Rosecurify

Seclog - #14

Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation – Youssef Sammouda

Account takeover of Facebook/Oculus accounts due to First-Party access_token stealing – Youssef Sammouda

DOM-XSS in Instant Games due to improper verification of supplied URLs – Youssef Sammouda

How I Hacked my Car Part 3: Making Software :: Programming With Style

Secure Software Development Lifecycle Basics -

HTTP Header Security -

Security Advisory: Remote Command Execution in binwalk - ONEKEY

Unserializable, but unreachable: Remote code execution on vBulletin

Prototype Pollution vulnerability found in mastodon

Learning eBPF exploitation

Jira Service Management Server and Data Center Advisory (CVE-2023-22501) | Atlassian Support | Atlassian Documentation

Exploiting Hardcoded Keys to achieve RCE in Yellowfin BI – Assetnote

Google Online Security Blog: Taking the next step: OSS-Fuzz in 2023

A Hacker’s Mind News - Schneier on Security

how to completely own an airline in 3 easy steps

Phishing with GitHub

What happened to CVE-2022-23529? And what can we learn from it?

Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails – Assetnote

The Good, Bad and Compromisable Aspects of Linux eBPF - Pentera

(Web-)Insecurity Blog | SSO Gadgets: Escalate (Self-)XSS to ATO

secvuln #

VMware Workstation update addresses an arbitrary file deletion vulnerability (CVE-2023-20854)

Jira Service Management Server and Data Center Advisory (CVE-2023-22501)

sectool #

Curio: Documentation

Ronin 2.0.0 finally released!

secvideo #

DEF CON 29 - Guillaume Fournier, Sylvain Afchain, Sylvain Baubeau - eBPF, I thought we were friends!

secgit #

A-poc/RedTeam-Tools: Tools and Techniques for Red Team / Penetration Testing

GhostManager/Ghostwriter: The SpecterOps project management and reporting engine

ThePorgs/Exegol: Fully featured and community-driven hacking environment

bmarsh9/gapps: Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, SSF tracking (and soon other frameworks)

adityatelange/bhhb: Tool to view HTTP history exported from Burp Suite Community Edition

duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC: CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator

Esonhugh/sshd_backdoor: /root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.


Suggestions & Feedback

Enjoyed this post? Subscribe to Seclog for more in-depth security analysis and updates.

For any suggestions or feedback, please contact us at: [email protected]

Subscribe to Seclog

Enjoyed this post? Subscribe for more in-depth security analysis and updates direct to your inbox.

No spam. Only high-security insights. Unsubscribe at any time.

Share this Seclog:

← Back to Seclog