ӉѦСҠіИԌ ҬЄѦӍ СѦИѦL ѺҒіСіѦL DіҒԱՏіóИ
قناة بسيطة
1 781
المشتركون
لا توجد بيانات24 ساعات
لا توجد بيانات7 أيام
لا توجد بيانات30 أيام
أرشيف المشاركات
"Parsing a maliciously crafted plist may lead to an unexpected app termination or arbitrary code execution"
Вот и 0-click RCE была зафикшена в iOS/iPadOS 16.4 и macOS 13.3
2023 Web Hacking Roadmap // How To Bug Bounty
https://www.youtube.com/watch?v=doFo0I_KU0o
JSpector is a Burp Suite extension that passively crawls JavaScript files and automatically creates issues with URLs and endpoints found on the JS files.
https://github.com/hisxo/JSpector
WAF bypass Tool is an open source tool to analyze the security of any WAF for False Positives and False Negatives using predefined and customizable payloads
https://github.com/nemesida-waf/waf-bypass
véanlo les servirá para entender como funcionan las leyes informáticas https://www.youtube.com/watch?v=FQGK4WGWEBw
TikTok es el ‘caballo de Troya’ de China, advierte la inteligencia de EE. UU. https://hipertextual.com/2023/03/tiktok-caballo-de-troya-china
Fancy Bear and where to find them https://www.tarlogic.com/blog/fancy-bear-where-to-find-them/
Múltiples vulnerabilidades permiten RCE en “Baseband Remote Exynos Modems” https://unaaldia.hispasec.com/2023/03/multiples-vulnerabilidades-permiten-rce-en-baseband-remote-en-exynos-modems.html?utm_source=rss&utm_medium=rss&utm_campaign=multiples-vulnerabilidades-permiten-rce-en-baseband-remote-en-exynos-modems
ChatGPT expuso los datos personales de sus usuarios, confirma OpenAI https://hipertextual.com/2023/03/bug-chatgpt-expuso-datos-personales-usuarios
🛠 Global Socket 1.4.40 🛠
Global Socket is a tool for moving data from here to there, securely, fast, and through NAT and firewalls. It uses the Global Socket Relay Network to connect TCP pipes, has end-to-end encryption (using OpenSSL's SRP / RFC-5054), AES-256 and key exchange using 4096-bit Prime, requires no PKI, has Perfect Forward Secrecy, and TOR support.
📖 Read
via "Packet Storm Security".⚙️ "Cómo ejecutar cmd.exe o powershell.exe con una imagen renombrada a .bat" https://www.hackplayers.com/2023/02/como-ejecutar-cmdexe-o-powershellexe.html
#BlueTeam #cve #exploit
•Privilege Escalation in Windows 7/8/10 through Atom Table Hijacking
https://github.com/SleepTheGod/Windows-Atom-Table-Hijacking
•CVE-2022-23773 : cmd/go in Go <1.16.14, 1.17.x - 1.17.7 can misinterpret branch names that falsely appear to be version tags (incorrect access control)
https://github.com/Liuyushung/CVE-2022-23773-Reproduce
Ultimos detalles sobre el arresto de Pompompurin
El fundador del famosos foro BreachedForums ha sido acusado formalmente en los EEUU de conspiracion por cometer fraude con dispositivos electronicos. Si se prueba la culpabilidad de Fitzpatrick, apellido del acusado, puede enfrentar un maximo de 5 años de prision. Segun documentos judiciales Fitzpatrick a cometido varios errores estupidamentes graves en contra de su OPSEC, como ser: uso correos personales para registrarse en foros de pirateria como RaidForum y el suyo Breached.vc, tambien segun el documento Fitzpatrick habia accedido a Breached sin usar un VPN. Los federales habian consultado datos a empresas como Verizon, Zoom, Apple y Google dando asi las pruebas suficientes para acusarlo de ser el administrador del infame foro Breached.#breached #pompompurin #busted #hackers Documentos judiciales: https://www.courtlistener.com/docket/67027008/united-states-v-fitzpatrick/
ICS and OT Vulnerabilities Analysis for 2022 https://claroty.com/resources/reports/state-of-xiot-security-2h-2022
Microsoft vetará a aquellos que usen la búsqueda de Bing en sus chatbot
https://elchapuzasinformatico.com/?p=500788
