g3n3r4l6
-
Scraping By: My YouTube Data Adventure (nv1t.github.io)
Exploring insights and lessons from a detailed journey into YouTube data scraping.
-
Announcing CodeQL Community Packs (github.blog)
A deep dive into the new CodeQL Community Packs and their implications for vulnerability research.
-
Portspoof: Fighting Back Scanners (drk1wi.github.io)
new approach to thwart port and service scanners with Portspoof.
-
Breaking Popular WAFs: Project NZT-48 (nzt-48.org)
An investigation into bypassing the most common Web Application Firewalls.
-
Databricks JDBC Attack via JAAS (blog.pyn3rd.com)
Analyzing the methods and impacts of a Databricks JDBC attack leveraging JAAS.
-
Polyglot Files: HTML/ZIP/PNG (gildas-lormeau.github.io)
Learn how to create polyglot files combining HTML, ZIP, and PNG formats. Explore Here
X3
-
Kevin Mitnick's Remote Attack (1994) (@todayininfosec)
Did Kevin Mitnick actually execute a remote attack using address spoofing and TCP sequence prediction?
-
First SQL Injection Demonstration (1998) (@todayininfosec)
Learn how rain.forest.puppy revealed the first SQL injection vulnerability in Phrack issue 54.
-
RCE Attempts Targeting TP-Link Routers (@sicehice)
A report on Mirai botnet attacks exploiting TP-Link Archer routers (CVE-2023-1389).
y0utube1
-
The Pager Plot; The Iron River; Joy to the World (youtube.com)
A comprehensive episode featuring riveting stories, including security-related narratives. Watch Here
g1thub2
-
RCE via Prompt Injection (github.com)
How a terminal prompt injection vulnerability opens doors for RCE in Cursor.
-
Tomcat CVE-2024-50379 PoC (github.com)
A proof of concept for RCE via a race condition in Apache Tomcat. Explore Here