Aggregator
API安全浅析
3 years 1 month ago
API安全浅析
3 years 1 month ago
API安全浅析
3 years 1 month ago
Romanian Gas Station Network Hit by Ransomware
3 years 1 month ago
Summary
Bleeping Computer has published an article detailing a ransomware attack against Romania's petroleum provider, Rompetrol. The attack has halted gas station service throughout the country.
Threat Type
Ransomware
Overview
A ransomware attack against Romania's petroleum provider has crippled the country's Fill&Go service and websites. Bleeping Computer states the actors behind the attack are the Hive ransomware gang. This is unconfirmed however, the ransom note left on the network is indicative of Hive
Russia Releases 17K IP Addresses in DDoS
3 years 1 month ago
Summary
A list of more than 17,000 IP addresses has been released by Vladimir Putin. The current unsubstantiated claim is that those listed are conducting active Distributed Denial of Service attacks against Russian targets.
Threat Type
DDoS
Overview
For more information on this story, please follow this link to the latest in our ongoing coverage of the Ukrainian/Russian war.
Indicators of Compromise
A list of IoCs can be found in the Reports section to the right.
References
https://www.cyberscoop.com/russi
What Does Fishing for Rebar Have to Do with Building a More Sustainable Internet?
3 years 1 month ago
Danny Lewin Community Care Days (DLCCDs) are a celebration of our late co-founder Danny Lewin?s generous spirit and his tenacious appetites for collaboration, innovation, and (especially) giving back to our global community. DLCCDs bring to life our values and empower all Akamai employees to volunteer in the communities where we work, operate, and live.
Mike Mattera
Actions Akamai Is Taking on Russia and Ukraine
3 years 1 month ago
Akamai stands with the people of Ukraine. As the assault on Ukraine continues, we are inspired by the courageous citizens defending their sovereignty.
Akamai
Disclosure of Vulnerability in Azure Automation Managed Identity Tokens
3 years 1 month ago
On December 10, 2021, Microsoft mitigated a vulnerability in the Azure Automation service. Azure Automation accounts that used Managed Identitiestokens for authorization and an Azure Sandbox for job runtime and execution were exposed. Microsoft has not detected evidence of misuse of tokens.
Microsoft has notified customers with affected Automation accounts. Microsoft recommends following the security best practices herefor the Azure Automation service
Java Web —— 从内存中Dump JDBC数据库明文密码
3 years 1 month ago
在红队行动中经常会遇到拿到Webshell后找不到数据库密码存放位置或者是数据库密码被加密的情况(需要逆向代码查找解密逻辑)。在此提出两种在从运行时获取所有的数据库连接信息(密码)的方式
java安全-java反序列化之URLDNS
3 years 1 month ago
darkless
Java Web —— 从内存中Dump JDBC数据库明文密码
3 years 1 month ago
在红队行动中经常会遇到拿到Webshell后找不到数据库密码存放位置或者是数据库密码被加密的情况(需要逆向代码查找解密逻辑)。在此提出两种在从运行时获取所有的数据库连接信息(密码)的方式
As-Exploits新模块SharpLoader
3 years 1 month ago
震惊!神秘插件竟新增如此功能。。。
学习笔记:自制查询IP归属地小应用
3 years 1 month ago
一个学习笔记
学习笔记:自制查询IP归属地小应用
3 years 1 month ago
一个学习笔记
让安全产品摆烂的十五条建议
3 years 1 month ago
看到一篇笔风挺意思的文章让安全团队快速倒闭的十条建议,模仿也写了几条关于安全产品的忠告建议,行之是否有效,也请自行甄别尝试,过程所产生的一切风险责任由践行者承担~~1、不必重视安全产品运营,交由...
Coco413
CVE-2022-0492: how release_agent escape become a vulnerability
3 years 1 month ago
Terenceli
fastjson<=1.2.68 漏洞分析
3 years 1 month ago
去年写的文章,没发出来,给公众号增加点内容,也留点笔记
从SSRF 到 RCE —— 对 Spring Cloud Gateway RCE漏洞的分析
3 years 1 month ago
从机制上对 Spring Cloud Gateway RCE进行了详细分析
fastjson<=1.2.68 漏洞分析
3 years 1 month ago
去年写的文章,没发出来,给公众号增加点内容,也留点笔记