Experts released VMware vRealize Log RCE exploit for CVE-2022-31706

Horizon3 security researchers released proof-of-concept (PoC) code for VMware vRealize Log Insight RCE vulnerability CVE-2022-31706. Last week, researchers from Horizon3’s Attack Team announced the release of PoC exploit code for remote code execution in VMware vRealize Log tracked as CVE-2022-31706 (CVSS base 9.8/10). The PoC exploit code will trigger a series of flaws in VMware […]

The post Experts released VMware vRealize Log RCE exploit for CVE-2022-31706 appeared first on Security Affairs.

Confused about this

Hello, I ran “netsh wlan profile name=‘name’ key=clear” and got the password assigned, however, whenever I entered said password, it said it was incorrect. I can attempt to link an image below. Screenshot of terminal output submitted by /…

GitHub to revoke stolen code signing certificates for GitHub Desktop and Atom

GitHub confirmed that threat actors exfiltrated encrypted code signing certificates for some versions of GitHub Desktop for Mac and Atom apps. GitHub this week disclosed a security breach, threat actors exfiltrated encrypted code signing certificates for some versions of GitHub Desktop for Mac and Atom apps. In response to the incident, the Microsoft-owned company is started […]

The post GitHub to revoke stolen code signing certificates for GitHub Desktop and Atom appeared first on Security Affairs.

Browser based SQL injection, tips?

Been using a tool to pentest on a website I set up with intentional vulnerabilities on my local network and I’m lost here.

A tool I used for scanning detected a blind SQL injection point, and gave me this link:

https://www.mywebsite.com/?℅22℅09or%09sleep%287%29%231

On the point https://www.mywebsite.com/

Not part of any indexes or other pages

What does the URL fully mean? What kind of request is being done and can I get anything out of it, if at all?

It looks like its tested for a time based blind SQL response but I’d want to know how else I can modify that request to give me other information about the site with no further context

submitted by /u/Blobman42
[link] [comments]

Pro-Palestine hackers threaten Israeli chemical companies

Threat actors are targeting Israeli chemical companies operating in the occupied territories, security experts warn. Threat actors have launched a massive hacking campaign aimed at Israeli chemical companies operating in the occupied territories. A group, named Electronic Quds Force, is threatening companies’ engineers and workers and are inviting them to resign from their positions. The […]

The post Pro-Palestine hackers threaten Israeli chemical companies appeared first on Security Affairs.

What is your Google dork story?

I was recently scanning open internet for vulnerable systems but then I figured out Google dork is very effective in doing the same. Exploit-db provides a good list of dork search string, and is very helpful. What more can be done with Google dork? htt…