ru
Feedback
Netsec

Netsec

Открыть в Telegram

This channel posts the feed from r/netsec. For any suggestions dm @streaak Donate to keep the bot running https://www.paypal.me/akhilgv

Больше
7 893
Подписчики
+124 часа
+207 дней
+13230 дней

Загрузка данных...

Привлечение подписчиков
сентябрь '26
сентябрь '26
+154
в 2 каналах
август '26
+132
в 2 каналах
Get PRO
июль '26
+140
в 1 каналах
Get PRO
июнь '26
+148
в 2 каналах
Get PRO
май '26
+162
в 3 каналах
Get PRO
апрель '26
+146
в 3 каналах
Get PRO
март '26
+108
в 2 каналах
Get PRO
февраль '26
+139
в 3 каналах
Get PRO
январь '26
+155
в 4 каналах
Get PRO
декабрь '25
+112
в 2 каналах
Get PRO
ноябрь '25
+163
в 3 каналах
Get PRO
октябрь '25
+119
в 1 каналах
Get PRO
сентябрь '25
+144
в 2 каналах
Get PRO
август '25
+80
в 2 каналах
Get PRO
июль '25
+103
в 3 каналах
Get PRO
июнь '25
+119
в 3 каналах
Get PRO
май '25
+45
в 3 каналах
Get PRO
апрель '25
+110
в 2 каналах
Get PRO
март '25
+125
в 2 каналах
Get PRO
февраль '25
+126
в 2 каналах
Get PRO
январь '25
+88
в 2 каналах
Get PRO
декабрь '24
+200
в 1 каналах
Get PRO
ноябрь '24
+626
в 4 каналах
Get PRO
октябрь '24
+223
в 2 каналах
Get PRO
сентябрь '24
+227
в 1 каналах
Get PRO
август '24
+162
в 2 каналах
Get PRO
июль '24
+148
в 1 каналах
Get PRO
июнь '24
+137
в 1 каналах
Get PRO
май '24
+190
в 1 каналах
Get PRO
апрель '24
+240
в 1 каналах
Get PRO
март '24
+287
в 1 каналах
Get PRO
февраль '24
+234
в 0 каналах
Get PRO
январь '24
+269
в 1 каналах
Get PRO
декабрь '23
+280
в 1 каналах
Get PRO
ноябрь '23
+511
в 1 каналах
Get PRO
октябрь '23
+244
в 1 каналах
Get PRO
сентябрь '23
+315
в 0 каналах
Get PRO
август '23
+243
в 0 каналах
Get PRO
июль '23
+869
в 0 каналах
Get PRO
июнь '23
+1 129
в 0 каналах
Get PRO
май '23
+253
в 0 каналах
Get PRO
апрель '23
+27
в 0 каналах
Get PRO
март '23
+51
в 0 каналах
Get PRO
февраль '23
+38
в 0 каналах
Get PRO
январь '23
+38
в 0 каналах
Get PRO
декабрь '22
+28
в 0 каналах
Get PRO
ноябрь '22
+32
в 0 каналах
Get PRO
октябрь '22
+32
в 0 каналах
Get PRO
сентябрь '22
+60
в 0 каналах
Get PRO
август '22
+61
в 0 каналах
Get PRO
июль '22
+47
в 0 каналах
Get PRO
июнь '22
+28
в 0 каналах
Get PRO
май '22
+37
в 0 каналах
Get PRO
апрель '22
+47
в 0 каналах
Get PRO
март '22
+99
в 0 каналах
Get PRO
февраль '22
+32
в 0 каналах
Get PRO
январь '22
+28
в 0 каналах
Get PRO
декабрь '21
+39
в 0 каналах
Get PRO
ноябрь '21
+29
в 0 каналах
Get PRO
октябрь '21
+24
в 0 каналах
Get PRO
сентябрь '21
+27
в 0 каналах
Get PRO
август '21
+55
в 0 каналах
Get PRO
июль '21
+33
в 0 каналах
Get PRO
июнь '21
+267
в 0 каналах
Get PRO
май '21
+22
в 0 каналах
Get PRO
апрель '21
+68
в 0 каналах
Get PRO
март '21
+37
в 0 каналах
Get PRO
февраль '21
+65
в 0 каналах
Get PRO
январь '21
+28
в 0 каналах
Get PRO
декабрь '20
+1 448
в 0 каналах
Дата
Привлечение подписчиков
Упоминания
Каналы
23 сентября+6
22 сентября+5
21 сентября+11
20 сентября+3
19 сентября+6
18 сентября+4
17 сентября+5
16 сентября+4
15 сентября+6
14 сентября+7
13 сентября+6
12 сентября+6
11 сентября+1
10 сентября+6
09 сентября+9
08 сентября+5
07 сентября+5
06 сентября+6
05 сентября+7
04 сентября+13
03 сентября+26
02 сентября+3
01 сентября+4
Посты канала
I asked my AI agent to inspect a website. The website took over my machine (34-run measurement across 5 agent harnesses) https://ift.tt/XTw17NA Submitted September 24, 2026 at 01:26AM by DaimoNNN via reddit https://ift.tt/4xmaZTM

