|11 months ago||3 months ago|
|GNU General Public License v3.0 or later||GNU General Public License v3.0 only|
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Mass exploitation of on-prem Exchange servers :(
4 projects | reddit.com/r/msp | 3 Mar 2021
There is likely a Cobalt Strike BEACON acting as C2 now even if you've patched. I recommend full incident response mode, probably want to isolate the server. Run an integrity check against a known good config with WinDiff or NSA's dirChecker to find other anomolies. https://github.com/nsacyber/Mitigating-Web-Shells
Independently secure, together not so much - a story of 2 WP plugins
1 project | reddit.com/r/netsec | 2 Nov 2021
If you've got the ability to write .htaccess files, you pretty much already have RCE and do not need additional upload vulnerabilities. See https://github.com/wireghoul/htshells for some fun examples.
4 projects | news.ycombinator.com | 13 Jan 2021
Found some GitHub issues  with something similar: an enterprise firewall blocking a repo because it contained the string "arglebargleglopglyf"  in some tests.
The text was flagged as malicious because of its presence in the repo github.com/wireghoul/htshells . However, the whole point of the word in the htshells repo is that it's an invalid command that breaks Apache, so it could have been almost any random string.
What are some alternatives?
fancy-index - A responsive Apache index page.
big-list-of-naughty-strings - The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
wstg - The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
FlameCord - Patches for Waterfall to improve overall performance, fix memory issues and protect against attacks.
GovCMS7 - Current stable release of the main Drupal 7 GovCMS distribution, with releases mirrored at https://www.drupal.org/project/govcms
hack - Kubernetes security and vulnerability tools and utilities.