History of Kali Linux: from Whoppix and BackTrack to Kali Purple
The complete history of Kali Linux: Whoppix in 2004, WHAX, Auditor, BackTrack, the 2013 Debian rebuild, Kali Purple and local AI. 20 years of pentesting.
The complete history of Kali Linux: Whoppix in 2004, WHAX, Auditor, BackTrack, the 2013 Debian rebuild, Kali Purple and local AI. 20 years of pentesting.
Discover the story of the Intel Management Engine, a hidden chip in Intel processors since 2008, capable of operating independently of the operating system.
Kali Linux is probably the most widely used operating system in the offensive security world... but wrongly so! In fact, there are much better alternatives!
How to avoid fines related to GDPR? The most effective solution is to conduct penetration tests. A complete guide is available in the article below.
How to choose the right tools for an intrusion test? Read more in the article below
What is the budget for an intrusion test?r
XZ Utils has a significant backdoor in its latest versions 5.6.0 and 5.6.1. However, its exploitation is not trivial.
WordPress, as one of the most widely used content management systems (CMS) in the world, powers a significant portion of websites, ranging from personal blogs to corporate sites.
A new class of speculative execution vulnerabilities, named GhostRace, has been discovered in March 2024. This attack is particularly dangerous as it can be used to exploit a wide array of software, including web browsers, operating systems, and critical applications.
Canon, a 20 billion euro multinational corporation, is impacted by 2 critical vulnerabilities that, under certain conditions, can compromise the infrastructure hosting the vulnerable application. Trackflaw shares its discovery and responsible disclosure process.
This article details how a simple vulnerability discovered in late January 2024 could allow an attacker to compromise Jenkins instances.
This article details and explains to the reader the different approaches to a penetration test and how to make the right choice.
This article details how GitLab is vulnerable to the CVE-2023-7028 flaw and why it should not be publicly exposed.
OwnCloud is an open-source software providing a platform for online file storage, sharing services, and various applications. It is presented as an alternative to Dropbox, which is based on a public cloud. However, like all software, it suffers from vulnerabilities.
Dive into the depths of 'reverse tab nabbing,' an incredibly effective phishing technique. Discover how hackers cleverly exploit your browser tabs to redirect you to malicious sites while making you believe you are safely browsing familiar sites. Through a realistic scenario, we show you step-by-step how this attack unfolds and highlight the exploitable vulnerabilities. Learn essential measures to protect yourself, such as avoiding the use of the target=_blank attribute or incorporating rel=noopener noreferrer. This article is a must-read for strengthening your cybersecurity and thwarting modern phishing traps.
In the article 'Cisco CVE-2023-20198 - Creating a Botnet Network,' published on October 20, 2023, Trackflaw explores a critical privilege escalation flaw in Cisco IOS-XE. Rated 10 on the CVSS scale, this vulnerability allows an unauthenticated attacker to create an account with the highest privileges. Trackflaw details the exploitation steps, from creating an administrator account to installing an implant, restarting the service, and clearing traces. The author also discusses how to locate vulnerable hosts and the protective measures recommended by Cisco in the absence of a patch. The article includes reliable references and an animation summarizing the exploitation.
Discover how to bypass file upload mechanisms by exploiting a file upload vulnerability. I guide you through the sophisticated techniques used to upload a malicious file to a target system, illustrated with the example of the l33t-hoster challenge from the Insomni'hack Teaser 2019 CTF. Learn how to create a polyglot file and bypass anti-PHP protection, while understanding the necessary security measures to counter such attacks. An essential article for cybersecurity enthusiasts looking to deepen their knowledge of file upload security.
Dive into the depths of 'reverse tab nabbing,' an incredibly effective phishing technique. Discover how hackers cleverly exploit your browser tabs to redirect you to malicious sites while making you believe you are safely browsing familiar sites. Through a realistic scenario, we show you step-by-step how this attack unfolds and highlight the exploitable vulnerabilities. Learn essential measures to protect yourself, such as avoiding the use of the target=_blank attribute or incorporating rel=noopener noreferrer. This article is a must-read for strengthening your cybersecurity and thwarting modern phishing traps.