Posts
2437
Following
590
Followers
1308
A drunken debugger

Heretek of Silent Signal
repeated
repeated

CVE-2024-38856, an incorrect authorization vulnerability affecting all but the latest version of Apache OFBiz, may be exploited by remote, unauthenticated attackers to execute arbitrary code on vulnerable systems.

https://www.helpnetsecurity.com/2024/08/05/cve-2024-38856/

0
2
0
repeated

We break down the cryptography services offered within Google Cloud Platform —Cloud KMS, Secret Manager, and Confidential Computing—helping you decide which tools are right for your project. https://buff.ly/3WQB69S

0
3
0
We have this Deposit Return System freshly implemented and of course the IT backend broke after few weeks.

The important thing to notice is that the operator just won't take *any* responsibility/SLA for the IT system, because IT just breaks y'know.

This rhymes pretty much with CrowdStrike's narrative about some random vendor taking out 8M computers is _just inevitable_. (see also: https://risky.biz/WWC4/ )

I'd also bet the reason they can't even tell when they will be able restore transaction processing is that their backend is some unnecessarily complex k8s and/or cloud-native monstrosity... (see also: https://blog.thinkst.com/2024/07/unfashionably-secure-why-we-use-isolated-vms.html )

(Report in Hungarian: https://hvg.hu/gazdasag/20240805_A-Mohu-Repont-app-kotelezo-visszavaltas-ebx )
0
0
0
repeated

Elastic: Dismantling Smart App Control
Elastic claims that Windows Smart App Control and SmartScreen have several design weaknesses that allow attackers to gain initial access with no security warnings or popups. A bug in the handling of LNK files can also bypass these security controls. They research bypasses for reputation-based systems and develop detections to identify indicators of attack. No CVE IDs associated.
See related The Hacker News reporting: Researchers Uncover Flaws in Windows Smart App Control and SmartScreen

0
1
0
University student phished others so he could steal their grants. Article in Hungarian:

https://hvg.hu/itthon/20240805_Feltorte-a-Neptun-rendszert-es-maganak-utalta-el-a-diakok-osztondijat-a-csalo-ebx

I'd like to note that In my time we wouldn't think of stealing from broke-ass students like ourselves...also had proper RCE's :P

#Hungary #Neptun
1
0
3
[RSS] Pnut: A Self-Compiling C Transpiler Targeting Human-Readable POSIX Shell

https://hackaday.com/2024/07/25/pnut-a-self-compiling-c-transpiler-targeting-human-readable-posix-shell/
0
0
0
[RSS] [Blog] Teaching the Old .NET Remoting New Exploitation Tricks

https://code-white.com/blog/teaching-the-old-net-remoting-new-exploitation-tricks/
1
3
3
[RSS] Breaking Barriers and Assumptions: Techniques for Privilege Escalation on Windows: Part 3

https://www.thezdi.com/blog/2024/7/31/breaking-barriers-and-assumptions-techniques-for-privilege-escalation-on-windows-part-3
0
0
0
[RSS] Extending Burp Suite for fun and profit – The Montoya way – Part 6

https://security.humanativaspa.it/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-6/
0
1
2
[RSS] Heap exploitation, glibc internals and nifty tricks.

http://blog.quarkslab.com/heap-exploitation-glibc-internals-and-nifty-tricks.html
0
0
1
Why Google’s “Dear Sydney” Ad Makes Me Want to Scream - by Shelly Palmer

https://shellypalmer.com/2024/07/why-googles-dear-sydney-ad-makes-me-want-to-scream/

(The ad was revoked, but this is still a great piece about the fundamental problems it represented)
0
2
1
repeated

“Crowdstrike has made intentional architectural engineering and QA decisions that made this happen. They were negligent in their engineering decisions and their QA decisions.”

@alexstamos starts off strong on his latest @riskybiz episode.

Note to sec company CTOs/CISOs:

If u put in the work to engage with the community on topics that don’t directly affect what u are selling, it buys u some leeway when u have to discuss products that do..

Many would be flamed for taking this stance openly. He pulls it off.

https://pca.st/episode/17c7a25f-faee-479a-b653-53f62679cc02

0
3
0
repeated

Fifteen years ago today, a group of hackers and security pros got together and made a little thing happen, the first ever BSides @SecurityBSidesGlobal, @BSidesLV

Things took off from there.

The next BSides on the event calendar is BSides Las Vegas, and it will be event number 1002.

0
3
1
Afk brb!
0
0
1
repeated

⚠️ Confirmed: Network data show disruptions to multiple internet providers in amid reports of a fibre sabotage campaign targeting telecoms infrastructure during the Paris 2024 Olympics 📉

0
7
0
repeated

Domi.UwUException | this nickname is now extra long to prove a point, hi linus yes ~~it runs netware

protip: when referring to your favourite programming language’s features, call them spells instead to sound more mysterious and cool.

neocat_thumbsdown “memory safety feature”

neocat_thumbsup “memory safety spell”

4
4
0
Show older