g3n3r4l16
-
Backdooring AMIs for Fun and Profit (blog.appsecco.com)
Ratnakar Singh explores the potential and pitfalls of backdooring Amazon Machine Images.
-
WIFI Credential Dumping (r-tec.net)
Techniques to retrieve the Pre-Shared Key (PSK) from a compromised workstation.
-
HTTP/2 CONTINUATION Flood (nowotarski.info)
Technical details of the HTTP/2 CONTINUATION flood attack.
-
The XZ Utils Backdoor (CVE-2024-3094) (securitylabs.datadoghq.com)
Everything you need to know about the XZ Utils backdoor.
-
DJI Mavic 3 Drone Firmware Analysis (nozominetworks.com)
A deep dive into the firmware of the DJI Mavic 3 drone.
-
Exploiting Empire C2 Framework (aceresponder.com)
Insights into vulnerabilities within the Empire Command and Control framework.
-
The V8 Sandbox (v8.dev)
A look into the sandboxing mechanism of the V8 JavaScript engine.
-
Panning For Gold: Sifting Through Network Logs (labs.greynoise.io)
Techniques for analyzing network logs for security insights.
-
Azure Redirect URI Takeover Vulnerability (secureworks.com)
Exploring a vulnerability in Azure's redirect URI handling.
-
Securing Flutter Applications (8ksec.io)
Best practices for enhancing the security of Flutter applications.
-
10,000 Bugfixes in 10,000 Days (daniel.haxx.se)
Reflecting on the milestone of fixing 10,000 bugs.
-
10 > 64, in QR Codes (huonw.github.io)
Exploring encoding efficiency in QR codes.
-
Fault Injection and the Supply Chain (oddsolutions.github.io)
Analyzing the impact of fault injection attacks on supply chain security.
-
Fine-tuning Semgrep for Ruby Security (blog.siddarthadukia.com)
Customizing Semgrep rules for Ruby security.
-
Security Research Without Ever Leaving GitHub (github.blog)
Leveraging GitHub for end-to-end security research.
-
The Dangers of AI Agents Unfurling Hyperlinks (embracethered.com)
Discussing the security risks of AI agents automatically unfurling hyperlinks.
g1thub5
-
xzbot (github.com)
Notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094). Explore on GitHub
-
endlessh-go (github.com)
A Golang implementation of endlessh exporting Prometheus metrics, visualized by a Grafana dashboard. Explore on GitHub
-
burp2caido (github.com)
A tool to migrate Burpsuite HTTP history to Caido. Explore on GitHub
-
apkd (github.com)
APK downloader from a few sources. Explore on GitHub
-
biotime-rce-8.5.5 (github.com)
Exploit covering several vulnerabilities in BioTime leading to Remote Code Execution or directory traversal. Explore on GitHub