A High-severity bug in F5 BIG-IP can lead to code execution and DoS

Experts warn of a high-severity vulnerability that affects F5 BIG-IP that can lead to arbitrary code execution or DoS condition. A high-severity vulnerability in F5 BIG-IP, tracked as CVE-2023-22374, can be exploited to cause a DoS condition and potentially lead to arbitrary code execution. “A format string vulnerability exists in iControl SOAP that allows an […]

The post A High-severity bug in F5 BIG-IP can lead to code execution and DoS appeared first on Security Affairs.

How to find source of any video on web?

I usually used to inspect any video and get the source URL from there. But the websites upped their security and started using blob URLs. Then I started looking for m3u8 files in the networks tab and used ffmpeg to download them. Now I have started seeing websites that use blob urls and dont even have m3u8’s in network tab. But I know there has to be some way to download these videos because there are other websites where we can paste the video URL and lets you download them. But downloading is not what I want.

What I want is to understand how to get the source of any video on the web. Because I feel if a video is playing on a website there has to be some source it is loading the video from. So are there any more methods other than the 2 I mentioned above? (Getting URL from inspect and m3u8s from networks tab)

submitted by /u/Redditforavenger
[link] [comments]

I think I made a mistake

Im currently applying for my bachelors right now and got into 2 universities for computer science with information security. But I feel like I made the wrong choice. I am already pretty aware of the infosec field, have done bug hunting, AD security but I really want to move forward with embedded systems security. Now I feel that I should’ve applied for computer systems engineering/electronics and computer engineering and could’ve learnt a lot about hardware and take cyber sec as an optional module. At the end of the day everything you can learn in a comp sci degree is available online but it is much harder for something like electronics. Opinions?

submitted by /u/Horse-Trojan
[link] [comments]

AIs as Computer Hackers

Hacker “Capture the Flag” has been a mainstay at hacker gatherings since the mid-1990s. It’s like the outdoor game, but played on computer networks. Teams of hackers defend their own computers while attacking other teams’. It’s a controlled setting for what computer hackers do in real life: finding and fixing vulnerabilities in their own systems and exploiting them in others’. It’s the software vulnerability lifecycle.

These days, dozens of teams from around the world compete in weekend-long marathon events held all over the world. People train for months. Winning is a big deal. If you’re into this sort of thing, it’s pretty much the most fun you can possibly have on the Internet without committing multiple felonies…

Experts warn of two flaws in popular open-source software ImageMagick

Experts disclosed details of two security flaws in the open-source software ImageMagick that could potentially lead to information disclosure or trigger a DoS condition. Researchers at Metabase Q discovered a couple of security vulnerabilities in the open-source image manipulation software ImageMagick that could potentially lead to information disclosure or trigger a Denial of Service (DoS) condition (CVE-2022-44268, CVE-2022-44267). ImageMagick is […]

The post Experts warn of two flaws in popular open-source software ImageMagick appeared first on Security Affairs.

Is it possible for someone to replace video feed with prerecorded video on an NVR camera system like Lorex?

Are there any known methods of taking a video feed and falsifying it on an ethernet based camera system?

There’s an employee that uses things like kali linux OS and miscellaneous hak5 devices and has previously gained access to the companies network… so I guess they could maybe be considered “a hacker”. The employee reclines in the office all night and probably sleeps, but is never caught. You can’t open the door to the offices without waking them up, and you can’t bust them sleeping because they’re awake by the time you get to their door within the offices.

There’s a Lorex video system with an extra channel, but it would be installed in an area where they would have direct access to the ethernet cord and no supervision. Is it possible for them to fake a video feed so that if I’m viewing the feed I see a fake video loop?

I’ve seen there are ways that people have faked video feed using OSB on ZOOM and wanted to know if there are any known methods that I myself am unaware of that could be used to provide a fake video feed to the NVR. I wouldn’t say we’re dealing with Mr. Robot, but they’re definitely not your average joe.

submitted by /u/anotherdumbschmuck
[link] [comments]

What do hackers use data breaches for?

I was wondering what do people usually do with the data breaches they download from forums like breached. The databases have lots of personal information like names, emails, phone numbers but obviously almost never passwords due to encryption. So I was curious trying to figure out what are they mostly used for.. I doubt it’s just for educational purposes, I bet people want to make money off it.

Are they going after the email lists to do some spamming/phishing? I’m just a curious beginner so that’s the only explanation I could think of

submitted by /u/quietestman
[link] [comments]

Over 30k Internet-Exposed QNAP NAS hosts impacted by CVE-2022-27596 flaw

Censys found 30,000 internet-facing QNAP appliances potentially impacted by a recently disclosed critical code injection flaw. On January 30, Taiwanese vendor QNAP released QTS and QuTS firmware updates to address a critical vulnerability, tracked as CVE-2022-27596 (CVSS v3 score: 9.8), that affects QNAP NAS devices. A remote attacker can exploit the vulnerability to inject malicious code […]

The post Over 30k Internet-Exposed QNAP NAS hosts impacted by CVE-2022-27596 flaw appeared first on Security Affairs.