@lastknight@lastknight@cgiustozzi avevano quindi abilitato il copy-on-write? (Funzionalità presente in alcuni filesystem e non abilitata di default es. btrfs e zfs che permette di preservare i dati originali)
After 23 years of looking at security vulnerabilities, hacking into things and trying to characterize adversaries, I am more and more convinced that the real difference between professional security experts and amateurs is the ability to properly model and assess threats.
Brilliant research by @samykamkar! Wondering about Client Side Defense? *Behave!* extension warns the user about the malicious scan when slipstream tries to access private IPs. ;) https://t.co/4slntsgI9o
Here's a browser extension, called "Behave!" that monitors and warns users if a web-page performs any following actions:
✅ Browser-based Port Scan
✅ Access Private IPs
✅ DNS Rebinding attacks to Private IPs
https://t.co/IsMBGeC748
#infosec#chrome#firefox#cybersecurity
@pdp Many Vulnerability amplification issues are a blend of internal administrive issues combined with publicly exploitable vuln. Such as second order Xss, Rce on the administrative panel for example
yo dawg we heard u like bugs so we put an error in ur error reporting so u can crash while u crash!
But seriously... what if by crashing an application using a non-security bug, you can exploit a real vulnerability in Windows Error Reporting?
🧐Quando ti arriva un muletto di ottima @EstrellaDammEs può voler dire soltanto una cosa...
Che il #databeers è alle porte! 🙌🎉
Ci vediamo domani sera per 4⃣ fantastiche storie di dati e tanta birra!!!
📅 29 Novembre 18:30
🌍@Uqido
🍻@EstrellaDammEs
Grazie ai nostri sponsor!
AWS on the track for mitigating SSRFs impact against EC2 instances. Due to their architecture design exposure to SSRFs (usually low risk) has been unusually high. Time to fix that, without opt-in
At #POC2019, Xpl017Elz will give the second round of “New Reliable Android Kernel Root Exploitation”(first round at POC2016). He will talk about bypassing attack against KASLR, PXN, RKP, JOPP, EPV, etc. If you are interested in making a fullchain in Android, come to #POC2019.