Copy
Welcome to the 44CON Newsbeat. This morning's news, tools and tips all in one place.

44CON | Shop | 44CON TV | Twitter | Linkedin

ProtonVPN TCP Accleration SYN+ACK Spoofing Analysis

Of course, not all applications complete the TCP 3-Way handshake, such as nmap which in some modes will only send the TCP SYN to determine if a port is open on a server.
https://remyhax.xyz/posts/protonvpn-tcp-hacks/

Read later on Instapaper

ScarredMonk/SysmonSimulator: Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and correlation rules by Blue teams.

This can be used by Blue teams for testing the EDR detections and correlation rules.
https://github.com/ScarredMonk/SysmonSimulator

Read later on Instapaper

Zynq Part 3: CVE-2021-27208 // ropcha.in //

Iteratively adding ONFI opcode support was nothing terribly exciting - though one amusing point was discovering that the NAND controller hardware in the Zynq won't complete a page read transaction unless you drive R/#B low for some period of time.
https://blog.ropcha.in/part-3-zynq-cve-2021-27208.html

Read later on Instapaper

 
Visit 44CON
Copyright © 2022 Sense/Net Ltd, All rights reserved.


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.