2
Breaking the Superuser Guardrails of managed-PostgreSQL Providers https://ift.tt/1YW7QpU Submitted September 24, 2026 at 01:26AM by wtfse via reddit https://ift.tt/mD6qlkj
90
3
Inside Corp MDM, the Android spyware targeting logistics companies https://ift.tt/pLsq2PN Submitted September 23, 2026 at 07:24PM by JDBHub via reddit https://ift.tt/Wfu0pgy
191
4
Android 17 enables certificate transparency, and breaks custom CAs https://ift.tt/SNPcF1n Submitted September 23, 2026 at 05:56PM by ScottContini via reddit https://ift.tt/9izIsOZ
227
5
Free, hands-on 14-week university security course (open to anyone online) https://ift.tt/HzjLWeV Submitted September 22, 2026 at 03:16PM by mrigaki via reddit https://ift.tt/I6kRGyN
262
6
Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy https://ift.tt/jMGDAOp Submitted September 23, 2026 at 10:50AM by mabote via reddit https://ift.tt/ypd8Dr5
295
7
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam https://ift.tt/Ov7RV9K Submitted September 23, 2026 at 09:23AM by AnimalStrange via reddit https://ift.tt/Z5FtdJp
287
8
Frame: Grounding LLM Vulnerability Detection with a Sound Separation-Logic Core https://lambdasec.github.io/Frame-Grounding-LLM-Vulnerability-Detection-with-a-Sound-Separation-Logic-Core/ Submitted September 23, 2026 at 06:05AM by Last-Health3222 via reddit https://ift.tt/ZH0gWn2
272
9
The finding said RCE. The second tester asked one question and the ticket died. Last year I inherited a “critical RCE” from an automated pass.The request looked perfect. Parameter host. Payload 8.8.8.8; sleep 5. Status 200. Response time jumped from ~800ms to ~6s. The scanner wrote OS command injection, confidence high. The client had already seen the word critical in the draft.I replayed it once. Same delay. Replay again. 1.1s. Again. 7s. Again. 900ms. The sleep was not in the response body. id came back as the literal string id. expr 41 + 1 came back as the literal string. The page was a diagnostics form. It echoed the query and, under load, the WAF in front of it spent extra time on anything that looked like a shell metacharacter.That is a known failure mode, not a rare one. Time-based command-injection checks fire when the response is merely slower, which also happens when the scan itself saturates the app, when a WAF inspects a “more suspicious” request, when a CDN queues you, or when the page is just doing a heavier search. SANS has been writing this up for years: ping -c 20 127.0.0.1 during a busy scan is not proof. ZAP’s sleep payloads have the same problem, and in some rules even reflecting the command string is enough to raise the issue. A 200 that contains bash -c is often a docs page, not a shell. The useful question is not “did a payload land.” It is “what value in this response can only exist if the server evaluated my input?” What I do now, on the same request, before I write the word confirmed:Send a benign twin. Same cookies, same content-type, same parameter, no metacharacters. That is the control. If the “interesting” string is already there, stop. That is echo, not execution.Do not ask the server to say whoami. Ask it to compute something it has never seen. Two random integers, added, wrapped in canaries that are also random for that probe. If the body contains the sum and the control does not, you have a result that reflection cannot invent.If there is no output channel, do not promote a single slow request. Change the delay. Plot it. If 3 / 7 / 11 seconds do not track the payload, it is jitter or a WAF. PortSwigger has a nice version of this trap: an exec-looking parameter delayed because the WAF worked harder, not because a binary ran. A DNS callback is a sink, not a shell. Collaborator lighting up after you plant a URL is often a link