 24-year-old data exchange protocol, and it can be used to silently attack machines with very little means of detection.
WordPress 4.8.3, actualización de seguridad
https://t.co/MlUGsNwa79
https://t.co/MlUGsNwa79
Daboweb | Seguridad y ayuda informática |
[Breves] Wordpress 4.8.3, actualización de seguridad - Daboweb | Seguridad y ayuda informática |
Nueva actualización para WordPress, la 4.8.3 considerada de seguridad que soluciona un problema grave de seguridad sobre la función $wpdb->prepare() que a pesar de no ser vulnerable por si misma podría llegar a inyectar código SQL a través de peticiones inseguras…