Post #557
38
Channel Public Channel
AL Alaid TechThread
@offensive_thread
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
- Subscribers
- 1.14K
- Photos
- 7
- Videos
- 2
- Links
- 1.4K
Showing posts older than #558 · Back to latest
Older Posts 20 shown
Post #556
50
Post #555
33
Post #554
36
Post #553
55
Think Outside the Scope: Advanced CORS Exploitation Techniques | https://medium.com/@sandh0t/think-outside-the-scope-advanced-cors-exploitation-techniques-dad019c68397
Post #552
42
Post #551
35
Post #550
36
Post #549
37
Post #548
34
DVCW
Damn Vulnerable Crypto Wallet is an extremely insecure Ethereum cryptowallet written in JavaScript.
It has three main modules:
https://gitlab.com/badbounty/dvcw
GitLab Bad Bounty Repo / dvcw · GitLab Damn Vulnerable Crypto Wallet is an extremely insecure Ethereum cryptowallet written in JavaScript.
It has three main modules:
https://gitlab.com/badbounty/dvcw
Post #547
38
Post #546
85
Приложение для Splunk, ориентированное на сопровождение Threat Hunting процессов
https://github.com/olafhartong/ThreatHunting
https://github.com/olafhartong/ThreatHunting
Post #545
38
Reverse Shell Cheat Sheet
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md
https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md
Post #544
56
Еще несколько PoC для macOS/iOS
https://github.com/maldiohead/CVE-2019-8540
https://github.com/maldiohead/CVE-2019-null
https://github.com/maldiohead/CVE-2019-8540
https://github.com/maldiohead/CVE-2019-null
Post #543
49
Post #542
42
Post #541
40
Forwarded from Noise Security Bit
Похоже уязвимостям в процессорах от Интел нет конца и края. Сегодня анонсированы два новых типа side-channel атак с использованием спекулятивных вычислений. Атаки #RIDL (Rogue In-Flight Data Load) и #Fallout (атака на CPU Store Buffers) основаны на Microarchitectural Data Sampling (#MDL) техниках. Обе атаки основаны на том, что могут получить доступ к памяти на центральном процессоре/кэшу (Line Fill Buffers, Load Ports, Store Buffers) и таким образом получать несанкционированный доступ к конфиденциальной информации внутри SGX доменов и обходить изоляцию виртуализации (VTx). Возможность воспроизвести эти вектора из Javascript делают эти атаки довольно опасными для облачной инфраструктуры.
Детали: https://mdsattacks.com/
Кстати исследователи приедут рассказать об этих атаках на offzone.moscow в июне.
Детали: https://mdsattacks.com/
Кстати исследователи приедут рассказать об этих атаках на offzone.moscow в июне.
Post #539
41
https://cpu.fail - ресурс, посвященный уязвимостям в CPU
Forwarded from r0 Crew (Channel)
ANBU - Automatic New Binary Unpacker with PIN DBI Framework https://github.com/Fare9/ANBU #reverse #pin #dukeBarman