Cyber Humanitarianism is achieved through community engagement, education and exercise. Hands on Keyboard lowering the security poverty line every day.
It's that time of year. We are pleased to bring you HackNWA Conference 2025: Sock Puppet Tycoon - Disposable Machine, Network, Server, Client and Identity;Make frens and influence ppl
Great speakers, activities, panelists, and afterparty concert in Bentonville
Get your tickets!
NEW LAB ๐ฅณ: WinDbg Crash Dump Analysis by @DebugPrivilege
Using WinDbg to analyze dumps of CVE-2024-29824 and CVE-2023-29357 exploited in the wild.
๐Solve the incident here ๐
xintra.org
Test your memory forensic skills on:
๐Reflective DLL Injection
๐Decoding NTLMSSP
๐Detecting remote code execution
๐Extracting payloads from memory
@XintraOrg
HashDB Release 1.10.0
Now with support for IDA 9, and continued backwards compatibility all the way back to IDA 7.5
๐ thanks to @plebourhis for the help!!
github.com/OALabs/hashdb-idaโฆ
First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS.
Let's start with creating malicious OAuth applications. By default, ANY USER can create app registrations and consent to Graph permissions as well as sharing 3rd party company data. In tenants where this is hardened, ability to create app registrations require Application Administrator or Cloud-Application Administrator and admins must consent to permissions used by the application whether local or from another tenant.
I made this little guy in the Lock Picking / Soldering village at #THOTCON. This was my first time. It works, but it needs a little lithium battery to power that green light. #FSociety#MrRobot