Analysis of Qualcomm Secure Boot Chains:
https://blog.quarkslab.com/analysis-of-qualcomm-secure-boot-chains.html
https://blog.quarkslab.com/analysis-of-qualcomm-secure-boot-chains.html
Quarkslab
Analysis of Qualcomm Secure Boot Chains - Quarkslab's blog
Qualcomm is the market-dominant hardware vendor for non-Apple smartphones. Considering the [SoCs] they produce are predominant, it has become increasingly interesting to reverse-engineer and take over their boot chain in order to get a hold onto the highest…
Implications of a Stealth Hard-Drive Backdoor
https://www.ibr.cs.tu-bs.de/users/kurmus/papers/acsac13.pdf
#Backdoor
https://www.ibr.cs.tu-bs.de/users/kurmus/papers/acsac13.pdf
#Backdoor
ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
Orange Tsai at DEFCON 29
https://www.youtube.com/watch?v=5mqid-7zp8k
Orange Tsai at DEFCON 29
https://www.youtube.com/watch?v=5mqid-7zp8k
YouTube
DEF CON 29 - Orange Tsai - ProxyLogon Just Tip of the Iceberg, New Attack Surface on Exchange Server
Microsoft Exchange Server is an email solution widely deployed within government and enterprises, and it is an integral part of both their daily operations and security. Needless to say, vulnerabilities in Exchange have long been the Holy Grail for attackers…
Chaining PHP Exploits with the help of Magic (and luck)
https://www.reddit.com/r/netsec/comments/p4dyuh/chaining_php_exploits_with_the_help_of_magic_and/
https://www.reddit.com/r/netsec/comments/p4dyuh/chaining_php_exploits_with_the_help_of_magic_and/
reddit
Chaining PHP Exploits with the help of Magic (and luck)
Posted in r/netsec by u/_creosote • 10 points and 6 comments
Zero-Day | RCE: The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month.
https://threatpost.com/unpatched-fortinet-bug-firewall-takeovers/168764/
https://threatpost.com/unpatched-fortinet-bug-firewall-takeovers/168764/
Threat Post
Unpatched Fortinet Bug Allows Firewall Takeovers
The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month.