@Burp_Suite Another vote for logger++. Very useful for tracking the behavior of an application when using scanner and other non-logged burp features (scanner mostly)
Version v3.2.0 of #OWASP Amass has been released!
The tool has been refactored quite a bit and the default settings run the enumerations much faster.
Use the '-max-dns-queries' flag if you wish to slow things down
#osint#recon#infosec#opensource#assetdiscovery#bugbounty
Please share this as widely as possible. Why should we have to police Amazon? This problem is ongoing since 2017. These counterfeits are shipped and sold by AMAZON, NOT A THIRD PARTY. This is not Marketplace.
🎉 Go 1.13 RC1 is released!
🏃♀️ Run it in dev. Run it in prod. File bugs.
🗒️ Release notes: https://t.co/JQdyovtWuH
⬇️ Download: https://t.co/nkFVZcK732
#golang
@Edu4rdSHL@owaspamass@TomNomNom@aboul3la Passive mode doesn't make any attempt to resolve the names to IPs and the majority of our users want only resolveable names
Pre-auth RCE on Fortinet and Pulse Secure (prior: Juniper) SSL VPN's by @orange_8361 and @mehqq_ - over 500k such VPN's on the internet. Heap overflow, arbitrary file read, plaintext passwords, magic backdoor, command injection...
Defcon slides:
https://t.co/jtBAPmC1Gh
As promised during our talk, we have released the user exploitation features for SharpGPOAbuse! @den_n1s@VillageRedTeam#DEFCON27
https://t.co/7tUtJibEBj
Thanks all for attending my #DEFCON talk! Humbling to see such a full room even on Sunday. Slides and demo videos are online at the media server.
Slides: https://t.co/TZVR6ndMIv
Demo vids: https://t.co/AqZ9Uw02hH
I’m suprised that CVE-2018-13382 (a trivial « backdoor » in Fortigate SSL VPN) didn’t get much attention, even after @orange_8361´s talks in Vegas... https://t.co/zlYZd5t3Wj