■■■□□ Autodiscover, a protocol used by Microsoft Exchange for automatic configuration of clients such as Microsoft Outlook, has a design flaw that causes the protocol to “leak” web requests to Autodiscover domains outside of the user’s domain but in the same TLD (i.e. Autodiscover.com). https://www.guardicore.com/labs/autodiscovering-the-great-leak/ https://t.me/cKure/9508
All posts by cK-bot
September 25, 2021 at 02:14PM
■■■□□ Supporting articles for (https://t.me/cKure/9506) https://machinehum.medium.com/im-putting-a-wifi-router-into-a-wall-charger-part-1-882df714bbf3 https://machinehum.medium.com/im-putting-a-wifi-router-into-a-wall-charger-part-2-bf04c779c905 https://machinehum.medium.com/im-not-putting-a-wifi-router-into-a-phone-charger-7b36e90ee08d https://t.me/cKure/9507
September 25, 2021 at 02:12PM
■■■■■ Tool: The WiFiWart is an open source WiFi penetration device masquerading as a regular wall charger. It features a 1.2Ghz Cortex A7 MPU with two WiFi chips onboard. The electrical, mechanical and software is all completely open source. The elec is design in Kicad, hardware in FreeCAD and software will be all GNU/Linux based.…
September 25, 2021 at 02:08PM
■□□□□ Data-Leak from Iran of apparent Traffic department is up for sale for 28K USD in BTC containing 24 M records. https://t.me/cKure/9504
September 25, 2021 at 02:05PM
■■■■■ VMware CVE-2021-22005 Technical & Impact analysis. https://censys.io/blog/vmware-cve-2021-22005-technical-impact-analysis/ https://t.me/cKure/9503
September 25, 2021 at 01:40PM
■■■■□ HCRootkit / Sutersu Linux Rootkit Analysis. https://www.lacework.com/blog/hcrootkit-sutersu-linux-rootkit-analysis/ https://t.me/cKure/9502
September 25, 2021 at 01:30PM
■■■■■ Disclosure of three 0-day iOS vulnerabilities and critique of Apple Security Bounty program. Tweets by illusionofcha0s https://habr.com/en/amp/post/579714 https://t.me/cKure/9498
September 25, 2021 at 01:14PM
■□□□□ Data-Leak: European Union formally blames Russia for the GhostWriter operation. https://hackademicus.nl/european-union-formally-blames-russia-for-the-ghostwriter-operation/ https://t.me/cKure/9497
September 25, 2021 at 01:13PM
■■■■□ subcrawl: find, scan and analyze open directories. https://github.com/hpthreatresearch/subcrawl https://t.me/cKure/9496
September 25, 2021 at 12:29PM
■■■■■ Researchers compile list of vulnerabilities abused by ransomware groups. So, we are up to 42 vulnerabilities across 17 technologies (with 1 pending) that ransomware groups exploit for initial access. This is why preaching “just patch” isn’t good enough. I don’t know what the answer is, but what we’re doing clearly isn’t working. https://t.co/oYBRUwTWf3 —…