previewer, a safe-browsing fetch, or a JNDI lookup that never loaded a class. Fastjson / Log4j writeups on here keep dying at that step: four DNS hits, zero command. Say lookup. Do not say RCE until a value only the target could have computed comes back, or you have a class-load you can show.If your flags never built a probe for that sink, the result is not negative. It is untested. I have watched people paste “not vulnerable” into a report because the scanner used shell separators against an OGNL parameter. Struts will happily evaluate %{7*7} and still return nothing useful to ; id. Wrong claim, clean-looking ticket.The ticket I inherited was closed as a false positive in fifteen minutes once the control existed. The next one, on a lab Webmin box, survived because the response contained a sum the request never sent. Same scanner family. Different question.If you only remember one thing from this: before you file P1, ask whether a second person can reproduce a value, not a delay. Triage queues are full of the second kind. That is why “not reproducible” shows up on reports that felt obvious at 1 a.m.I later wrapped the control + random-arithmetic check into a small stdlib-only helper so I would stop doing it by hand on jump boxes. That is not the point of the post. The point is the question. If you want the benches against Webmin / Struts2 / a Log4j lookup so you can disagree with the verdict names, I will drop the repo in a comment. Submitted September 22, 2026 at 05:58PM by No-View3333 via reddit https://ift.tt/cHBbGuj
290
10
CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) https://ift.tt/F7GwLVQ Submitted September 22, 2026 at 04:45PM by AlexandreDaubois via reddit https://ift.tt/ir6ZaF5
319
11
vCenter pre-auth RCE: CVE-2026-59309/59310 https://ift.tt/zJ9a7yN Submitted September 22, 2026 at 01:28PM by MobetaSec via reddit https://ift.tt/UohWrc9
323
12
Agent Blast Radius: Graph-Based Modeling, Admission Prevention, and LLM Benchmarking for Kubernetes Privilege Escalation https://ift.tt/CJ153X4 Submitted September 22, 2026 at 11:52AM by vishalmurugan1986 via reddit https://ift.tt/tSe2MuH
304
13
From a Sandbox Pod to cluster-admin: Benchmarking Autonomous LLM Agents on K8s Privilege Escalation https://ift.tt/CJ153X4 Submitted September 22, 2026 at 11:45AM by vishalmurugan1986 via reddit https://ift.tt/IS8a6Ah
301
14
Inside BambooToken’s Linux implant: shell and file control over MQTT https://app.reverser.space/p/duckie/inside-bambootoken-s-linux-implant-shell-and-file Submitted September 22, 2026 at 09:06AM by 420ass_slayer69 via reddit https://ift.tt/trEyg7s
304
15
Windows Exploitation Techniques: Dangling COM Object Registrations https://ift.tt/tfrgQJv Submitted September 22, 2026 at 08:49AM by wojtekch via reddit https://ift.tt/G3z9VEI
292
16
Implant Encryption via the Dump Encoding Library https://ipurple.team/2026/09/21/dump-encoding-library/ Submitted September 21, 2026 at 11:32PM by netbiosX via reddit https://ift.tt/2q0XNTG
338
17
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 https://minanagehsalalma.github.io/zte-smartlife-app-pwned/ Submitted September 21, 2026 at 10:00PM by TheReedemer69 via reddit https://ift.tt/6FZrOV0
356
18
ChatGPT now knows what you do on other websites via ad collector https://ift.tt/1WvKSGj Submitted September 20, 2026 at 09:02PM by AdTemporary2475 via reddit https://ift.tt/o2OsxtR
403
19
Three memory-safety bugs in Godot's untrusted-file parsers https://ift.tt/aL0FjdV Submitted September 21, 2026 at 02:38PM by bitbutter via reddit https://ift.tt/vL1NnXQ
370
20
Silent packet loss in PcapSplitter: a file collision bug on TCP session reuse https://ift.tt/yFW3fA6 Submitted September 21, 2026 at 07:35AM by Hot_Interest_4915 via reddit https://ift.tt/l1KMyOv
461