Kali Linux And Termux
Відкрити в Telegram
Welcome to our channel . Here is our chat group @kalinux2021
Показати більше1 569
Підписники
+524 години
+217 днів
+11930 день
Архів дописів
Repost from Hypersec
🛡Kali Linux
The xz package, starting from version 5.6.0 to 5.6.1, was found to contain a backdoor. The impact of this vulnerability affected Kali between March 26th to March 29th. If you updated your Kali installation on or after March 26th, it is crucial to apply the latest updates today:
sudo apt update && sudo apt install --only-upgrade liblzma5
🔗 https://www.helpnetsecurity.com/2024/03/29/cve-2024-3094-linux-backdoor/
🔗 https://www.openwall.com/lists/oss-security/2024/03/29/4
🔗 https://threadreaderapp.com/thread/1773786266074513523.html
📲 [ tweet ]
⚠️ UPDATE ASAP ⚠️
#CVE
تیم سورینRepost from Hypersec
⚠️CVE-2024-3094 (CVSS 10): Backdoor Flaw Discovered in Popular Linux Compression Tool
آسیب پذیری CVE-2024-3094 یک آسیبپذیری مهم ( CVSS 10.0) است که بر نسخههای 5.6.0 و 5.6.1 نرمافزار فشردهسازی داده XZ Utils تأثیر میگذارد و به طور گسترده در توزیعهای اصلی لینوکس استفاده میشود.
⏺تجزیه و تحلیل آسیب پذیری :
🟧تأثیر: کدهای مخرب در نسخههای 5.6.0 و 5.6.1 XZ Utils درج شد و به مهاجمان این امکان را میدهد تا به طور بالقوه دسترسی غیرمجاز از راه دور به سیستمهای آسیبپذیر داشته باشند.
◾️علت: این آسیبپذیری از یک supply chain attack ناشی میشود که در آن کدهای مخرب در طول فرآیند ساخت به داخل نرمافزار نفوذ کرده است.
🔴اکسپلویت: مهاجمان از کتابخانه در معرض خطر برای تزریق کد به فرآیند سرور OpenSSH استفاده کردند و آنها را قادر می ساخت تا احراز هویت را دور بزنند و دستورات را روی سیستم اجرا کنند.
خوشبختانه، آسیب پذیری نسبتاً سریع شناسایی شده و وصله ها توسط توزیع های اصلی لینوکس منتشر شد.
🔗https://nvd.nist.gov/vuln/detail/CVE-2024-3094
🔗https://securityonline.info/cve-2024-3094-cvss-10-backdoor-flaw-discovered-in-popular-linux-compression-tool/
#CVE
تیم سورین
Kali Linux 2024.1 Release (Micro Mirror) | Kali Linux Blog
https://www.kali.org/blog/kali-linux-2024-1-release
FTC fined Avast $16.5 million for collecting and selling users' browsing data despite privacy promises.
Full story: https://thehackernews.com/2024/02/ftc-slams-avast-with-165-million-fine.html
🧶BurpSuite Roadmap
🔗https://github.com/Ignitetechnologies/Mindmap/blob/main/Burp%20Suite/Burp%20Suite%20UHD.png
●▬۩❁ @geeekgirls ❁۩▬●
#burpsuite
Repost from The Hacker News
🔥 Chrome Zero-Day Alert!
Update your browser NOW to patch a new critical flaw exploited by hackers. This memory leak bug lets attackers steal your secrets.
Learn more about CVE-2024-0519:
https://thehackernews.com/2024/01/zero-day-alert-update-chrome-now-to-fix.html
⚡ Critical security flaw found in Opera Browser!
MyFlow sync feature lets attackers take over your Windows and macOS systems.
Read the full story: https://thehackernews.com/2024/01/opera-myflaw-bug-could-let-hackers-run.html
Attention all GitLab users! 🚨🚨🚨
Attention all GitLab users! 🚨🚨🚨
Several vulnerabilities have recently been discovered in GitLab that require immediate attention. These vulnerabilities include CVE-2023-7028, CVE-2023-5356, CVE-2023-2030, and several others.
🔒 These vulnerabilities range in severity from 3.5 to 10.0, making them a critical threat to your GitLab. It is imperative that you take immediate action to protect your sensitive data and prevent any potential breach.
Here's what you need to know:
1️⃣ CVE-2023-7028:
This vulnerability allows an attacker to bypass authentication and gain unauthorized access to your GitLab. It is important to update to the latest version of GitLab, as a patch has been released to fix this issue.
2️⃣ CVE-2023-5356:
This vulnerability exposes sensitive information, including user credentials, due to improper input validation. To mitigate this risk, we strongly recommend that you update yourself and apply strict input verification measures.
3️⃣ CVE-2023-2030:
This vulnerability would allow an attacker to execute arbitrary code on your GitLab server, potentially leading to a complete compromise of your system. Updating to the latest version and applying any available security patches is essential.
👉🏻 Link: https://nt.ls/IZZxE
👉🏻 Dork: http.meta:"Gitlab"
Vendor's advisory : https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
#GitLab #Security #Vulnerabilities #CVEs #StaySecure
Sorin's team
Best way to install nodejs in Debian based os
https://github.com/jakbin/nodejs-deb
Google settles a $5 billion class-action lawsuit over tracking in 'incognito mode.' Users believed their online activity was private on web browsers, but the settlement reveals hidden data collection.
Learn more: https://thehackernews.com/2024/01/google-settles-5-billion-privacy.html
#Kali Linux 2023.4 Release (Cloud ARM64, Vagrant Hyper-V & Raspberry Pi 5)
https://www.kali.org/blog/kali-linux-2023-4-release/
