g3n3r4l20
-
Read More (speakerdeck.com)
-
SMTP Smuggling - Spoofing E-Mails Worldwide (sec-consult.com)
Exploring the advanced techniques of email spoofing and SMTP smuggling.
-
Weaponizing DHCP DNS Spoofing — A Hands-On Guide (akamai.com)
A practical exploration of DHCP DNS spoofing vulnerabilities and their exploitation.
-
Impersonating JA3 Fingerprints (medium.com)
Techniques and consequences of impersonating JA3 fingerprints in cybersecurity.
-
Aerospace Security: Hacking The Skies (read.martiandefense.llc)
Unveiling the security threats and challenges in the aerospace industry.
-
An AWS IAM Identity Center Vulnerability (awsteele.com)
Deep dive into a significant vulnerability within AWS IAM Identity Center.
-
An In-depth Analysis of Arbitrary Address Spoofing Attacks (slowmist.medium.com)
Comprehensive analysis of arbitrary address spoofing and its impact on network security.
-
Exploring chained vulnerabilities leading to remote code execution in Outlook.
-
The Anatomy of a Block Stuffing Attack (medium.com)
Detailed examination of block stuffing attacks in cybersecurity.
-
Terrapin Attack (terrapin-attack.com)
Insight into the Terrapin cyber attack and its methodologies.
-
Summer Interns 2023 Recap (blog.trailofbits.com)
Insights and experiences from the summer interns at Trail of Bits in 2023.
-
Securing the Web PKI - Freedom to Tinker (freedom-to-tinker.com)
Addressing the challenges and solutions in securing the web's Public Key Infrastructure.
-
PETEP (PEnetration TEsting Proxy) (petep.warxim.com)
An overview of PETEP, a tool designed for penetration testing.
-
Rust Foundation - Improving Supply Chain Security for Rust Through Artifact Signing (foundation.rust-lang.org)
Enhancing Rust's supply chain security through artifact signing initiatives.
-
SSH ProxyCommand == RCE (vin01.github.io)
Analysis of a remote code execution vulnerability in SSH's ProxyCommand.
-
Data Exfiltration from (promptarmor.substack.com)
Writer.com with Indirect Prompt Injection Investigating data exfiltration from Writer.com through indirect prompt injection.
-
Detailed analysis of attacking and defending JetBrains Teamcity, focusing on CVE-2023-42793.
-
Securitum - securitum-protonmail-security-audit (pentestreports.com)
A comprehensive security audit report of ProtonMail conducted by Securitum.
-
ZoneTransfer.me (digi.ninja)
Exploring the ZoneTransfer.me project and its significance in cybersecurity.
-
Full Chain Baseband Exploits, Part 1 (labs.taszk.io)
A deep dive into the world of full-chain baseband exploits.
y0utube2
-
Insights into the security aspects of the Pixel modem. Watch Here
-
AI transcends physical boundaries in cybersecurity. Watch Here
g1thub8
-
ANG13T/skytrack (github.com)
A cybersecurity toolkit for various security tasks. Explore on GitHub
-
unknownhad/AWSAttacks (github.com)
Tools and strategies for attacking AWS services. Explore on GitHub
-
RUB-NDS/Terrapin-Scanner (github.com)
A scanner for detecting vulnerabilities in cybersecurity systems. Explore on GitHub
-
ivre/ivre (github.com)
An open-source network reconnaissance tool. Explore on GitHub
-
brandon-t-elliott/CVE-2023-49438 (github.com)
Analysis of the CVE-2023-49438 vulnerability. Explore on GitHub
-
som3canadian/Cloudflare-Redirector (github.com)
A tool for managing redirects in Cloudflare. Explore on GitHub
-
hannob/smtpsmug (github.com)
A project focused on SMTP smuggling research. Explore on GitHub
-
Linux virtual machines optimized for containerized environments. Explore on GitHub