TGViewer
Channel Public Channel
cKure Red

cKure Red

@ckured

The director's cut on critical feeds from InfoSec world 🌎

Main Channel: @cKure

☕️ or queries email us
📨 i@ckure.org
Subscribers
2.78K
Photos
73
Videos
69
Links
481

Showing posts older than #490 · Back to latest

Older Posts 20 shown
Post #488
cKure Red pinned «🍊Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server. https://blog.orange.tw/posts/2024-08-confusion-attacks-en/»
Post #484
cKure Red pinned «☣️ Project Zero: ‘It Will Take All of Us to End The Era of Zero Days’. It’s becoming increasingly apparent that security research is not enough to end the era of zero days. Natalie Silvanovich https://duo.com/decipher/project-zero-it-will-take-all-of-us…»
Post #482 2.74K
Post #481 1.93K
💥💥💥
‼️‼️‼️

Cyber-Warfare
📍Apparently the Jew ✡️ (Israel) used sonic booms 💥 of fighter jets (apparently F-35s) in Beirut, Lebanon 🇱🇧 and nearby areas during the telecast of Hizbollah chief Hassan Nasrallah's speech to get his location in a corelation attack (had it been live).

https://x.com/Lonewolf8ier/status/1820825946212978816
Post #479 2.34K
Post #478 1.9K
🎧Basic offensive security tactics for various domains.
Post #477 2.04K
Post #474
cKure Red pinned «💥💥💥👉 Breached Forum backend data is publicly searchable. Includes credentials, registrant IP, and last login IP, among other details. https://bf.based.re/»
Post #473 2.24K
💥💥💥👉 Breached Forum backend data is publicly searchable.

Includes credentials, registrant IP, and last login IP, among other details.


https://bf.based.re/
Post #470 2.16K
💥 VPN Zero-Day

DYK most VPN services can actually make you less secure? Today x.com/PET_Symposium, Benjamin Mixon-Baca will present research done in collaboration with the Citizen Lab about how VPNs can enable an attacker to act as an in-path router between you and the VPN server. The study identifies a new vulnerability called a “port shadow”.
https://petsymposium.org/popets/2024/popets-2024-0070.pdf
X (formerly Twitter) PETS (@PET_Symposium) on X Official account of the Privacy Enhancing Technologies Symposium. Next event: PETS 2025, July 14-19, Washington, DC and Online. mastodon: @PET_Symposium@infosec
Post #468 2.52K
p25.pdf593.2 KB
🖥 Header Enrichment: A technique used by Telco operators to acquire MSISDN (phone number) through a website (HTTP-GET is enough).

It can be used to trace users and target them for ads by the ISP or their associated vendors. And if the API key 🔑 is leaked through a vendor or ISP itself.

Scenarios:
1. The token can be used by anyone in a get request to fetch the end-user's phone number. This request can be posted via QR-codes of restaurant menus where there will be HTTP-302 (redirection) to the actual menu or by injecting 💉.js in a vulnerable website (viz. XSS); which is famous (like some blog or forum).

2. A user sharing hotspot from their phone, the hotspot client can acquire the phone number. In addition to this, if the HE enables authentication. This would lead to 0-click account takeover.


● I had tested systems for this implementation for a telco. The telco without informing users (IMHO) was sharing data to third parties.
-Admin cKure


Source: https://conferences.sigcomm.org/sigcomm/2015/pdf/papers/hotmiddlebox/p25.pdf
Post #465 2.38K
🤍Rockyou-2024 has been released on July 4, 2024, in a 45 GB zip file.

Previous Rockyou-2021 had 8.4 billion passwords, and the new version has 1.5 billion (added by hacker 'ObamaCare'), making it a 10 billion word-list.
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →