Aggregator
CVE-2016-3116 | Dropbear SSH up to 2016.71 Shell Command Restriction crlf injection (ID 136251 / EDB-40119)
北京市第六届职业技能大赛电子数据取证分析师项目决赛考试成绩公示
CVE-2004-1854 | Picophone Internet Telephone up to 1.63 Logging memory corruption (EDB-23876 / XFDB-15595)
注意喚起: 2024年10月マイクロソフトセキュリティ更新プログラムに関する注意喚起 (公開)
真实·黑客说|GEEKCON 2024 上海站赛程议题公布
CVE-2020-2038 | Palo Alto PAN-OS up to 9.0.9/9.1.3/10.0.0 Management Interface os command injection (EDB-51005)
国际 | “深度伪造”肆虐 韩国立法应对
观点 | 如何加强对算法的治理
关注 | 国际电信联盟发布《全球网络安全指数2024年版》报告 呼吁合力应对全球网络安全挑战
前沿 | 标识解析在油气储运行业“工业互联网+安全生产”中的应用
行业 | 安胜华信获第九届“创客中国”网络安全中小企业创新创业大赛一等奖
全球视野 | 国际网安快讯(第31期)
LayeredSyscall – Abusing Vectored Exception Handling to Bypass EDRs
LayeredSyscall Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows. The general idea is to generate a legitimate call stack before...
The post LayeredSyscall – Abusing Vectored Exception Handling to Bypass EDRs appeared first on Penetration Testing Tools.
倒计时9天!2024补天白帽大会全议程发布!
Remote Method Guesser: Java RMI enumeration and bruteforce of remote methods
Remote Method Guesser Remote Method Guesser (rmg) is a command-line utility written in Java and can be used to identify security vulnerabilities on Java RMI endpoints. Currently, the following operations are supported: List available bound names and their...
The post Remote Method Guesser: Java RMI enumeration and bruteforce of remote methods appeared first on Penetration Testing Tools.
高通修复已遭利用的高危0day漏洞
Apache Avro SDK 中存在严重漏洞,可导致在 Java 应用中实现RCE
HybridTestFramewrok: End to End automation testing of Web, API and Security
HybridTestFramewrok In the era of the cloud-native world, we cannot stick to a particular framework, however, due to project requirements we often need to evolve the existing testing solution in such a way that...
The post HybridTestFramewrok: End to End automation testing of Web, API and Security appeared first on Penetration Testing Tools.