Hejto.pl
Dodaj post

Wpisz coś do wyszukania (minimum 2 znaki)

#informatyka

GURU

w Informatyka

5piorunów

właśnie se przez liska usunąłem węzeł, który zaczynał się od <iframe> i już mi jakieś gówna nie wyskakuja i nie blokują playlisty (chyba 10 lat temu zrobionej) na sylwka na YT :smiley:

albo jestem geniuszem, albo pokolenie Z przejmuje giganta z debilnymi filmikami :smiley:

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.30.md

AI pentest scoping playbook - https://devansh.bearblog.dev/ai-pentest-scoping/

Sliding into your DMs: Abusing Microsoft Teams for Malware Delivery - https://permiso.io/blog/sliding-into-your-dms-abusing-microsoft-teams-for-malware-delivery

How Malware Takes a Bit Out of the Apple - https://reversea.me/index.php/how-malware-takes-a-bit-out-of-the-apple/

SPTM - The Last Bits - https://www.df-f.com/blog/sptm4

Extracting Syscalls from a Suspended Process - https://cymulate.com/blog/extracting-syscalls-from-a-suspended-process/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.28.md

Tracking malicious code execution in Python - https://rushter.com/blog/python-code-exec/

Advisory - Netskope Client for Windows - Local Privilege Escalation via Rogue Server (CVE-2025-0309) - https://blog.amberwolf.com/blog/2025/august/advisory---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/

Hidden in Plain Sight: A Misconfigured Upload Path That Invited Trouble - https://www.varonis.com/blog/misconfigured-upload-path

What's Next: React2Shell Beyond Next.js - https://www.vulncheck.com/blog/react2shell-beyond-nextjs

Microsoft Defender for Identity Recommended Actions: Remove non-admin accounts with DCSync permissions - https://thalpius.com/2025/09/23/microsoft-defender-for-identity-recommended-actions-remove-non-admin-accounts-with-dcsync-permissions/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.26.md

Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes - https://darkmentor.com/publication/2025-11-hardweario/

Malware development: persistence - part 26. Microsoft Edge - part 1. Simple C example - https://cocomelonc.github.io/persistence/2024/08/14/malware-pers-26.html

Operation Artemis: Analysis of HWP-Based DLL Side Loading Attacks - https://www.genians.co.kr/en/blog/threat_intelligence/dll

Referral Beware, Your Rewards are Mine (Part 1) - https://rhinosecuritylabs.com/research/referral-beware-your-rewards-are-mine-part-1/

IPv4/IPv6 Packet Fragmentation: Detection & Reassembly - https://packetsmith.ca/ip_frag_reassembly/

Fenomen

w Hydepark

2piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.24.md

Backing up Spotify - https://annas-archive.li/blog/backing-up-spotify.html

Yet Another DCOM Object for Command Execution Part 2 - https://sud0ru.ghost.io/yet-another-dcom-object-for-command-execution-part-2/

Magecart Skimmer Analysis: From One Tweet to a Campaign - https://blog.himanshuanand.com/2025/09/magecart-skimmer-analysis-from-one-tweet-to-a-campaign/

Pwn2Own 2025: Pwning Lexmark’s Postscript Processor - https://boredpentester.com/pwn2own-2025-pwning-lexmarks-postscript-processor/

From Zero to Shell: Hunting Critical Vulnerabilities in AVideo - https://chocapikk.com/posts/2025/avideo-security-vulnerabilities/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.22.md

Smile, You’re on Camera: A Live Stream from Inside Lazarus Group’s IT Workers Scheme - https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation/

Inside the brain of a hacking robot: Exploring traces | AI Cyber Challenge - https://theori.io/blog/exploring-traces-63950

Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications - https://research.eye.security/consent-and-compromise/

How I Found the Worst ASP.NET Vulnerability — A $10K Bug (CVE-2025-55315) - https://www.praetorian.com/blog/how-i-found-the-worst-asp-net-vulnerability-a-10k-bug-cve-2025-55315/

Rust for Malware Development - https://bishopfox.com/blog/rust-for-malware-development

Zawodowiec

w Programowanie

8piorunów

Czy prościej znaczy lepiej? - devszczepaniak.pl

O tym, że czasami prościej znaczy lepiej, miałem okazję przekonać się zbyt wiele razy. Nie zliczę, ile razy szedłem w przekombinowane lub wręcz niepotrzebne rozwiązania. O jednej z takich sytuacji przygotowałem artykuł na blogu. Opisałem praktyczny problem napotkany jakiś czas temu

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.20.md

Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows - https://connormcgarr.github.io/km-shadow-stacks/

