Skip to content

Severins kleine Cyber Seite

Nichts auf der Welt ist so mächtig wie ein Phishing-Email, dessen Zeit gekommen ist. (frei nach Victor Hugo)

  • Discovery
  • About Me
  • Impressum

Month: January 2023

The Attackers Guide to Azure AD Conditional Access

On January 27, 2023 By severin In Gefundenes

Conditional Access is one of Microsoft’s most powerful security features and the central engine for their zero trust architecture. https://danielchronlund.com/2022/01/07/the-attackers-guide-to-azure-ad-conditional-access/

Continue reading

IIS Crypto

On January 10, 2023 By severin In Gefundenes

IIS Crypto allows you to create your own custom templates which can be saved and then executed on multiple servers. To create your own template, select all of the settings for your configuration. Click on …

Continue reading

Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More

On January 4, 2023 By severin In Gefundenes

During the fall of 2022, a few friends and I took a road trip from Chicago, IL to Washington, DC to attend a cybersecurity conference and (try) to take a break from our usual computer …

Continue reading

New AMSI Bypass Using CLR Hooking

On January 4, 2023 By severin In Gefundenes

In this article, I will present a new technique to bypass Microsoft’s Anti-Malware Scan Interface (AMSI) using API Call Hooking of CLR methods. https://practicalsecurityanalytics.com/new-amsi-bypass-using-clr-hooking/

Continue reading

Sponsor j3ssie/Osmedeus

On January 4, 2023 By severin In Gefundenes

What is Osmedeus? Osmedeus allows you automated run the collection of awesome tools to reconnaissance and vulnerability scanning against the target. Next generation version? Enjoying this tool? Support it’s development and take your game to …

Continue reading

Web Security Academy

On January 4, 2023 By severin In Gefundenes

This cross-site scripting (XSS) cheat sheet contains many vectors that can help you bypass WAFs and filters. You can select vectors by the event, tag or browser and a proof of concept is included for …

Continue reading

Recent Posts

  • OWASP/wrongsecrets
  • OIDC Tester
  • «Die US-Regierung hat die Möglichkeit, auf viele Politiker­mails in Europa zuzugreifen»
  • URL validation bypass cheat sheet for SSRF/CORS/Redirect – 2024 Edition | W
  • Conditional Access Regelwerke in 2025 –

Recent Comments

No comments to show.

Archives

  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • June 2024
  • April 2024
  • February 2024
  • January 2024
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • June 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • August 2022
  • May 2022
  • March 2022
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • October 2020

Categories

  • Gefundenes
  • Uncategorized
WordPress Theme: Chronus by ThemeZee.