Aggregator
iOS和macOS系统曝关键漏洞,可破坏TCC框架
CVE-2022-2552 | Duplicator Plugin 0.5.10/1.1.3/1.2.32/1.3.0/1.4.7 on WordPress information disclosure (EDB-50993)
OpenAI发布12月11日ChatGPT宕机报告:集群出现死循环把工程师挡在门外
原创漏洞-西门子博途19全局配置文件反序列化漏洞分析
原创漏洞-西门子博途19全局配置文件反序列化漏洞分析
CVE-2019-11269 | Oracle Banking Virtual Account Management 14.1.0/14.3.0/14.4.0 Common Core redirect (EDB-47000)
How to make my IP cameras vulnerable
CVE-2004-0685 | Linux Kernel 2.4 USB Driver copy_to_user information disclosure (VU#981134 / Nessus ID 22609)
Apache Struts Arbitrary File Upload Vulnerability S2-067 (CVE-2024-53677)
Apache Struts Arbitrary File Upload Vulnerability S2-067 (CVE-2024-53677)
Overview Recently, NSFOCUS CERT monitored that Apache released a security bulletin, fixing the Apache Struts arbitrary file upload vulnerability S2-067 (CVE-2024-53677). Due to a logical defect in the file upload function, an unauthenticated attacker can perform path traversal by controlling the file upload parameters, thereby uploading malicious files to achieve remote code execution. The CVSS […]
The post Apache Struts Arbitrary File Upload Vulnerability S2-067 (CVE-2024-53677) appeared first on NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks..
The post Apache Struts Arbitrary File Upload Vulnerability S2-067 (CVE-2024-53677) appeared first on Security Boulevard.
messages on iphones
ISC Stormcast For Monday, December 16th, 2024 https://isc.sans.edu/podcastdetail/9256, (Mon, Dec 16th)
I made a Wireshark dissector for the Suitelink protocol used in industrial automation
谷歌Chrome已在F12控制台为开发者提供AI功能 可以快速调试代码
Cable: .NET post-exploitation toolkit for Active Directory reconnaissance and exploitation
Cable Cable is a simple post-exploitation tool used for enumeration and further exploitation of Active Directory environments. This tool was primarily created to learn more about .NET offensive development in an Active Directory context,...
The post Cable: .NET post-exploitation toolkit for Active Directory reconnaissance and exploitation appeared first on Penetration Testing Tools.
BOAST: The BOAST Outpost for AppSec Testing
BOAST The BOAST Outpost for AppSec Testing BOAST is a server built to receive and report Out-of-Band Application Security Testing reactions. Some application security tests will only cause out-of-band reactions from the tested...
The post BOAST: The BOAST Outpost for AppSec Testing appeared first on Penetration Testing Tools.
Zeek Network Security Monitor: powerful network analysis framework
Zeek Network Security Monitor Zeek is a powerful framework for network analysis and security monitoring. It is a powerful system that on top of the functionality it provides out of the box, also offers...
The post Zeek Network Security Monitor: powerful network analysis framework appeared first on Penetration Testing Tools.