Aggregator
ISC Stormcast For Monday, August 26th, 2024 https://isc.sans.edu/podcastdetail/9112, (Mon, Aug 26th)
4 months 3 weeks ago
French Police Arrest Telegram CEO and Owner
4 months 3 weeks ago
Pavel Durov Reportedly Detained For Complicity Over Criminal Use
French media reported Saturday the detention outside Paris of Pavel Durov, CEO and owner of social media network Telegram, reportedly for failing to take steps to curb criminal activity on the platform. The Russian Embassy in France said it has demanded an explanation from the French government.
French media reported Saturday the detention outside Paris of Pavel Durov, CEO and owner of social media network Telegram, reportedly for failing to take steps to curb criminal activity on the platform. The Russian Embassy in France said it has demanded an explanation from the French government.
ADSpider: monitor Active Directory changes in real time
4 months 3 weeks ago
ADSpider Tool for monitoring Active Directory changes in real-time without getting all objects. Instead, it uses replication metadata and Update Sequence Number (USN) to filter the current properties of objects. How to use git...
The post ADSpider: monitor Active Directory changes in real time appeared first on Penetration Testing Tools.
ddos
创始人被捕后Telegram称遵守欧盟法律 但平台和所有者不应对滥用行为负责
4 months 3 weeks ago
CVE-2024-8152 | SourceCodester QR Code Bookmark System 1.0 Parameter add-bookmark.php name/url cross site scripting
4 months 3 weeks ago
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argument name/url leads to cross site scripting.
This vulnerability was named CVE-2024-8152. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8153 | SourceCodester QR Code Bookmark System 1.0 delete-bookmark.php bookmark cross site scripting
4 months 3 weeks ago
A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site scripting.
The identification of this vulnerability is CVE-2024-8153. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-8154 | SourceCodester QR Code Bookmark System 1.0 Parameter update-bookmark.php tbl_bookmark_id/name/url cross site scripting
4 months 3 weeks ago
A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_bookmark_id/name/url leads to cross site scripting.
This vulnerability is traded as CVE-2024-8154. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
WinObjEx64: Windows Object Explorer 64-bit
4 months 3 weeks ago
WinObjEx64 WinObjEx64 is an advanced utility that lets you explore the Windows Object Manager namespace. For certain object types, you can double-click on it or use the “Properties…” toolbar button to get more information,...
The post WinObjEx64: Windows Object Explorer 64-bit appeared first on Penetration Testing Tools.
ddos
一体化vs.模块化,谁才是SOC的未来?
4 months 3 weeks ago
目前还没有一个平台能满足 SOC 所有技术要求
CVE-2016-3720 | Data Format Extension on Jackson XmlMapper xml external entity reference (ID 199 / Nessus ID 91057)
4 months 3 weeks ago
A vulnerability was found in Data Format Extension on Jackson. It has been classified as very critical. This affects an unknown part of the component XmlMapper. The manipulation leads to xml external entity reference.
This vulnerability is uniquely identified as CVE-2016-3720. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-5254 | Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0 Apache ActiveMQ input validation (Nessus ID 87410 / ID 11889)
4 months 3 weeks ago
A vulnerability was found in Oracle BI Publisher 11.1.1.7.0/12.2.1.1.0/12.2.1.2.0. It has been rated as very critical. Affected by this issue is some unknown functionality of the component Apache ActiveMQ. The manipulation leads to improper input validation.
This vulnerability is handled as CVE-2015-5254. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2007-1375 | PHP 5.2.1 substr_compare length integer coercion (EDB-3424 / Nessus ID 26107)
4 months 3 weeks ago
A vulnerability has been found in PHP 5.2.1 and classified as critical. Affected by this vulnerability is the function substr_compare. The manipulation of the argument length leads to integer coercion error.
This vulnerability is known as CVE-2007-1375. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2010-3468 | Blueriver Sava CMS up to 5.2 fileManager.cfc FILEID path traversal (EDB-15120 / Nessus ID 49700)
4 months 3 weeks ago
A vulnerability classified as problematic has been found in Blueriver Sava CMS up to 5.2. Affected is an unknown function of the file fileManager.cfc. The manipulation of the argument FILEID leads to path traversal.
This vulnerability is traded as CVE-2010-3468. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2015-5254 | Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0 Apache ActiveMQ input validation (Nessus ID 90071 / ID 11889)
4 months 3 weeks ago
A vulnerability classified as very critical has been found in Oracle Enterprise Repository 11.1.1.7.0/12.1.3.0.0. Affected is an unknown function of the component Apache ActiveMQ. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2015-5254. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
【电子数据取证之隐私密码】
4 months 3 weeks ago
【他是破案“魔术师”!】
4 months 3 weeks ago
组建了一支专业教官团队,带出了一批优秀的年轻教官... ...
Operation DevilTiger:APT-Q-12 使用 0day 漏洞技战术披露
4 months 3 weeks ago
攻击者在使用漏洞攻击前往往会进行非常复杂的信息收集,APT-Q-12使用多套复杂的邮件探针,周期性的向目标投递探针邮件以此来收集受害者的使用习惯和行为逻辑,包括常用的邮件平台、品牌,在针对不同office产品又会进行区别处理。
派早报:专家回应网号、网证热点问题
4 months 3 weeks ago
你可能错过的新鲜事专家回应网号、网证热点问题据新华社报道,近期,公安部、国家网信办等研究起草《国家网络身份认证公共服务管理办法(征求意见稿)》,向社会公开征求意见,引发广泛关注。新华社记者梳理当前
BlackSuit Ransomware
4 months 3 weeks ago
Key TakeawaysIn December 2023, we observed an intrusion that started with the execution of a Cob