Hejto.pl
Dodaj post

Wpisz coś do wyszukania (minimum 2 znaki)

#informatyka

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.03.md

SharePoint ToolShell – One Request PreAuth RCE Chain - https://blog.viettelcybersecurity.com/sharepoint-toolshell/

The Havoc framework - https://lorenzomeacci.com/the-havoc-framework

Executive Offense - Building AI Hackbots, Part 1 - https://executiveoffense.beehiiv.com/p/ai-hackbots-part-1

Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer - https://qriousec.github.io/post/oob-angle/

Domain Fronting is Dead. Long Live Domain Fronting! - https://www.praetorian.com/blog/domain-fronting-is-dead-long-live-domain-fronting/

Koneser

w Dyskusje

13piorunów

Czy wkrótce zabraknie adresów IP? I co to dla ciebie znaczy?

Pełen artykuł przeczytasz po kliknięciu tutaj: :arrow_forward: Co się stanie kiedy zabraknie adresów IP? :arrow_backward: \ \ 25 listopada 2019 roku skończyły się wolne pule adresów IPv4 w Europie — ale internet pomimo tego jakoś nie eksplodował. Dlaczego? Bo inżynierowie sieci przez

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.10.01.md

The art of self mutating malware - https://0xf00sec.github.io/0x48

CrushFTP RCE Explained - https://pwn.guide/free/web/crushftp

Getting Started With Malware Development - https://www.crow.rip/nest/mal/dev/getting-started

Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening? - https://nac-l.github.io/2025/01/25/lifting_0.html

nRF51 RBPCONF bypass for firmware dumping - https://lessonsec.com/posts/nrf51-bypass/

Fenomen

w Hydepark

10piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.29.md

Turning Camera Surveillance on its Axis - https://claroty.com/team82/research/turning-camera-surveillance-on-its-axis

Quick-Skoping through Netskope SWG Tenants - CVE-2024-7401 - https://quickskope.com/

CPP / C++ Notes - Windows API Programming Win32 - https://caiorss.github.io/C-Cpp-Notes/WindowsAPI-cpp.html

Using Reflective Loaders to Replace LoadLibrary for Hot Swappable Modules in C++ - https://racoten.gitbook.io/red-team-developments-and-operations

More than you wanted to know about how Game Boy cartridges work - https://abc.decontextualize.com/more-than-you-wanted-to-know/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.27.md

[CVE-2025-41243] Spring Cloud Gateway: complicating evaluation context - https://blog.z3r.ru/posts/spring-cloud-gateway-spel-vuln/

How to Unpack Malware with x64dbg - https://www.varonis.com/blog/x64dbg-unpack-malware

Fixing A FakeNet/-NG PCAP - https://packetsmith.ca/tutorial-fakenet/

How We Accidentally Discovered a Remote Code Execution Vulnerability in ETQ Reliance - https://slcyber.io/assetnote-security-research-center/how-we-accidentally-discovered-a-remote-code-execution-vulnerability-in-etq-reliance/

Invision Community <= 5.0.7 (oauth/callback) Reflected Cross-Site Scripting Vulnerability - https://karmainsecurity.com/KIS-2025-05

Osobistość

w Hydepark

9piorunów

Dlaczego mi wcześniej nie zapaliła się lampka? Po przejęciu przez NetArt hostingu netmark wywalili ceny w kosmos. Za przedłużenie domeny .pl wołają 295 brutto! Nie wspominając już o cenie za hosting...
Czy ktoś ma do polecenia jakiś SPRAWDZONY hosting w normalnych pieniądzach?

Wymagania: 2 domeny (.pl i .eu), 3 subdomeny, MySQL, node.js + e-mail

Gruba ryba1piorunów

hosting domeny? ovh jest OK. I na pohybel netartowi.

Gruba ryba1piorunów

Hostido.

Mały histing, nie ma żadnych "bab" na infolinii tylko informatycy z prawdziwego zdarzenia, za free potrafią coś przekonfigurować jeśli nie ogarniesz. Działa i po ludzku, bez korpo chwytów.

