The Hunt.io research team found an open directory staging the full toolkit behind an intrusion into a Philippine nuclear research agency and a naval contractor. The ownCloud path is the interesting part technically. CVE-2023-49105 lets you forge pre-signed WebDAV URLs when the signing secret is empty, which is the default state on a fresh install. Five custom Python scripts on the server implement this: the signing routine passes an empty bytes literal as the PBKDF2 salt, sets OC-Credential to the account being impersonated, and issues GET requests against /remote.php/dav/files/ /<patβ¦
submitted by /u/BluebirdDifficult260 [link] [comments]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also
submitted by /u/jfmengels [link] [comments]
submitted by /u/AncientSport3783 [link] [comments]
Follow-up to my post a couple of weeks ago about a 2.5 GB PCAP that took 6-7 hours to process. Streaming tshark's output into Go got it to 70 minutes, but it was still single-threaded. The most common response here was: why not just add goroutines? Turns out you can't, and the reason is that tshark's dissection is linear state. What it reads in one packet determines how it decodes the next β TCP reassembly, connection tracking, anything under tcp.analysis.* reads and updates shared conversation tables as it goes. Strict ordering isn't a design choice, it's what dissection requires. Goroutinβ¦
submitted by /u/vgsa [link] [comments]

submitted by /u/_Dark_Wing [link] [comments]

submitted by /u/IKeepItLayingAround [link] [comments]

submitted by /u/suhummygangles2 [link] [comments]

submitted by /u/rahmanism [link] [comments]
submitted by /u/Top_Dinner_9121 [link] [comments]
submitted by /u/AnimalStrange [link] [comments]
submitted by /u/TurbulentTopic39 [link] [comments]

submitted by /u/the_hypotenuse [link] [comments]
I built Masker after needing to share financial PDFs with a tax strategist without also sharing names, addresses, tax IDs, phone numbers, and account numbers. It is a native macOS app. It finds repeated PII, uses Appleβs on-device OCR for scanned pages, and lets you review every mask before export. Institution names and amounts can remain visible while account identifiers are covered. Mask sets and labels can be reused across folders. Everything runs locally. The tests generate fake PDFs, export them, and use text extraction and OCR to check that the selected values are gone. Built with Swiβ¦
submitted by /u/ControlCAD [link] [comments]

I was handed a cryptohack badge kit from the Cryptocurrency Village, but I think I needed go to another area of the conference to collect the rest of the parts of the kit. I want to try and assemble it and use it. Specifically, I'm missing the screen and the antenna Does anyone know the part numbers for the screen and antenna used on the cryptohack badge? Here is a picture of what I'm talking about... the cryptohack badge without the screen or antenna. submitted by /u/redud [link] [comments]

I dont know which of yall runs BlanketfortCon but I feel like you need to see this. https://www.reddit.com/r/3Dprinting/s/gcyktEfZYj submitted by /u/Nyrlath [link] [comments]
#defcon #reddit #hacking #blankfortcon #3dprinting #blanketfortcon #comments #dont
submitted by /u/abrownn [link] [comments]

submitted by /u/SnoozeDoggyDog [link] [comments]

submitted by /u/ControlCAD [link] [comments]

submitted by /u/serene_sketch [link] [comments]