No Alloc, No Problem: Leveraging Program Entry Points for Process Injection - https://bohops.com/2023/06/09/no-alloc-no-problem-leveraging-program-entry-points-for-process-injection/

HijackLoader Expands Techniques to Improve Defense Evasion - https://www.crowdstrike.com/en-us/blog/hijackloader-expands-techniques/

Malware Just Got Its Free Passes Back! - https://klezvirus.github.io/posts/Moonwalk-plus-plus/

Pwning Millions of Smart Weighing Machines with API and Hardware Hacking - https://spaceraccoon.dev/pwning-millions-smart-weighing-machines-api-hardware-hacking/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.18.md

Intel Outside: Hacking every Intel employee and various internal websites - https://eaton-works.com/2025/08/18/intel-outside-hack/

TLS NoVerify: Bypass All The Things - https://f0rw4rd.github.io/posts/tls-noverify-bypass-all-the-things/

Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer - https://securitylabs.datadoghq.com/articles/enumerating-aws-the-quiet-way-cloudtrail-free-discovery-with-resource-explorer/

macOS LPE via the .localized directory - https://theevilbit.github.io/posts/localized/

Copilot Broke Your Audit Log, but Microsoft Won’t Tell You - https://pistachioapp.com/blog/copilot-broke-your-audit-log

GURU

w Hydepark

27piorunów

Festerku ratuj, bo mi się laptok spalił.

Przynieś, popaczam.

W U T ???!!!:astonished: :astonished:

.

.

.

.

.

.

.

.

.

.

.

.

.

.

.

.

.

.

Pamiętajcie dzieciaczki nie zostawiajcie na stole stroików świątecznych z zapalonymi świeczkami.

Płyta oczywiście martwa, ale dysk (trochę osmalony) ocalał, leci kopia posektorowa.

Pokaż więcej komentarzy (13)

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.16.md

FortMajeure: Authentication Bypass in FortiWeb (CVE-2025-52970) - https://pwner.gg/blog/2025-08-13-fortiweb-cve-2025-52970

“Vibe Hacking”: Abusing Developer Trust in Cursor and VS Code Remote Development - https://blog.calif.io/p/vibe-hacking-abusing-developer-trust

From Process Injection to Function Hijacking - https://klezvirus.github.io/posts/From-stomping-to-hijacking/#function-stomping

How to fuse CTI with threat hunting - https://feedly.com/ti-essentials/posts/how-to-fuse-cti-with-threat-hunting

Declarative Binary Parsing for Security Research with Kaitai Struct - https://husseinmuhaisen.com/blog/declarative-binary-parsing-for-security-research-with-kaitai-struct/

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.14.md

Zero Click, One NTLM: Microsoft Security Patch Bypass (CVE-2025-50154) - https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/

The Pool Party You Will Never Forget: New Process Injection Techniques Using Windows Thread Pools - https://www.safebreach.com/blog/process-injection-using-windows-thread-pools/

OmniProx: Multi-Cloud IP Rotation Made Simple - https://blog.zsec.uk/omniprox/

When Defenders Become the Attackers: The Elastic EDR 0-Day (RCE + DoS) - https://ashes-cybersecurity.com/0-day-research/

From Support Ticket to Zero Day - https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/

Fenomen

w Hydepark

4piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.12.md

Breaking change on GitHub Actions pull_request_target - https://blog.richardfan.xyz/2025/11/17/github-actions-pull-request-target-changes.html

How to Research & Reverse Web Vulnerabilities 101 - https://projectdiscovery.io/blog/how-to-research-web-vulnerabilities

A File Format Uncracked for 20 Years - https://landaire.net/a-file-format-uncracked-for-20-years/

From Drone Strike to File Recovery: Outsmarting a Nation State - https://profero.io/blog/from-drone-strike-to-file-recovery-outsmarting-a-nation-state

CVE-2025-6554: The (rabbit) Hole - https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html

Osobistość

w AI

15piorunów

Gemini halucynuje front page hackernews z 2035 (i robi to dobrze)

#cobotpowiedzial #ai #heheszki #humorinformatykow #informatyka Ktoś dla jaj kazał Gemini zrobić klon strony hackernews (news.ycombinator.com) z 2035 roku i wyszło całkiem realistycznie. Do tego niżej wrzucam też jak ktoś poszedł dalej tym tropem i dodał halucynacje dyskusji. Żeby wejść

Fenomen

w Hydepark

7piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.10.md

Reverse Engineering Network Protocols - https://jhalon.github.io/reverse-engineering-protocols/

