bytebutcher ретвитнул
bytebutcher
14 posts

bytebutcher ретвитнул

netfetch is a tool designed to scan Kubernetes namespaces for network policies and check whether a network policy targets your workloads
➜ github.com/deggja/netfetch
English
bytebutcher ретвитнул

A lot of people liked PayloadsAllTheThingsWeb, it is now out of beta and live on the main repository. Every changes will now be reflected in 5 minutes instead of a cron scheduled every 6 hours🥳
swisskyrepo.github.io/PayloadsAllThe…
English
bytebutcher ретвитнул
bytebutcher ретвитнул

The @offensive_con talk "How to Fuzz Your Way to Android Universal Root: Attacking Android Binder" from Google folks featured Pwndbg's functionalities to inspect kernel allocator and Android binder's state (github.com/pwndbg/pwndbg/…) :)
#pwndbg #offensivecon #pwning



English
bytebutcher ретвитнул

An (almost) full VM escape with a single bit clear. Wow
(Almost because ASLR & CFG bypass here is incompete so it can only pop calc without arbitrary code execution)
This piece of code in VirtualBox is well known and has been audited down and through, meaning that it took Cody a lot of hard manual work to find the bug. My HVR training alone has 2-3 exercises on this code, plus tons of stuff on device IO, VMMDevice, PDM, racing samples...
TrendAI Zero Day Initiative@thezdi
In a new guest blog, @cogallag describes the bug he used to exploit #Oracle #VirtualBox at #Pwn2Own Vancouver. He gives an in-depth analysis of how he used a race condition to win $20,000 at the contest. zerodayinitiative.com/blog/2024/5/9/…
English
bytebutcher ретвитнул


Tired of copying & pasting multiple shell scripts across servers? 😩
Meet bundler.sh - Bundle all your scripts into ONE with a simple CLI!
Get bundler.sh: github.com/bytebutcher/bu…
#Bash #Pentesting #Productivity
English
bytebutcher ретвитнул
bytebutcher ретвитнул

This article discusses Kubernetes security fundamentals and provides five practical steps to bolster security:
➀ Proper configuration
➁ Image scanning
➂ Network security
➃ Controlling running applications
➄ Auditing and logging events
➜ blog.palark.com/kubernetes-sec…

English
bytebutcher ретвитнул

eBPF kernel 'backdoor' to snoop on ALL ssh/sudo/su/login/passwd sessions. github.com/hackerschoice/…
English
bytebutcher ретвитнул

I'm sharing my content from 30+ conferences with community to learn 🙏
✅Talks & Slides
✅Presentations & Videos
✅Workshops & Trainings
✅Books & Documentation
Please Share & RT
madhuakula.com/content/
#InfoSec #Security #DevSecOps #Pentesting #DevOps #CloudNative #OpenSource

English








