๐ฉโ๐ปIW Weekly #77: Azure AD privilege escalation, CVE-2022-3910, Web Cache deception attack, GraphQL enumeration techniques, IDOR and many more..
Welcome to the #IWWeekly77 - the Monday newsletter that brings the best in Infosec straight to your inbox.
To help you out, we have 5 Articles, 4 Threads, 3 Videos, 2 Job Alerts and a Special Item ๐ซข
Read, upskill yourself and spread love to the community ๐
Excited? Letโs jump in ๐
๐ 5 Infosec Articles
- The article by @secureworks explains about Azure Active Directory Domain Services privilege escalation, including proof of concept and steps.
- In the article by @a13h1_, explore how he earned $500 by uncovering a privilege escalation vulnerability that allowed him to delete documents with student roles.
- The team at @whiteoaksecurity has brought up an article which explains about Graphql APIs and its enumeration techniques.
- A new method for container escape using file-based DirtyCred to exploit CVE-2022-3910 has been brought up by the team at @starlabs_sg .
- Get a detailed mind map on how to hunt for Web Cache Deception vulnerability through this article by ย @hbenja_m.
๐งต4 Trending Tweets
- Discover the leading tools for automating SQL Injection vulnerability testing in an insightful thread by @intigriti.
- Explore a captivating account of an crazy IDOR adventure by @atomiczsec.
- Uncover the secrets of espionage malware, unraveling its features and techniques in this insightful post by @RedHatPentester.
- Discovering a CSP Protection Bypass with Google's Domain โ @therceman's First Bug Bounty Tip.
๐ฝ๏ธ 3 Insightful Videos
- Explore the world of Windows security research in this informative video by @hacktricks_live.
- Gain insights into bounty ethics and real findings in this episode of @ctbbpodcast.
- Unlock network pivoting techniques with Chisel in this video, guided by @_JohnHammond.
๐ผ 2 Job Alerts
- Techdefencelab is hiring for Security Analysts with 1-2 years of experience.
- Payatu has open roles for Cyber threat Intelligence Interns and Customer Success manager.
๐ 1 Special Item
Thatโs all for this week. Hope you enjoyed these incredible finds and learned something new from todayโs newsletter. Meet you again next week hacker, until then keep pushing ๐ช
This newsletter would not have been made possible without our amazing ambassadors.
Resource contribution by: Nikhil A Memane, Ayush Singh, Bhavesh Harmalkar, Bimal Kumar Sahoo, Tuhin Bose, Mohit Khemchandani, Rushi Padhiyar
Newsletter formatting by: Nikhil A Memane, Rushi Padhiyar, Nithin R, Shlok
Lots of love
Editorial team,
Infosec Writeups
๐ง
If you have questions, comments, or feedback reach out to us on Twitter @InfoSecComm or email [email protected]