Posts
2355
Following
513
Followers
1230
A drunken debugger

Heretek of Silent Signal
repeated
[RSS] Linksys Velop Routers Caught Sending WiFi Creds in the Clear

https://hackaday.com/2024/07/15/linksys-velop-routers-caught-sending-wifi-creds-in-the-clear/
0
3
1
repeated

We love Open Source contributors.

If you are a significant contributor to an Open Source project, DM us, and we will give you a full briefings pass to BlackHat USA (absolutely free).

__
* Tickets handed out totally at our discretion;
** We only have a few tickets left;

0
3
0
repeated

fq 0.12.0 released 🥳 nothing fancy, REPL and jpeg fixes otherwise mostly update of dependencies.

https://github.com/wader/fq/releases/tag/v0.12.0

0
2
0
[oss-security] backtrace_symbols() misuse by Ceph and its supposedly-safe use

Interesting thread on safe crash handling in the light of signal handler races

https://www.openwall.com/lists/oss-security/2024/07/12/1
0
1
2
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472) (4920.00USD)

https://hackerone.com/reports/2585385
0
0
0
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474) (4920.00USD)

https://hackerone.com/reports/2585381

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
0
0
0
[RSS] Resurrecting a dead Dune RTS game

https://wheybags.com/blog/emperor.html
0
7
7
repeated

Spent the last four days coordinating incident response for the Squarespace domain hijackings with @tay and @AndrewMohawk. Now that it seems to be resolved, we wrote a little postmortem/retrospective

https://securityalliance.notion.site/A-Squarespace-Retrospective-or-How-to-Coordinate-an-Industry-Wide-Incident-Response-fead693b66c14543a48283d85aec19ad

1
3
0
repeated

Starting from v0.10 (the next version), HyperDbg uses @keystone_engine as its assembler. ❤️

Thanks to our new team member @AbbasMasoumiG for adding it.

The following commands are added to assemble virtual and physical memory:

- https://docs.hyperdbg.org/commands/debugging-commands/a

- https://docs.hyperdbg.org/commands/extension-commands/a

1
1
1
repeated

Clever & fun technique to dump LSA secrets bypassing by @sensepost

Dumping LSA secrets: a story about task decorrelation

https://sensepost.com/blog/2024/dumping-lsa-secrets-a-story-about-task-decorrelation/

0
5
1
I almost felt guilty finding out the guy accidentally gave me two of these "original palestinian" scarves instead of one
0
0
2
[RSS] SSD Advisory – SonicWall SMA100 Stored XSS to RCE

https://ssd-disclosure.com/ssd-advisory-sonicwall-sma100-stored-xss-to-rce/
0
1
1
repeated

Introduction to the Wild West of Proof of Concept Code () aka SSHing the Masses

https://santandersecurityresearch.github.io/blog/sshing_the_masses.html

1
3
0
repeated
Edited 2 months ago
5
21
4
repeated

Everyone complains about meetings, but rarely anybody puts time before the meeting to do the work needed for the meeting to be useful.

6
2
1
Evernote RCE: From PDF.js font-injection to All-platform Electron exposed ipcRenderer with listened BrokerBridge Remote-Code Execution

https://0reg.dev/blog/evernote-rce
0
1
4
Show older