aegilops :github::microsoft: · @aegilops
126 followers · 470 posts · Server fosstodon.org

I open sourced a tool to create lists of repos to run GitHub CodeQL’s Multi-Repository Variant Analysis on, using a keyword search on GitHub.

It's a Bash script you can trigger with a VSCode build task. It uses the GitHub API (via the GitHub CLI) to fill a list in the VSCode settings.

It’s a stopgap before this sort of feature makes it into the product.

github.com/advanced-security/m

#mrva #variantanalysis #CodeQL #github #vscode #buildtask #sast #vulnerabilityresearch

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
118 followers · 432 posts · Server fosstodon.org

You can now run a single static analysis query across thousands of repos on GitHub using CodeQL's MRVA (Multi-repo Variant Analysis).

That's great both for security research and rapidly auditing exposure to a single vuln or weakness for security teams.

It works from the CodeQL extension for VSCode, with open source public repos & private repos where CodeQL Code Scanning is enabled.

github.blog/2023-03-09-multi-r

#github #securityresearch #vulnerabilityresearch #CodeQL #variantanalysis #mrva #sast

Last updated 2 years ago

TODO Courses · @TODO
0 followers · 1 posts · Server infosec.exchange

We've just setup shop on Mastodon! 🐘The TODO training platform's still in early development, however, if you're looking to learn , , and then you've come to your right place. πŸ‘¨β€πŸ’»πŸ‘©β€πŸ’»πŸ§‘β€πŸ’»

ReverseEngineering.courses

#reverseengineering #vulnerabilityresearch #offensivesecurity

Last updated 2 years ago

JamesStevenson · @JamesStevenson
42 followers · 6 posts · Server infosec.exchange

I've been working on a , , , and training platform over the past few months. It's still in the 'MVP' stage so I'd love any feedback folk have for it! πŸ§‘β€πŸ’»πŸ‘©β€πŸ’»πŸ‘¨β€πŸ’»

TODO.courses

#reverseengineering #vulnerabilityresearch #pentesting #offensivesecurity

Last updated 2 years ago

JamesStevenson · @JamesStevenson
202 followers · 7 posts · Server infosec.exchange

I've been working on a , , , and training platform over the past few months. It's still in the 'MVP' stage so I'd love any feedback folk have for it! πŸ§‘β€πŸ’»πŸ‘©β€πŸ’»πŸ‘¨β€πŸ’»

TODO.courses

#reverseengineering #vulnerabilityresearch #pentesting #offensivesecurity

Last updated 2 years ago

JamesStevenson · @JamesStevenson
202 followers · 7 posts · Server infosec.exchange

I've finally setup an account on Mastodon πŸ™Œβ€‹πŸ˜…β€‹ Now that I'm here, thought that I'd fill my feed with a few bits and pieces that I've been up to over the past year. πŸ§΅β€‹

πŸ“±β€‹100% off Analysis Course:
udemy.com/course/android-malwa

πŸ€–β€‹ 100% off Android Games Course:
udemy.com/course/learn-reverse

πŸ“šβ€‹ 75% Off My Android / and book: ko-fi.com/jamesstevenson/link/

#android #malware #reverseengineering #ios #vulnerabilityresearch #pentesting

Last updated 2 years ago

anne-marie creamer · @amcreamer
161 followers · 62 posts · Server zirk.us
Tinker β˜€οΈ · @tinker
8184 followers · 4740 posts · Server infosec.exchange

To this! It's looks like @alex has set up a Mastodon instance that can be messed around with as a sort of lab environment (is that right, Alex?!) - Perhaps a valid target for web app pentesting and bug research for Mastodon?

(HT @JoshCGrossman for the tip!)

Talk to @alex to be sure and for more information.

But here's the link to the server:
cybervillains.com/explore

_____

#WebAppPentesting #vulnerabilityresearch #mastodon

Last updated 2 years ago

Tinker β˜€οΈ · @tinker
8184 followers · 4740 posts · Server infosec.exchange

So @jerry has brought together all these hackers, all these information security professionals, all these web application penetration testers...

...and put them together on an open sourced web application.

Look, I ain't telling you to hack this specific server. But I am telling you to have fun with the software (IN YOUR OWN LAB ENVIRONMENT!!!)

Anyhoo... information on how to report vulnerabilities within Mastodon here: github.com/mastodon/mastodon/s

_______

#WebAppPentesting #infosec #foss #vulnerabilityresearch

Last updated 2 years ago

weetster · @weetster
169 followers · 74 posts · Server ioc.exchange

It’s crazy to me how often I find some vulnerable code in a library but it’s unreachable for whatever reason. Maybe it becomes reachable one day or maybe it sits there forever, just out of reach, because either way it’s not worth anyone’s time to report or fix.

#infosec #vulnerabilityresearch

Last updated 2 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online
ITSEC News · @itsecbot
738 followers · 32490 posts · Server schleuss.online
ITSEC News · @itsecbot
738 followers · 32490 posts · Server schleuss.online
ITSEC News · @itsecbot
738 followers · 32490 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Zoom Communications User Enumeration - Video conferencing and calling software has spiked in popularity as individuals across the globe are... more: feedproxy.google.com/~r/feedbu

#vulnerabilityresearch #vulnerabilityspotlight

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Information disclosure vulnerability in Microsoft Media Foundation - Marcin β€œIcewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.

Microsoft ... more: feedproxy.google.com/~r/feedbu

#vulnerabilityresearch #vulnerabilityanalysis #microsoftpatchtuesday #vulnerabilityspotlight #microsoftmediafoundation

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: Multiple vulnerabilities in Videolabs libmicrodns - Claudio Bozzato of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.

A specific li... more: feedproxy.google.com/~r/feedbu

#videolabs #vulnspotlight #denialofservice #vulnerabilityresearch #vulnerabilityspotlight #vulnerabilityadvisories

Last updated 5 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online

Vulnerability Spotlight: WAGO products contain remote code execution, other vulnerabilities - Patrick DeSantis, Kelly Leuschner and Lilith [-_-]; of Cisco Talos discovered these vulnerabilities.... more: feedproxy.google.com/~r/feedbu

#ics #wago #wagopfc #controllers #vulnerabilities #vulnerabilityresearch #vulnerabilityspotlight

Last updated 5 years ago