Repo sensacional explicando como detectar cada tipo de Web Application Firewall e técnicas de evasão:
https://github.com/0xInfection/Awesome-WAF
https://github.com/0xInfection/Awesome-WAF
GitHub
GitHub - 0xInfection/Awesome-WAF: Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥 - 0xInfection/Awesome-WAF
fica pior quando vc lê o contexto
https://boletimsec.com.br/falha-no-ministerio-da-economia-expoe-dados-de-20-mil-brasileiros/
https://boletimsec.com.br/falha-no-ministerio-da-economia-expoe-dados-de-20-mil-brasileiros/
BoletimSec
Falha no Ministério da Economia expõe dados de 20 mil brasileiros - BoletimSec
A vulnerabilidade foi apontada em um relatório divulgado na última quinta-feira (16). Segundo a análise, o servidor de 55 GB estava exposto há pelo menos dois meses. De acordo com a chefe da equipe de pesquisa avançada de ameaças persistentes da empresa Group…
"Such data leaks are fairly common, according to Michael Gazeley, managing director at Hong Kong-based security firm Network Box."
Well, well, well...
https://indianexpress.com/article/world/alleged-chinese-police-database-hack-leaks-data-of-1-billion-8011433/
Well, well, well...
https://indianexpress.com/article/world/alleged-chinese-police-database-hack-leaks-data-of-1-billion-8011433/
The Indian Express
Alleged Chinese police database hack leaks data of 1 billion
Hackers claim to have obtained a trove of data on 1 billion Chinese from a Shanghai police database in a leak that, if confirmed, could be one of the largest data breaches in history
fckn good article on powershell obfuscation
https://www.offensive-security.com/offsec/powershell-obfuscation/
https://www.offensive-security.com/offsec/powershell-obfuscation/
OffSec
PowerShell Obfuscation | OffSec
Community moderator Tristram (gh0x0st) shares with us an approach to scripting payload obfuscation via PowerShell in order to avoid AV and AMSI detection.
Forwarded from 0lab channel ™
#Red_Team_Tactics
1. Scraping Login Credentials With XSS
https://www.trustedsec.com/blog/scraping-login-credentials-with-xss
2. UAC bypass, Elevate, Persistence methods
https://github.com/rootm0s/WinPwnage
1. Scraping Login Credentials With XSS
https://www.trustedsec.com/blog/scraping-login-credentials-with-xss
2. UAC bypass, Elevate, Persistence methods
https://github.com/rootm0s/WinPwnage
TrustedSec
Scraping Login Credentials With XSS
We'll use a reflected XSS vulnerability to frame the application login page in the IFrame trap, scrape the credentials from the login form as the victim…
Forwarded from 0lab channel ™
#hardening
1. Blocking ISO mounting
https://malicious.link/post/2022/blocking-iso-mounting
2. Windows 11 x64 Security Hardening Guide
https://github.com/beerisgood/Windows11_Hardening
3. Exploit Protection Settings
https://github.com/jdgregson/Exploit-Protection-Settings
Share and support us <3
1. Blocking ISO mounting
https://malicious.link/post/2022/blocking-iso-mounting
2. Windows 11 x64 Security Hardening Guide
https://github.com/beerisgood/Windows11_Hardening
3. Exploit Protection Settings
https://github.com/jdgregson/Exploit-Protection-Settings
Share and support us <3
My cool site
Blocking ISO mounting
Update: 10/15/2022
One of the hard parts of implementing a block like this is the concern that it will “break something”. The DFIR Report’s post on Bumblebee Round 2 has a great suggestion on how to detect legitimate (and illegitimate) use of ISO mounting…
One of the hard parts of implementing a block like this is the concern that it will “break something”. The DFIR Report’s post on Bumblebee Round 2 has a great suggestion on how to detect legitimate (and illegitimate) use of ISO mounting…
Verifica utilizando métodos usados em malwares se a máquina em questão é uma VM
https://github.com/a0rtega/pafish
Script para ofuscar detecção de VM no VirtualBox
https://github.com/d4rksystem/VBoxCloak
https://github.com/a0rtega/pafish
Script para ofuscar detecção de VM no VirtualBox
https://github.com/d4rksystem/VBoxCloak
GitHub
GitHub - a0rtega/pafish: Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis…
Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do - a0rtega/pafish