Experimenteller Jailbreak bis iOS 17.0 aufgetaucht

Ein neuer experimenteller Jailbreak bis iOS 17.0 ist für Tester verfügbar. Die Ausführung kann allerdings 15 Minuten und länger dauern!

TARNKAPPE.INFO
Leaking the phone number of any Google user ($5k bounty)

YouTube
Bruteforcing the phone number of any Google user

From rate limits to no limits: How IPv6's massive address space and a crafty botguard bypass left every Google user's phone number vulnerable

brutecat.com
Bruteforcing the phone number of any Google user

From rate limits to no limits: How IPv6's massive address space and a crafty botguard bypass left every Google user's phone number vulnerable

brutecat.com
Thanks to our #TurrisSentinel #security #research program, #CZNIC #CSIRT team discovered large scale #FTP #attack. Coming from 45.78.4.0/22, it is #bruteforcing #slowly - it takes it 19 day to get through it's #passwords. Big thanks to everybody who helps us by running our #minipots on their devices! Report in #Czech is available on CSIRT website https://csirt.cz/cs/kyberbezpecnost/aktualne-z-bezpecnosti/distribuovany-ftp-bruteforcer/
Distribuovaný FTP bruteforcer - Aktuálně z bezpečnosti - CSIRT

Aktuálně z bezpečnosti

How many services have a default username, but can have a custom password? Redis comes to mind (AUTH default password123).
#bruteforcing

A case of missing bytes: #bruteforcing your way through #Jenkins' CVE-2024-23897

(In which US crypto export restrictions prove to be still harmful after 25 years)

https://www.errno.fr/bruteforcing_CVE-2024-23897.html

A case of missing bytes: bruteforcing your way through Jenkins’ CVE-2024-23897

Guillaume Quéré
I decided to write a Ruby micro-framework for writing bruteforcers. In order to test my code, I would need bruteforce-able servers. So I created this bruteforceable repo of various apps and Dockerfiles. Please feel free to contribute some additional servers/Dockerfiles. Currently have FTP and HTTP Basic-Auth, still need HTTP Login Form, SMTP, POP3, IMAP, and RDP. What else am I missing?
https://github.com/ronin-rb/bruteforceable
#bruteforcers #bruteforcing #infosec #dockerfiles
GitHub - ronin-rb/bruteforceable: A collection of bruteforceable apps

A collection of bruteforceable apps. Contribute to ronin-rb/bruteforceable development by creating an account on GitHub.

GitHub

@gaycookie Nah...

Personally I'd literally block all non-consumer-facing #ISP's to prevent #botting and #Spamming like #BruteForcing #Credentials.

Shure that'll inconvenience some users like you and me but Microsoft doesn"t gove a damn about something >99% of users won't experience ever...

https://github.com/nitrogenez/nitroforce

Yes, I'm naming my software like the smurfs do.
So.

This is an android pentest tool made by me in Lua.
It uses adb to bruteforce Android phone's PIN.
Notice included.

To those smarties that would like to use that NOT in educational purpose: you need to at least enable USB-debugging on a victim's phone.

Made it just for fun and to upgrade my Lua skills.

#bruteforce #bruteforcing #android #pentest #pentesting #justforfun

GitHub - nitrogenez/nitroforce: Simple Android PIN-code bruteforcer written on Lua

Simple Android PIN-code bruteforcer written on Lua - GitHub - nitrogenez/nitroforce: Simple Android PIN-code bruteforcer written on Lua

GitHub