Pokaż więcej komentarzy (14)

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.25.md

Silly EDR Bypasses and Where To Find Them - https://malwaretech.com/2023/12/silly-edr-bypasses-and-where-to-find-them.html

Direct Syscalls in Beacon Object Files - https://www.outflank.nl/blog/2020/12/26/direct-syscalls-in-beacon-object-files/

Inside Windows Sessions: A Deep Dive with Pavel - https://trainsec.net/library/windows-internals/inside-windows-sessions/

A Novel Technique for SQL Injection in PDO’s Prepared Statements - https://slcyber.io/assetnote-security-research-center/a-novel-technique-for-sql-injection-in-pdos-prepared-statements/

Creating a C2 infrastructure on AWS - https://lorenzomeacci.com/creating-a-c2-infrastructure-on-aws

GURU

w Historia

4piorunów

Abakus, pascalina i karty dziurkowane – początki cyfrowej rewolucji » Historykon.pl

Ludzkie pragnienie ułatwienia sobie obliczeń zaczęło się od prostych kamyków przesuwanych w rowkach, a doprowadziło do maszyn, które potrafiły liczyć szybciej niż człowiek mógł pomyśleć. Od abakusa po karty dziurkowane kryją się początki cyfrowej rewolucji, która odmieniła nie

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.23.md

Reversing for dummies - x86 assembly and C code (Beginner/ADHD friendly) - https://0x44.cc/reversing/2021/07/21/reversing-x86-and-c-code-for-beginners.html

Dissecting DCOM partie 1 - https://www.synacktiv.com/publications/dissecting-dcom-partie-1

Binder Fuzzing - https://androidoffsec.withgoogle.com/posts/binder-fuzzing/

HITCON CTF 2025 -- calc - https://bruce30262.github.io/hitcon-ctf-2025-calc/

Root Shell on Credit Card Terminal - https://stefan-gloor.ch/yomani-hack

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.21.md

When a Wi-Fi SSID Gives You Root on an MT02 Repeater - https://chocapikk.com/posts/2025/when-a-wifi-name-gives-you-root/

Hosting a WebSite on a Disposable Vape - https://bogdanthegeek.github.io/blog/projects/vapeserver/

Code auditing 101 - https://blog.rodolpheg.xyz/posts/code-auditing--101/

Mapping Hidden Alliances in Russian-Affiliated Ransomware - https://dti.domaintools.com/mapping-hidden-alliances-russian-affiliated-ransomware/

Extraction of Synology encrypted archives - Pwn2Own Ireland 2024 - https://www.synacktiv.com/en/publications/extraction-of-synology-encrypted-archives-pwn2own-ireland-2024

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.19.md

Copy-Paste Pitfalls: Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy - https://www.varonis.com/blog/applocker-bypass-risks

A Simple AD Problem - https://techbrandon.github.io/active%20directory/security/rant/2025/09/09/a-simple-ad-problem.html

Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass - https://www.welivesecurity.com/en/eset-research/introducing-hybridpetya-petya-notpetya-copycat-uefi-secure-boot-bypass/

Windows local privilege escalation through the bitpixie vulnerability - https://blog.syss.com/posts/bitpixie/

Qualcomm DSP Kernel Internals - https://streypaws.github.io/posts/DSP-Kernel-Internals/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.17.md

Automated Function ID Database Generation in Ghidra on Windows - https://blog.mantrainfosec.com/blog/17/automated-function-id-database-generation-in-ghidra-on-windows

Learning Lens Blur Fields - https://blur-fields.github.io/

Training Specialist Models: Automating Malware Development - https://www.outflank.nl/blog/2025/08/07/training-specialist-models/

CVE-2025-48384: Breaking Git with a carriage return and cloning RCE - https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384

Exploiting the Impossible: A Deep Dive into A Vulnerability Apple Deems Unexploitable - https://jhftss.github.io/Exploiting-the-Impossible/

Osobistość

w Technologia

22piorunów

No i ch.. im w ...
Po update systemu chrome wstał bez opcji włączenia uBlocka. Po wielu latach to chyba koniec mojej przygody z przeglądarką od googla.

Witaj Brave, zobaczymy czy razem wytrzymamy 😛

GURU6piorunów

Brave bazuje na Chrome'ie, więc to też jest kwestia czasu.
Ciekawe jak długo FireFox da radę na starym manifeście ciągnąć.

Osobistość1piorunów

@Fly_agaric właśnie tego też sie obawiam, ale jak na razie sprawnie się przeniosłem wiec mam nadzieje, ze ta zmiana bedzie dla mnie niezauwazalna

Autorytet4piorunów

Ja mam operę gej iks i narazie się nie obraziłem na nią

Pokaż więcej komentarzy (11)

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.15.md

Hiding In PlainSight - Proxying DLL Loads To Hide From ETWTI Stack Tracing - https://0xdarkvortex.dev/proxying-dll-loads-for-hiding-etwti-stack-tracing/
Under the Hood of AFD.sys Part 1: Investigating Undocumented Interfaces - https://leftarcode.com/posts/afd-reverse-engineering-part1/
BadPie: Bake it ‘Til You Fake It - https://dtm.uk/badpie/
Guest Post: How I Scanned all of GitHub’s “Oops Commits” for Leaked Secrets - https://trufflesecurity.com/blog/guest-post-how-i-scanned-all-of-github-s-oops-commits-for-leaked-secrets
A Fuzzy Escape - A tale of vulnerability research on hypervisors - https://bughunters.google.com/blog/5800341475819520/a-fuzzy-escape-a-tale-of-vulnerability-research-on-hypervisors

