Dockerfile-sec is a simple but powerful rules-based security checker for Dockerfiles
https://ift.tt/3zakoUX
Submitted June 08, 2021 at 03:08PM by cr0hn
via reddit https://ift.tt/2Rw45Rg
https://ift.tt/3zakoUX
Submitted June 08, 2021 at 03:08PM by cr0hn
via reddit https://ift.tt/2Rw45Rg
GitHub
cr0hn/dockerfile-security
Static security checker for Dockerfiles. Contribute to cr0hn/dockerfile-security development by creating an account on GitHub.
Let’s Encrypt Change Affects OpenSSL 1.0.x and CentOS 7
https://ift.tt/3iqug7a
Submitted June 08, 2021 at 02:49PM by ssh-bi
via reddit https://ift.tt/3fZPB5y
https://ift.tt/3iqug7a
Submitted June 08, 2021 at 02:49PM by ssh-bi
via reddit https://ift.tt/3fZPB5y
Medium
Let’s Encrypt change affects OpenSSL 1.0.x and CentOS 7
Default certificate chain to include an expired root certificate
How to: Find WordPress Plugin Vulnerabilities Free eBooK
https://ift.tt/3g2vcgs
Submitted June 08, 2021 at 04:43PM by ethicalhack3r
via reddit https://ift.tt/3z7yo1I
https://ift.tt/3g2vcgs
Submitted June 08, 2021 at 04:43PM by ethicalhack3r
via reddit https://ift.tt/3z7yo1I
NoSql Injection Cheatsheet
https://ift.tt/3g2qdfx
Submitted June 08, 2021 at 05:57PM by Charlie-B
via reddit https://ift.tt/353qrN2
https://ift.tt/3g2qdfx
Submitted June 08, 2021 at 05:57PM by Charlie-B
via reddit https://ift.tt/353qrN2
Null Sweep
NoSql Injection Cheatsheet
Learn how NoSQL Injection works, with example strings to inject to test for injections.
How much security gain do you get by implementing a NAC solution? The answers might suprise you.
https://ift.tt/3gh22sS
Submitted June 08, 2021 at 08:12PM by The-Luemmel
via reddit https://ift.tt/3puuiMM
https://ift.tt/3gh22sS
Submitted June 08, 2021 at 08:12PM by The-Luemmel
via reddit https://ift.tt/3puuiMM
luemmelsec.github.io
I got 99 problems but my NAC ain´t one
This post will be all about Network Access Control (NAC) solutions and how they might lull you into a sense of security.
Designed to keep rouge devices out of your network, I´ll show you ways around it, as well as ways to protect yourself.
From a pentester´s…
Designed to keep rouge devices out of your network, I´ll show you ways around it, as well as ways to protect yourself.
From a pentester´s…
Dead Ends in Cryptanalysis #2: Timing Side-Channels
https://ift.tt/35aCubP
Submitted June 08, 2021 at 07:58PM by Soatok
via reddit https://ift.tt/2T3VxS9
https://ift.tt/35aCubP
Submitted June 08, 2021 at 07:58PM by Soatok
via reddit https://ift.tt/2T3VxS9
Dhole Moments
Dead Ends in Cryptanalysis #2: Timing Side-Channels - Dhole Moments
Previously on Dead Ends in Cryptanalysis, we talked about length-extension attacks and precisely why modern hash functions like SHA-3 and BLAKE2 aren’t susceptible. The art and science of sid…
Your Microsoft Teams chats aren’t as private as you think..
https://ift.tt/3g15XuU
Submitted June 08, 2021 at 09:19PM by infinitelogins
via reddit https://ift.tt/3x7qHqo
https://ift.tt/3g15XuU
Submitted June 08, 2021 at 09:19PM by infinitelogins
via reddit https://ift.tt/3x7qHqo
Infinite Logins
Your Microsoft Teams chats aren’t as private as you think..
Encrypt and Anonymize Your Internet Connection for as Little as $3/mo with PIA VPN. Learn More Microsoft Teams is a proprietary business communication platform developed by Microsoft, as …
Hacker's guide to deep-learning side-channel attacks: code walkthrough
https://ift.tt/3whNgsJ
Submitted June 09, 2021 at 12:11AM by ebursztein
via reddit https://ift.tt/2T8KxTx
https://ift.tt/3whNgsJ
Submitted June 09, 2021 at 12:11AM by ebursztein
via reddit https://ift.tt/2T8KxTx
Elie Bursztein's site
Hacker's guide to deep-learning side-channel attacks: code walkthrough
Learn how to perform a deep-learning side-channels attack using TensorFlow to recover AES cryptographic keys from a hardware device power traces, step by step.
Fuzzing the Office Ecosystem - Check Point Research
https://ift.tt/3g20jZl
Submitted June 09, 2021 at 12:01AM by sagitz_
via reddit https://ift.tt/3gcqSd6
https://ift.tt/3g20jZl
Submitted June 09, 2021 at 12:01AM by sagitz_
via reddit https://ift.tt/3gcqSd6
Check Point Research
Fuzzing the Office Ecosystem - Check Point Research
Research By: Netanel Ben-Simon and Sagi Tzadik Introduction Microsoft Office is a very commonly used software that can be found on almost any standard computer. It is also integrated inside many products of the Microsoft / Windows ecosystem such as Office…
The Walls Have Ears - Compromising a Conference Table Microphone
https://ift.tt/2TTSfkU
Submitted June 09, 2021 at 12:07PM by pocorgtfoftw
via reddit https://ift.tt/3zbgNGf
https://ift.tt/2TTSfkU
Submitted June 09, 2021 at 12:07PM by pocorgtfoftw
via reddit https://ift.tt/3zbgNGf
Grimm-Co
The walls have ears
Introduction Modern business often relies heavily on the Internet and software resources such as Zoom or Skype to support daily operat...
