Vulnerability Management. A thread.
I don’t see much written on vulnerability management in more holistic terms vs. patch/bug fixing. This might be ok given a lot of vuln. mgmt. should be contextualized into enterprise risk/control. But still worth a short thread.......
1/13
💻 What to look for on a site with IIS?
1. Use shortscan to search for short (and possibly full) filenames and extensions.
- shortscan : - github.com/bitquark/short…
2. Check for reverse proxy and try directory traversal:
/backend/ -> 10.0.0.1/api/
/backend/..%2Ftest ->…
################################
CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent
################################
now.. first questions...
how many devices in your enterprise do you have running a vulnerable version of SSH?
How many of these are internet…
How many of these do you know? 100 web app exploits, in case you were bored :)
Cross-Site Scripting (XSS)
SQL Injection
Cross-Site Request Forgery (CSRF)
Remote File Inclusion (RFI)
Local File Inclusion (LFI)
Server-Side Request Forgery (SSRF)
Clickjacking
Directory Traversal…
#7 So what can you do?
▪️Eat saturated fats and cut out seed oils
▪️Limit carbs and sugars
▪️Grow your own food in your self-made compost
▪️Exercise at least 3 times a week
▪️Limit your screen time
▪️Enjoy the sun as much as possible
▪️Read the book 'Turtles All the Way Down'
I'm working on a talk and looking for some ideas for port scanning. I'm currently scanning ports 443,8443,8000,5000 across a set of IP addresses. What other ones would you scan and why? 8081? 3000?
#CVE#Hunting#MDE#M365D CVE-2023-21554
Alternative to look only at process events
DeviceProcessEvents
| where Timestamp > ago(30d)
| where ProcessVersionInfoOriginalFileName has "MQSVC"
| summarize by DeviceName
#CVE#Hunting#MDE#M365D
CVE-2023-21554
DeviceNetworkEvents
| where Timestamp > ago(30d)
| where ActionType == "ListeningConnectionCreated"
| where LocalPort == "1801"
| where InitiatingProcessVersionInfoOriginalFileName has "MQSVC"
| summarize by DeviceName
Stanford University offers this free course on Web Security.
The course covers:
1. HTTP, Cookies, Sessions
2. Same Origin Policy
3. Cross-Site Scripting (XSS)
4. Denial-of-service, Phishing, Side Channels
5. WebAuthn
6. Server security
and more...
Link: stanford.io/2UHIu65
Hey all!! We are running yet another Pay What You Can for SOC Core Skills next week!
Yes, $0 is an option.
Let's break some gates down and get more cool people in the industry.
antisyphontraining.com/soc-core-skill…
2K Followers 4K FollowingCar & van leasing; vehicle finance solutions; salary sacrifice schemes. Feefo Excellence Award for a decade of best-in-class customer experience. Est 2006.
570 Followers 411 FollowingHead of EDI, York and Scarborough Teaching Hospitals FT. WRES Expert. MSc in HRM, PgC in Diversity Management.
Unapologetically ME! My pronouns are she & her
2K Followers 5K FollowingAlhamdulillah for Everything | An Ambivert |
I prefer loneliness to a fake company - Muhammad Ali The Greatest And Finest Boxer
477 Followers 4K FollowingIt's later.. I'm dipping my toes in again...
Translating business security needs into proposals for business investments to reduce risk.
1.7M Followers 21 FollowingThe official Twitter page of the Central Bank of Nigeria. We ensure price and financial system stability and promote sustainable economic development.
178K Followers 43 FollowingThis is the Official Twitter handle of the FEDERAL MINISTRY OF EDUCATION Facebook-https://t.co/U4tOWDL7Na E-mail- [email protected]
2K Followers 53 Following25
They/Them
Screenwriter
Telling stories that exclusively centre relationships between Black Queer people.
https://t.co/LGyisPDdqu
378K Followers 3K FollowingMatthew Russell Lee for/as Inner City Press covers SDNY, UN Gate, banks & IMF. books https://t.co/xHL0pGID4n https://t.co/VTEqaLISDB
125K Followers 178 FollowingOfficial account of the National Agency for Food and Drug Administration and Control, Nigeria. Follow for updates on the Agency's activities.
4K Followers 4K FollowingWriter. Medical Doctor. Entrepreneur. Building global solutions at 𝐀𝐥𝐚 𝐀𝐟𝐫𝐢𝐜𝐚 𝐋𝐚𝐛𝐬. Founder @careeredu_ & @mindhelpa (Techstars ‘24).
392 Followers 149 FollowingWe are the largest and best-equipped cancer treatment centre in Nigeria. Radiotherapy | Brachytherapy | Chemotherapy 07006742588; 09030009436 [email protected]
3K Followers 896 FollowingExposing the killings in Alaigbo, carried out by the Biafra Liberation Army led by @Simon_Ekpa.| Not employee of the gov/security | Opinions are mine.
128K Followers 17K Followingjournalist | Hell is not enough |Documentation October 7th massacre | Former 0404 news editor.
You can support my work here: https://t.co/SOtb4tJlxB
12K Followers 133 FollowingWe’re one of the UK’s leading financial services groups. We’re available via our website Mon-Fri 9am–5.30pm. Direct messages from X are not monitored.
30K Followers 798 FollowingUnapologetic truth-slinger, rooted in "logic over feelings". I champion what’s real, call out the noise, and keep it 100. 🪬🪬” The Luabi Spirit” 🪬
55K Followers 86 FollowingLondon's Metropolitan Police Service Contact Centre (MetCC). We are available for non-emergency enquiries 24/7/365. In an emergency, always dial 999.
165K Followers 2K FollowingGoogle Whistleblower via James O'Keefe . Disclosed Google's "Machine Learning Fairness", the AI system that censors and controls your access to information.
597 Followers 112 FollowingInnovative threat intelligence-driven and AI-powered company aiming at cyber threat detection and response.
🏢 https://t.co/0FL345uw8M
🔎 https://t.co/5mM9C3Boux
23K Followers 74 FollowingONCD’s mission is to advance national security, economic prosperity, and technological innovation through cybersecurity policy leadership.
2K Followers 2K Followingwe are all vibrating energy spiraling throughout the infinity
*all original content*
#poetry #poets #poem #poetrycommunity #vss365
287K Followers 10K FollowingMember, Kaduna North Federal Constituency, @HouseNGR. Former SLA to Senator @UbaSaniUs. Former Manager @Huawei. Chairman House Committee on Banking Regulations.
141K Followers 518 FollowingWe are the police force for the City of London 'Square Mile'. Please don't report crime here; call 101 or 999 in an emergency. Not monitored 24/7.
2.7M Followers 31 FollowingMountaineer. Avid traveler and adventurer. #TableShaker. #1 Bestselling Author. @BusinessInsider Influencer of 2022. Hollywood Festival Awardee. Globetrotter.
350K Followers 117 FollowingThe official X account of The Federal Ministry of Information and National Orientation, Federal Republic of Nigeria | Honourable Minister: @HMMohammedIdris
No recent Favorites. New Favorites will appear here.