"Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearSE
Jump
Fake zero-day PoC exploits on GitHub push Windows, Linux malware
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearEX
    execveat
    1y ago 100%

    They're not even that stealthy. The code is bullshit, gitignore folder is super suspicious and malware is just a binary within the zip file. Clearly meant for script kiddies.

    1
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearSE
    Security News execveat 1y ago 100%
    Fake zero-day PoC exploits on GitHub push Windows, Linux malware
    www.bleepingcomputer.com

    Someone created a bunch of github profiles impersonating real researchers alongside fake Twitter accounts. Pretty fascinating, really.

    3
    3
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research execveat 1y ago 100%
    WWDC23: Passkeys
    blog.millerti.me
    1
    0
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research execveat 1y ago 100%
    BChecks (SDL for defining custom scans) available in Burp 2023.6
    portswigger.net

    It's like nuclei templates I guess, but built into Burp. Only available in the Early Adopter release for now.

    1
    1
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research 1y ago
    Jump
    What's your side project of a month?
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearEX
    execveat
    1y ago 100%

    I played around with WebSockets and wrote a new tool: https://github.com/doyensec/wsrepl

    It's an interactive REPL interface like websocat, but it's meant specifically for pentesting, not debugging, and it's easily extensible in Python (while still retaining REPL interface). In future releases I'd like to expand the extensibility by adding declarative style configuration (the ultimate feature would be something like what Burp's Autorize plugin does, but for websockets).

    1
  • "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research execveat 1y ago 100%
    Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures
    https://www.usenix.org/system/files/sec23summer_235-rohlmann-prepub.pdf

    OOXML signatures are rendered pretty much useless due to 3 flaws in specification and 2 flaws in implementation. *"The vulnerabilities have been acknowledged by Microsoft. However, Microsoft has decided that the vulnerabilities do not require immediate attention."*

    2
    0
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearSE
    Security News execveat 1y ago 100%
    Fortinet tries to silently patch critical RCE, researches burn it
    www.bleepingcomputer.com

    *Timely and ongoing communications with our customers is a key component in our efforts to best protect and secure their organization. There are instances where confidential advance customer communications can include early warning on Advisories to enable customers to further strengthen their security posture, prior to the Advisory being publicly released to a broader audience. This process follows best practices for responsible disclosure to ensure our customers have the timely information they need to help them make informed risk-based decisions. For more on Fortinet’s responsible disclosure process, visit the Fortinet Product Security Incident Response Team (PSIRT) page: https://www.fortiguard.com/psirt_policy.*

    2
    1
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research execveat 1y ago 100%
    CS:GO: From Zero to 0-day
    neodyme.io

    They've chained 4 logic bugs to achieve RCE in CS:GO, pretty impressive. Valve sucks at communication and bug bounty payouts though.

    2
    0

    cross-posted from: https://infosec.pub/post/48321 > If you're working on a research or side project, this is your platform to share your findings, roadblocks, breakthroughs, and more. Doesn't matter if it's still a work in progress or has been recently published - all stages of research are welcome. > > Maybe you're not actively researching, but you're closely following an interesting development in the industry or a certain researcher's work - feel free to share that here too! > > Or perhaps, you've got an idea for a project or research you wish to undertake, but need resources, collaborators, or simply some guidance - let the community know. > > Here's a simple guideline to kickstart the conversation: > > - What's the research about? (Give a brief overview of the project or topic) > - Current progress/Findings (If applicable) > - Challenges and roadblocks (What issues are you facing or expect to face?) > - Help needed (Are you looking for collaborators, resources, advice, etc.?)

    1
    0
    "Initials" by "Florian Körner", licensed under "CC0 1.0". / Remix of the original. - Created with dicebear.comInitialsFlorian Körnerhttps://github.com/dicebear/dicebearRE
    Research execveat 1y ago 100%
    What's your side project of a month?

    If you're working on a research or side project, this is your platform to share your findings, roadblocks, breakthroughs, and more. Doesn't matter if it's still a work in progress or has been recently published - all stages of research are welcome. Maybe you're not actively researching, but you're closely following an interesting development in the industry or a certain researcher's work - feel free to share that here too! Or perhaps, you've got an idea for a project or research you wish to undertake, but need resources, collaborators, or simply some guidance - let the community know. Here's a simple guideline to kickstart the conversation: - What's the research about? (Give a brief overview of the project or topic) - Current progress/Findings (If applicable) - Challenges and roadblocks (What issues are you facing or expect to face?) - Help needed (Are you looking for collaborators, resources, advice, etc.?)

    2
    2