Rare are the pentesters who have never come across an up-to-date CMS installation during a 3 days audit, wondering what to do next. We are starting a blogpost series covering CMSs and web frameworks internals, with two articles by @_bluesheet
https://t.co/j8stWNWfiy
Here is a first draft on an NTLM relay mindmap 🙂 from authentication coercion to post-relay exploitation. I'll gladly update/correct it if you think there are things wrong or missing.
➡️Featured on The Hacker Recipes https://t.co/0y4cOkMcTb
🚨🚨METTEZ À JOUR VOS APPAREILS APPLE ! !! !!!
CitizenLab a trouvé un exploit sur #Apple qui est utilisé et qui pourrait mener à une surveillance totale de votre téléphone, vous voir, vous entendre, vous espionner...
Cet exploit inquiète car il ne nécessite aucun clic de l'utilisateur... aucune interaction ; c'est ce que l'on appelle les zero-clic attack !
L'attaquant n'aura besoin que de vous envoyer un son - cadeau 🎁 - via iMessage.
#NSO #NSOGroup #Pegasus #CitizenLab
🚩Bravo aux participants du CTF de @_barbhack_ !
Pour ceux qui le souhaitent, voici les sources et les writeups (en mode torchon) de mes 4 challs web :
https://t.co/gsjXwTZYfZ
GG à la team Orga pour l'énorme boulot sur l'infra 👏
A très bientôt pour d'autres challs 🤟 !
14 credential stuffing nuclei templates for both cloud and self-hosted services!
Including login checks for:
🔥 Datadog
🚀 Postman
🔥 Grafana
🚀 Jira
🔥 Github
And many more! You can find them all here 👇
🔗 https://t.co/wkt5J2ww1V
[NEW-RELEASE]
Nuclei Template Editor - AI-powered hub to create, debug, scan, and store templates. Collaborate effortlessly with your team and community.
Public signup is open; we're eager to hear your feedback on this early release.
- Editor: https://t.co/CdYNwij0rD
- Docs: https://t.co/NcXnOpSirP
#Hackwithautomation #AI #CyberSecurity
[Astuce d'été] https://t.co/A9ZW7Anj9S recommande le service https://t.co/Iy7ldj0sPc qui permet d'ajouter un #filigrane sur vos documents officiels afin d'éviter qu'ils ne puissent être réutilisés facilement à votre insu (ie. #usurpation d'#identité).
https://t.co/oXnfs522se
🥁 This time we present SQLovin, a new DOJO challenge that will put your SQL injection skills to the test!
Top 3 reports win exclusive some swags! 🎁
Submit your solution before 01/09/2023 🗓️
Check it out here 👉 https://t.co/9LWdDgMVVX
#YesWeRHackers#BugBounty
One week remaining until Smashing the state machine: the true potential of web race conditions! Can't wait to see what happens once the community gets their hands on the novel techniques, tooling & labs!
https://t.co/2wedm47tEt
Just pushed a pretty neat update for ShadowClone. In my testing, this change makes it about 25-40% faster that before! Check it out https://t.co/ojNAm0Ku2X
🛠️Continuing our tool-release series, we're excited to introduce 'cdncheck' to the Library!
This utility identifies technology for given IPs and uncovers hosts behind WAFs like Cloudflare. Perfect for enhancing our 'Find a server's origin IP' workflow!
https://t.co/uwMfzmSprF