I maintain some notes about HTTP/2 ‘Rapid Reset’ DDoS attack - CVE-2023-44487
🔗 https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
#rapidreset #http2 #infosec #ddos #vulnerability #CVE-2023-44487
Hacker, working as a reverse engineer and malware analyst. I occasionally do some programming, devops, hardware stuff.
Looking for new jobs opportunity, feel free to contact me.
#malware #reverse #reverseengineering #intel #threat #threatintel #infosec #homelab #python #devops
| Blog | https://blog.codsec.com |
| Github | https://github.com/y0ug |
| https://twitter.com/y0ug |
I maintain some notes about HTTP/2 ‘Rapid Reset’ DDoS attack - CVE-2023-44487
🔗 https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088
#rapidreset #http2 #infosec #ddos #vulnerability #CVE-2023-44487
CrackMapExec now includes DPAPI cred dumping as a core feature thanks to the dploot library by Thomas Seigneuret from the Orange Cyberdefense French team.
Picture from @mpgn’s bird account.
I wonder how many AV engines ship with an affected version 🤔
CVE-2021-20294 POC - readelf stack overflow
https://github.com/tin-z/CVE-2021-20294-POC
DynamoRIO: nice intro for beginners for tracing and manipulating programs
https://vx.zone/2022/10/22/tracingwithdynamo-utku.html
#dynamorio #tracing #reverseengineering #hacking #infosec #learning
CVE-2023-22809: Sudoedit can edit arbitrary files
Website owners should secure their Google Tag Manager account and be on the lookout for injected code that would reference an additional GTM.
Several attacks I've looked at recently used a Google Tag Manager library to load credit card skimmers.
Here's an example and a couple of new #Magecart domains:
webstatlstics[.]com (skimmer)
info-select[.]com (exfiltration)
The Furby source code is public and heavily commented. For example, it turns the microphone off when the motors are running.
Furby was the 1998 version of ChatGPT and tons of people thought it actually slowly learned English words. The NSA was alarmed. However it turned out the "learning" process was just on a timer and the "microphone" only triggers on loud sounds.
https://archive.org/details/furby-source