Copy
Welcome to the 44CON Newsbeat. This morning's news, tools and tips all in one place.

44CON | Shop | 44CON TV | Twitter | Linkedin

A real-life case of the Log4Shell vulnerability

The cybersecurity incident at ONUS started with a Log4Shell vulnerability in their payment software provided by Cyclos but later escalated due to misconfigurations and mistakes in granting permissions at AWS S3. Attackers took advantage of the vulnerability in the Cyclos software to attack even before the vendor could inform and provide patch instructions for its clients.
https://cystack.net/research/the-attack-on-onus-a-real-life-case-of-the-log4shell-vulnerability

Read later on Instapaper

Bypassing early 2000s copy protection for software preservation

The CD of Bygg hus med Mulle Meck incorporates a disc copy protection scheme known as SafeDisc V2, which was very common in games of the era.
https://blog.paavo.me/masa-copy-protection/

Read later on Instapaper

Still waiting on the daybreak, its shadows in my mind

The following simple code was used to extract the differences between the two speckle patterns, I picked the red channel from the image and found out about this way to 'difference' two images from - https://www.
https://www.anfractuosity.com/projects/fun-with-speckle-patterns/

Read later on Instapaper

PHP LFI with Nginx Assistance

Upload a big client body to force nginx to create a /var/lib/nginx/body/$X def.
http://bierbaumer.net/security/php-lfi-with-nginx-assistance/

Read later on Instapaper

archercreat/vmpfix: Universal x86/x64 VMProtect 2.0-3.X Import fixer

VMPfix is a dynamic x86/x64 VMProtect 2.13-3.5 import fixer.
https://github.com/archercreat/vmpfix

Read later on Instapaper

Microsoft Defender for Identity security alert lateral movement playbook

The lateral movement playbook is third in the four part tutorial series for Microsoft Defender for Identity security alerts.
https://docs.microsoft.com/en-us/defender-for-identity/playbook-lateral-movement

Read later on Instapaper

 
Visit 44CON
Copyright © 2021 Sense/Net Ltd, All rights reserved.


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.