Fenomen

w Hydepark

7piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.13.md

Methods to Bypass OTP in Mobile Apps: Successful VAPT Scenarios - https://www.resecurity.com/blog/article/methods-to-bypass-otp-in-mobile-apps-successful-vapt-scenarios
Absurdity-I: Chrome’s Security Mechanisms - https://para0x0dise.github.io/absurdities/Absurdities-I/#absurdity-i-chromes-security-mechanisms
Understanding WdBoot (Windows Defender ELAM) - https://n4r1b.com/posts/2019/11/understanding-wdboot-windows-defender-elam/
CryptoJacking is dead: long live CryptoJacking - https://cside.dev/blog/cryptojacking-is-dead-long-live-cryptojacking
CVE-2025-52915: A BYOVD Evolution Story - https://blacksnufkin.github.io/posts/BYOVD-CVE-2025-52915/

Fenomen

w Hydepark

8piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.11.md

Stealthy Persistence With Non-Existent Executable File - https://www.zerosalarium.com/2025/09/Stealthy-Persistence-With-Non-Existent-Executable-File.html
KongTuke FileFix Leads to New Interlock RAT Variant - https://thedfirreport.com/2025/07/14/kongtuke-filefix-leads-to-new-interlock-rat-variant/
Reliable system call interception - https://blog.mggross.com/intercepting-syscalls/
CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM - https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/
An unexpected journey into Microsoft Defender's signature World - https://retooling.io/blog/an-unexpected-journey-into-microsoft-defenders-signature-world

Fenomen

w Hydepark

7piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.09.md

A Novel Technique for SQL Injection in PDO’s Prepared Statements - https://slcyber.io/assetnote-security-research-center/a-novel-technique-for-sql-injection-in-pdos-prepared-statements/
A Navajo weaving of an integrated circuit: the 555 timer - https://www.righto.com/2025/09/marilou-schultz-navajo-555-weaving.html
Ghosting the Sensor: Disrupting Defender for Identity Without Detection - https://cyberdom.blog/ghosting-the-sensor-disrupting-defender-for-identity-without-detection/
Exploiting Retbleed in the real world - https://bughunters.google.com/blog/6243730100977664/exploiting-retbleed-in-the-real-world
Hunting postMessage Vulnerabilities – Part 1 - https://blog.ryukudz.com/posts/postmessage-part-1/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.07.md

This overlooked Linux boot flaw defeats Secure Boot heres how to fix it https://nerds.xyz/2025/07/linux-initramfs-security-flaw-secure-boot-bypass/
A CT scanner reveals surprises inside the 386 processor's ceramic package  https://www.righto.com/2025/08/intel-386-package-ct-scan.html
Exploit development for IBM i https://blog.silentsignal.eu/2025/09/04/Exploit-development-for-IBM-i/
Death by a thousand slops https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/
Bypassing EDR to dump LSA secrets - Orange Cyberdefense https://www.orangecyberdefense.com/global/blog/cybersecurity/bypassing-edr-to-dump-lsa-secrets

Zawodowiec

w Programowanie

6piorunów

Najbardziej bezużyteczna funkcja Gita? Czym są git notes? - devszczepaniak.pl

Jakiś czas temu, analizując dokumentację Gita, natknąłem się na polecenie git notes. Myślałem, że znam Gita całkiem dobrze, ale to było dla mnie coś nowego. W najnowszym artykule wyjaśniam, czym są git notes i analizuję możliwości, jakie daje ta funkcja. Dowiesz się również jakie

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.09.05.md

Scanning for Post-Quantum Cryptographic Support - https://www.anvilsecure.com/blog/scanning-for-post-quantum-cryptographic-support.html
Hiding Linux Processes with Bind Mounts - https://righteousit.com/2024/07/24/hiding-linux-processes-with-bind-mounts/
SSD Advisory – Linux Kernel Pipapo Set Double Free LPE - https://ssd-disclosure.com/ssd-advisory-linux-kernel-pipapo-set-double-free-lpe/
Double Dash, Double Trouble: A Subtle SQL Injection Flaw - https://www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw/
Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit? - https://slavamoskvin.com/hunting-bugs-in-linux-kernel-with-kasan-how-to-use-it-whats-the-benefit/