- 8 Posts
- 6 Comments
execveat@infosec.pubOPMtoResearch@infosec.pub•What's your side project of a month?English2·2 years agoNot at all. Figuring a work-life balance that suits you is a worthy goal.
execveat@infosec.pubOPMtoResearch@infosec.pub•BChecks (SDL for defining custom scans) available in Burp 2023.6English1·2 years agoAlso, repo for sending PRs: https://github.com/PortSwigger/BChecks
execveat@infosec.pubOPMtoResearch@infosec.pub•What's your side project of a month?English1·2 years agoI played around with WebSockets and wrote a new tool: https://github.com/doyensec/wsrepl
It’s an interactive REPL interface like websocat, but it’s meant specifically for pentesting, not debugging, and it’s easily extensible in Python (while still retaining REPL interface). In future releases I’d like to expand the extensibility by adding declarative style configuration (the ultimate feature would be something like what Burp’s Autorize plugin does, but for websockets).
execveat@infosec.pubOPtoSecurity News@infosec.pub•Fortinet tries to silently patch critical RCE, researches burn itEnglish3·2 years agoWith all of the embarrassing command injections they keep getting, Fortinet should assess their SOC and incident preparedness and find compromises that may lie hidden by calling their own Security Advisory Services.
execveat@infosec.pubMtoResearch@infosec.pub•Side projects for May/June 2023 (🔒podcast)English0·2 years agoHey there and congratulations on getting a few first episodes out! Launching is half the battle, and it looks like you’re well on your way.
I’m actually running a small podcast as well and I feel your pain about figuring out the target audience and the personal style. Unless you’re aiming for mainstream success, I’d suggest focusing on what you personally feel is missing in the podcasting sphere. Hopefully it will keep you driven, and ensure that you genuinely enjoy the process. Plus, it increases the odds that you won’t abandon the project midway. Keep on the good work!
They’re not even that stealthy. The code is bullshit,
gitignore
folder is super suspicious and malware is just a binary within the zip file. Clearly meant for script kiddies.