Stillepost - Or: How to Proxy your C2s HTTP-Traffic through Chromium - https://x90x90.dev/posts/stillepost/

Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling - https://spaceraccoon.dev/nokia-beacon-router-uart-command-injection/

CLRaptor: Hunting reflected assemblies with Velociraptor - https://labs.infoguard.ch/posts/clraptor_hunting_for_assemblies/

Evading Elastic EDR's call stack signatures with call gadgets - https://offsec.almond.consulting/evading-elastic-callstack-signatures.html

Fenomen

w Hydepark

6piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.08.md

CVE-2024-12718: Path Escape via Python’s tarfile Extraction Filters - https://www.upwind.io/feed/cve-2024-12718-path-escape-via-pythons-tarfile-extraction-filters

AI LLM Red Team Handbook - https://cph-sec.gitbook.io/ai-llm-red-team-handbook-and-field-manual

Public Disclosure: Backdooring Managed Identities via Azure API Management - https://dazesecurity.io/blog/apimMIVuln

Grafana Dashboard for my Blackstone Smoker - https://paulsec.github.io/posts/grafana-dashboard-for-my-blackstone-smoker/

Malware Sideloading via MFC Satellite DLLs - https://r136a1.dev/2025/12/03/malware-sideloading-via-mfc-satellite-dlls/

Zawodowiec

w Programowanie

6piorunów

Książki programistyczne, które przeczytałem w 2025 roku - devszczepaniak.pl

Końcówka 2025 roku to świetna okazja, by podsumować książki, które w tym roku zdążyłem przeczytać. W najnowszym wpisie zebrałem tytuły, które szczególnie mnie zainteresowały, a którym nie poświęciłem osobnych recenzji. W artykule znajdziesz książki poruszające takie tematy

GURU

w Hydepark

27piorunów

AAAAAAAAA trzymcie mnie, bo nie wytrzymie. :imp: 💀 :skull_and_crossbones:

Płatnik to :hankey: i jakiś ponury żart.

Przesiadka z WIN7PRO64bit na WIN11PRO64bit, Płatnik 10.02.002(313) z bazą .mdb, wypierdala się koncertowo w losowych momentach, z komunikatami o braku zasobów - jaaaasne -nowy komp, nowy system, 32GB/1TB to za mało.

Coś mi się zdaje, że będzie migracja bazy na SQL-a.

Osobistość1piorunów

@UncleFester To, że komp ma tyle zasobów to nie znaczy, że program ma do nich wszystkich dostęp. Takie rzeczy można modyfikować jeśli program jest uruchamiany jako usługa, maszyna wirtualna Javy itd. Nie wiem jak to wygląda w Płatniku ale u mnie w firmie były takie niespodzianki i niektórych klientów i robiliśmy łatki/instrukcje zmiany dostępu do zasobów.

Pokaż więcej komentarzy (8)

Fenomen

w Hydepark

3piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.06.md

ClickFix Gets Creative: Malware Buried in Images - https://www.huntress.com/blog/clickfix-malware-buried-in-images

Developing Modern Ransomware Part 1: User-Land - https://lorenzomeacci.com/developing-modern-ransomware-part-1-user-land

Exploiting DLL Hijacking in Windows Electron Apps - https://hexiosec.com/blog/dll-hijacking-and-proxying/

Implementing syscall hooks in Rust - https://fluxsec.red/implementing-syscall-hooking-rust

The cryptography behind electronic passports - https://blog.trailofbits.com/2025/10/31/the-cryptography-behind-electronic-passports/

Fenomen

w Hydepark

5piorunów

Link on Github --> https://github.com/Nieuport/news-and-links/blob/gh-pages/docs/2025.12.04.md

Long Live Pass-The-Cert: Reviving the Classical Rendition of Lateral Movement across Entra ID joined Devices - https://www.alteredsecurity.com/post/long-live-pass-the-cert-reviving-the-classical-rendition-of-lateral-movement-across-entra-id-joined

Ublock Origin Script Injection - https://grahamhelton.com/blog/ublock-origin-script-injection

ROX: Vulnerability Research - how to approach a black box without wasting time - https://numb3rs.re/posts/approaching_large_binaries/

Memory Analysis with Velociraptor - Part 1 - https://docs.velociraptor.app/blog/2025/2025-11-15-memory-analysis-pt1/

BetterSuccessor: Still abusing dMSA for Privilege Escalation (BadSuccessor after patch) - https://www.alteredsecurity.com/post/bettersuccessor-still-abusing-dmsa-for-privilege-escalation-badsuccessor-after-patch