ALPACA Attack
https://ift.tt/2TT9djn
Submitted June 09, 2021 at 06:01PM by shapelez
via reddit https://ift.tt/3w84I2C
https://ift.tt/2TT9djn
Submitted June 09, 2021 at 06:01PM by shapelez
via reddit https://ift.tt/3w84I2C
reddit
ALPACA Attack
Posted in r/netsec by u/shapelez • 21 points and 4 comments
Author spoofing in Google Colaboratory
https://ift.tt/3514BtV
Submitted June 09, 2021 at 06:50PM by zoh4rs
via reddit https://ift.tt/3pB27vC
https://ift.tt/3514BtV
Submitted June 09, 2021 at 06:50PM by zoh4rs
via reddit https://ift.tt/3pB27vC
Big Stages Implementation And Library Files
https://ift.tt/2TgjvJP
Submitted June 09, 2021 at 08:22PM by hlldz
via reddit https://ift.tt/3cMZJNl
https://ift.tt/2TgjvJP
Submitted June 09, 2021 at 08:22PM by hlldz
via reddit https://ift.tt/3cMZJNl
with knowledge comes power
Big Stages Implementation And Library Files
If you have a command & control server running a RAT, you should protect this server from possible detections. This is one of the golden rules for OPSEC. There has been a lot of content shared on this topic lately, and researchers are detecting command &…
Now Available: Impacket Release v0.9.23
https://ift.tt/2RFYubi
Submitted June 09, 2021 at 09:56PM by mgalloar
via reddit https://ift.tt/35aMBNr
https://ift.tt/2RFYubi
Submitted June 09, 2021 at 09:56PM by mgalloar
via reddit https://ift.tt/35aMBNr
On how to access (protected) networks
https://ift.tt/3zdZNz8
Submitted June 09, 2021 at 10:59PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3g5ycsc
https://ift.tt/3zdZNz8
Submitted June 09, 2021 at 10:59PM by S3cur3Th1sSh1t
via reddit https://ift.tt/3g5ycsc
s3cur3th1ssh1t.github.io
On how to access (protected) networks | S3cur3Th1sSh1t
This post is about common misconfigurations and attack szenarios that enable an attacker to access separated networks with critical systems or sensitive data...
c0c0n 2021 | Call For Papers & Call For Workshops is now open
https://ift.tt/3ctMmRZ
Submitted June 09, 2021 at 11:42PM by pr4jwal
via reddit https://ift.tt/3g7srdL
https://ift.tt/3ctMmRZ
Submitted June 09, 2021 at 11:42PM by pr4jwal
via reddit https://ift.tt/3g7srdL
Hacking Unity Games with Malicious GameObjects
https://ift.tt/355jWK0
Submitted June 10, 2021 at 01:33AM by IncludeSec
via reddit https://ift.tt/3ivja0M
https://ift.tt/355jWK0
Submitted June 10, 2021 at 01:33AM by IncludeSec
via reddit https://ift.tt/3ivja0M
Include Security Research Blog
Hacking Unity Games with Malicious GameObjects - Include Security Research Blog
The Unity game engine provides various means for getting external assets into a game, such as AssetBundles, for adding assets at runtime and the Asset Store, for purchasing third-party assets. It’s possible for a GameObject to execute arbitrary code using…
Let's share salary information 💰💰in InfoSec 👨💻👩🏿💻 globally 🌍 and make it publicly available
https://ift.tt/3iuMe8D
Submitted June 10, 2021 at 02:21AM by infosec-jobs
via reddit https://ift.tt/2T9n2K5
https://ift.tt/3iuMe8D
Submitted June 10, 2021 at 02:21AM by infosec-jobs
via reddit https://ift.tt/2T9n2K5
salaries.infosec-jobs.com
infosec-jobs.com Salaries
We collect salary information anonymously from professionals all over the world in the InfoSec/Cyber Security space and make it publicly available for anyone to use, share and play around with.
How i was able to bypass parental pin of showmax
https://ift.tt/3zeyjtc
Submitted June 10, 2021 at 02:59AM by abdulsec
via reddit https://ift.tt/3wmc2HO
https://ift.tt/3zeyjtc
Submitted June 10, 2021 at 02:59AM by abdulsec
via reddit https://ift.tt/3wmc2HO
Medium
How i was able to bypass parental pin of showmax
Showmax is an online subnoscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…
I Am Living A Nightmare and I need Help ASAP! (Please Stop and Read)
https://ift.tt/3is0SNT
Submitted June 10, 2021 at 11:02AM by MoulayAdnan
via reddit https://ift.tt/3g7hTLy
https://ift.tt/3is0SNT
Submitted June 10, 2021 at 11:02AM by MoulayAdnan
via reddit https://ift.tt/3g7hTLy
Kapwing
netsec.PNG
Video made on Kapwing
Pop-Ups in a good-world
https://ift.tt/3pCxFRG
Submitted June 10, 2021 at 02:14PM by albinowax
via reddit https://ift.tt/3vgrB2M
https://ift.tt/3pCxFRG
Submitted June 10, 2021 at 02:14PM by albinowax
via reddit https://ift.tt/3vgrB2M