CVE 2022-40055
This post sheds light on CVE-2022-40055. Vulnerable device: GPON ONT: Titanium 2122A found HERE Software Version: T2122-V1.26EXL Hardware Version: C40-210 Descrip...
Alpha Threat Blog
Malware tradecraft, pentest technique, tooling in Ruby and Python, and plain-English security awareness — 30 articles from the Alpha Threat team.
Latest
This post sheds light on CVE-2022-40055. Vulnerable device: GPON ONT: Titanium 2122A found HERE Software Version: T2122-V1.26EXL Hardware Version: C40-210 Descrip...
The Linux concept of 'Everything is a file' is a very helpful one. This post share details of an attacker can read the network statistics even if the commands lik...
Sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. ...
Obfuscation can be simply understood as the art of hiding code in plainsight, in order to defeat the signature based defence mechanisms in place. Obfuscation has ...
How can you avoid being a victim of a cyber-attack? Here are 7 cybersecurity best practices you can begin to implement today to protect yourself from cyber attack...
Make you own Security Solution, get alert on new process launch. Stay tuned Today's post can be used by System Admins and fellow friends to detect any suspicious ...
This post discuss about how to read the data that your browser stores locally. This data includes cookies, forms, history, boookmarks, etc which can be used to ob...
This amazingly interesting post describes persistence techniques malwares use today via Registry entries. Malwares have been an interesting topic of research sinc...
In this post we dive deep into the ICMP protocol and utilise the same for exfiltration of data without any external tool. Before we get into technical stuff let u...
This post explains a very simple technique to skip detection of your backdoor from native tools like netstat, ps, lsof This article assumes the attacker have alre...
In recent years, the purpose of ransomware attacks have evolved to target businesses by encrypting entire computer networks and files, stopping operations until p...
DNSCrypt aids in encrypting the normal DNS traffic so that it can't be snooped DNSCRYPT DNSCrypt focuses on securing communications between a client and its first...
This post offers a list of Open source security controls to adapt. Special thanks to Adrian Grigorof for compiling this list SECURITY CONTROLS OPEN SOURCE Firewal...
This post lists some commonly known APT groups of various countries CHINA Comment Crew, APT2 UPS, IXESHE APT16, Hidden Lynx Wekby, Axiom Winnti Group, Shell Crew ...
This blog post discuss the art of Optical Character Recognition and using it to read the Captchas. OPTICAL CHARACTER RECOGNITION (OCR) Simply stating Optical Char...
This article discusses about the Employee Management Security Controls organization can adapt to enhance their security posture Security controls are safeguards o...
This article discusses about using GoLang tool webify to establish a simple HTTP backdoor that listens on a port and executes remote commands sent over. There are...
Title says it all.This list comes handy during a pentest. Format is CAMERA MODEL: USERNAME/PASSWORD multiple authentication are separated by a comma (,) ACTi: adm...
This post sheds light to how the attackers are able to bring down a single or all the wireless networks around. We claim no responsibility of the harm done via an...
This blog gives an excerpt on attacking WPS feature of a router WPS or WiFi protected setup is used to automatically configure a wireless network with a Service s...
Batch file programming is the native programming offered by the Microsoft Windows Operating System. Batch file is created using any text editors like notepad, Wor...
This post explains all the tool categories under Kali linux. This post is upon request from one of our readers. Kali contains tons of tools categorized under vari...
This article focus on a DNS attack named "DNS Cache Snooping". This helps an outside attacker to gather the intelligence of domains being visited by the organisat...
When there is no activity in a tab (NAP) a malicious code is executed that can be used for a phishing attack. Original page is then redirected to another fake pag...
Netcat is a utility that is able to write and read data across TCP and UDP network connections. It is widely used by network or system analysts. Netcat can be use...
This is a handy trick to execute custom script or executable on target machine if you lack execute permission Lack of execute permission can put some guys to halt...
Here i share code i wrote to search my study related material which was spread all over the Hard disk in multiple partitions. So I have all my learning stuff spre...
This post provides an insight on some of the methods ( C code snippets) that can be use to detect either a program is running in a Virtual Machine instance. Sourc...
Here we will take a peek into the creativity of attackers who always keep on trying new and creative ideas to steal your identity. This post shows some real email...
Develop a unique oneliner colored reverse shell in Ruby Language This is a simple one liner reverse shell with threading and color feature. Every command gets exe...
No articles match that filter.