Pake : un outil Open Source développé en Rust permettant de transformer n'importe quelle page web en application de bureau plus rapide et plus compacte qu'Electron
Pake : un outil Open Source développé en Rust permettant de transformer n'importe quelle page web en application de bureau plus rapide et plus compacte qu'Electron
Stirling PDF : une application Open Source pour manipuler vos fichiers PDF.
Avec des fonctionnalités complètes de modification, conversion et sécurisation.
Stirling PDF : une application Open Source pour manipuler vos fichiers PDF.
Avec des fonctionnalités complètes de modification, conversion et sécurisation.
JumpServer : un système de gestion des accès privilégiés Open Source.
Un PAM permet de sécuriser, contrôler et surveiller l'accès aux ressources critiques.
JumpServer : un système de gestion des accès privilégiés Open Source.
Un PAM permet de sécuriser, contrôler et surveiller l'accès aux ressources critiques.
tldr, the repo's github action workflow wasn't safely evaluating the github PR's branch name, and it opened up a shell injection, and the attacker was able to inject a crypto miner into a popular pypi package
tldr, the repo's github action workflow wasn't safely evaluating the github PR's branch name, and it opened up a shell injection, and the attacker was able to inject a crypto miner into a popular pypi package
Though 🔵 is a fair approximation of what it would look like.
People underestimate the Pacific.
Though 🔵 is a fair approximation of what it would look like.
People underestimate the Pacific.
*attempts to install requirements*
ERROR: EXTERNALLY-MANAGED-ENVIRONMENT
😡
*attempts to install requirements*
ERROR: EXTERNALLY-MANAGED-ENVIRONMENT
😡
2FA all your things. All of them. Avoid the SMS code version, there are multiple ways to compromise that. I recommend getting a Yubikey. Barring that, an authenticator app like Duo or Authy will work fine.
Signal for your texts and calls, especially for anything sensitive.
2FA all your things. All of them. Avoid the SMS code version, there are multiple ways to compromise that. I recommend getting a Yubikey. Barring that, an authenticator app like Duo or Authy will work fine.
Signal for your texts and calls, especially for anything sensitive.
#bugbounty #bugbountytips #bugbountytip #hackerone #bugcrowd #infosec #cybersecurity #pentesting #redteam #informationsecurity #securitycipher #technology #coding #code #recon #ai #llm #owasp
#bugbounty #bugbountytips #bugbountytip #hackerone #bugcrowd #infosec #cybersecurity #pentesting #redteam #informationsecurity #securitycipher #technology #coding #code #recon #ai #llm #owasp
Because when they need to update a timestamp in MySQL they call NOW(), but when they do it in MSSQL they can pretend they're finally getting a date (GETDATE())
Because when they need to update a timestamp in MySQL they call NOW(), but when they do it in MSSQL they can pretend they're finally getting a date (GETDATE())
phrack.org/issues/71/17...
phrack.org/issues/71/17...