Aggregator
Patch Tuesday, December 2024 Edition
Anton’s Security Blog Quarterly Q4 2024
Binary pointer alias analysis — beating CodeQL’s taint analysis without even having source code
Silver SAML Forger: Implement the Silver SAML attack
Silver SAML Forger Silver SAML Forger is C# tool that helps you create custom SAML responses. It can be used to implement the Silver SAML attack. Defend against Silver SAML To safeguard effectively against...
The post Silver SAML Forger: Implement the Silver SAML attack appeared first on Penetration Testing Tools.
3AM ransomware: what you need to know
French internet operator fined $53 million for unsolicited ads and tracking users without consent
直击黄牛抢票、滥用SEO乱象,DataCon竞赛探索网络黑产治理新思路
S3Scanner: Scan for open S3 buckets and dump
S3Scanner A tool to find open S3 buckets in AWS or other cloud providers: AWS DigitalOcean DreamHost GCP Linode Custom The tool takes in a list of bucket names to check. Found S3 buckets...
The post S3Scanner: Scan for open S3 buckets and dump appeared first on Penetration Testing Tools.
CVE-2024-45475 | Siemens Tecnomatix Plant Simulation V2404 prior 2302.0016 WRL File memory corruption (ssa-583523)
CVE-2024-45476 | Siemens Tecnomatix Plant Simulation V2404 prior 2302.0016 WRL File null pointer dereference (ssa-583523)
CVE-2024-47046 | Siemens Simcenter Nastran 2406 BDF File memory corruption (ssa-852501)
CVE-2024-10968 | 1000 Projects Bookstore Management System 1.0 /contact_process.php fnm sql injection
CVE-2024-10969 | 1000 Projects Bookstore Management System 1.0 Login /admin/login_process.php unm sql injection
CVE-2024-11138 | DedeCMS 5.7.116 friendlink_add.php logoimg unrestricted upload
CVE-2024-11250 | code-projects Inventory Management up to 1.0 /model/editProduct.php id sql injection
CVE-2024-22122 | Zabbix Server up to 5.0.42/6.0.30/6.4.15/7.0.0rc2 SMS Notification Number command injection (Nessus ID 208100)
CVE-2024-43882 | Linux Kernel up to 6.10.5 Group Member do_filp_open race condition (Nessus ID 207884)
Knock: enumerate subdomains on a target domain
Knock Knock is a Python tool designed to enumerate subdomains on a target domain through a wordlist. It is designed to scan for DNS zone transfer and to try to bypass the wildcard DNS...
The post Knock: enumerate subdomains on a target domain appeared first on Penetration Testing Tools.