Popular interview question: how to diagnose a mysterious process that’s taking too much CPU, memory, IO, etc?
The diagram below illustrates helpful tools in a Linux system.
🔹‘vmstat’ - reports information about processes, memory, paging, block IO, traps, and CPU activity.
I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions
We all know vulnerabilities exist. This isn't an injection, XSS, or RCE.
But the crazy thing about it?
It took 2 hours to discover. 🤯
Here's the story of #AutoWarp👇 (1/10)
Are you available for #BlackHatEurope in London next week and eager to attend @BitK_ Arsenal session?
We have 2 tickets to give away. To win one: follow us, retweet this before 05/11, 4pm CET, and cross your fingers 🤞
#YesWeRHackers#SharingIsCaring
https://t.co/uVEh5igiiP
Nos experts #cyber@podalirius_ et @_nwodtuhs vous proposent aujourd’hui un nouvel outil #pentest qui a pour objectif d’extraire les mots de passes stockés dans les préférences de stratégie de groupe (#GPP) sous #Windows.
+ d’informations ⬇️ https://t.co/BNf4FRNbWp
My colleague @seanyeoh wrote up his security research on H2C smuggling and the various cloud providers he successfully exploited (Cloudflare, Azure). He also released a tool called h2csmuggler! Check it out at https://t.co/C4QTDcI7JH
I released v0.1 of Hetty tonight! 🐣 Building an open source alternative to Burp Suite Pro. I’d love to know what features infosec peeps use the most. @InsiderPhD @AlMadjus @ngalongc@_tomsteele@TomNomNom can you recommend some maybe? https://t.co/sHmQC1aAfx
This release also fixes a bypass if somebody does DOMPurify.sanitize(html).toLowerCase(). Check this example: https://t.co/xLJA8SGvne
Hint: in blocKquote - K = U+212A (KELVIN SIGN) which is lowercased to ASCII "k".