Archive

Archive

1481 bookmarks
Custom sorting
Microsoft Build Engine Compromise - Part One
Microsoft Build Engine Compromise - Part One
Disclaimer: This blog represents my personal ideas and experiences and not my employer. tl;dr MSBuild.exe and all its parts are absolutely...
·subt0x11.blogspot.com·
Microsoft Build Engine Compromise - Part One
Malicious PowerPoint Documents Abusing Mouse Over Actions
Malicious PowerPoint Documents Abusing Mouse Over Actions
A new type of malicious MS Office document has appeared: a PowerPoint document that executes a PowerShell command by hovering over a link with the mouse cursor (this attack does not involve VBA macros…
·blog.nviso.be·
Malicious PowerPoint Documents Abusing Mouse Over Actions
New PHP Exploitation Technique Added
New PHP Exploitation Technique Added
Last week a new exploitation technique for PHP applications was announced at the BlackHat USA conference. Find out everything you need to know in this blog post.SummaryThe security researcher Sam Thom…
·blog.ripstech.com·
New PHP Exploitation Technique Added
Remote Code Execution on packagist.org
Remote Code Execution on packagist.org
tl;dr There was a remote code execution vulnerability on packagist.org, the default package server behind Composer, a PHP package manager. Packagist currentl...
·justi.cz·
Remote Code Execution on packagist.org
NES.css
NES.css
NES-style CSS Framework | ファミコン風CSSフレームワーク
·bcrikko.github.io·
NES.css
Атака на Github Pages с перехватом сайта на вашем домене
Атака на Github Pages с перехватом сайта на вашем домене
Большинство разработчиков знают и любят github pages. На случай, если вы не встречались с ними — этот сервис даёт возможность создать статический сайт из...
·habr.com·
Атака на Github Pages с перехватом сайта на вашем домене
New technique to find Blind-XSS
New technique to find Blind-XSS
Blind-XSS is a powerful attack, now i will talk about a technique i have used in Bug Bounty programs to find it..
·medium.com·
New technique to find Blind-XSS
An anti-sandbox/anti-reversing trick using the GetClipboardOwner API
An anti-sandbox/anti-reversing trick using the GetClipboardOwner API
This is a little nifty trick for detecting virtualization environments. At least, some of them. Anytime you restore the snapshot of your virtual machine your guest OS environment will usually run some…
·hexacorn.com·
An anti-sandbox/anti-reversing trick using the GetClipboardOwner API
s0md3v/AwesomeXSS
s0md3v/AwesomeXSS
Awesome XSS stuff. Contribute to s0md3v/AwesomeXSS development by creating an account on GitHub.
·github.com·
s0md3v/AwesomeXSS
Scaling up Binary Exploitation Education
Scaling up Binary Exploitation Education
The shortage of proficient cyber operators in a world now dependent on connectivity and information has left nations scrambling to build capabilities in a vo...
·blog.ret2.io·
Scaling up Binary Exploitation Education
Abusing Microsoft Office Online Video
Abusing Microsoft Office Online Video
Cymulate’s research team has discovered a way to abuse the Online Video feature on Microsoft Word to execute malicious code. Attackers could use this for malicious purposes such as phishing, as the do…
·blog.cymulate.com·
Abusing Microsoft Office Online Video