Aggregator
CVE-2023-32007 | Apache Spark UI prior 3.4.0 command injection
CVE-2023-31039 | Apache bRPC up to 1.4.x ServerOptions::pid_file input validation
CVE-2023-31038 | Apache Log4cxx prior 1.1.0 ODBC Appender sql injection
CVE-2023-37203 | Mozilla Firefox up to 114 Drag/Drop API Remote Code Execution (Bug 291640)
CVE-2023-36189 | LangChain 0.0.64 SQLDatabaseChain sql injection (Issue 5923 / Replaces VDB-243107)
CVE-2023-38428 | Linux Kernel up to 6.3.3 ksmbd fs/ksmbd/smb2pdu.c UserName out-of-bounds
CVE-2023-38408 | OpenBSD OpenSSH up to 9.3p1 PKCS 11 unquoted search path (ID 173661)
CVE-2023-38408 | Oracle Communications Cloud Native Core Binding Support Function Install/Upgrade unquoted search path
CVE-2023-27530 | Rack Gem on Ruby Multipart MIME Parsing denial of service (Nessus ID 207797)
EchoStrike: Undetectable Reverse Shells with a Pythonic Twist
EchoStrike EchoStrike is a tool designed to generate undetectable reverse shells and perform process injection on Windows systems. Through an interactive wizard written in Python, users can customize their binaries with advanced persistence and encryption techniques. The malware code is written...
The post EchoStrike: Undetectable Reverse Shells with a Pythonic Twist appeared first on Penetration Testing Tools.
OWASP SecurityRAT: Tool for handling security requirements
OWASP SecurityRAT OWASP SecurityRAT (Requirement Automation Tool) is a tool supposed to assist with the problem of addressing security requirements during application development. The typical use case is: specify parameters of the software artifact you’re...
The post OWASP SecurityRAT: Tool for handling security requirements appeared first on Penetration Testing Tools.
Cloudsplaining: an AWS IAM Security Assessment tool
Cloudsplaining Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report. Cloudsplaining identifies violations of least privilege in AWS IAM policies and generates a...
The post Cloudsplaining: an AWS IAM Security Assessment tool appeared first on Penetration Testing Tools.
每日安全动态推送(10-15)
Sri Lankan Police Arrest Over 200 Chinese Scammers
Sri Lankan authorities have arrested more than 200 Chinese nationals who they say overstayed their visitor visas and engaged in large-scale financial scam operations targeting victims across Asia. The Chinese Embassy in Colombo says it supports the law enforcement crackdown.