AppSweep, mobile application scanning for developers!
https://ift.tt/3jmxSpH
Submitted August 03, 2021 at 06:13PM by dznn
via reddit https://ift.tt/3Cb1EWJ
https://ift.tt/3jmxSpH
Submitted August 03, 2021 at 06:13PM by dznn
via reddit https://ift.tt/3Cb1EWJ
Guardsquare
Mobile Application Security Testing | AppSweep
Find and fix security issues in your Android app’s code with AppSweep: a mobile application security testing solution, based on ProGuard technology.
AppSec - Account Takeover (ATO) Checklist
https://ift.tt/2VdXQDu
Submitted August 03, 2021 at 06:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3frcjTB
https://ift.tt/2VdXQDu
Submitted August 03, 2021 at 06:48PM by ZealousidealYogurt41
via reddit https://ift.tt/3frcjTB
GitHub
ato-checklist/README.md at master · magoo/ato-checklist
A checklist of practices for organizations dealing with account takeover (ATO) - ato-checklist/README.md at master · magoo/ato-checklist
How to set up GoPhish to evade security controls.
https://ift.tt/3CcBT8r
Submitted August 03, 2021 at 07:59PM by _meatball_
via reddit https://ift.tt/3lz8LlU
https://ift.tt/3CcBT8r
Submitted August 03, 2021 at 07:59PM by _meatball_
via reddit https://ift.tt/3lz8LlU
Bypassing Authentication on 20+ Arcadyan Routers with CVE-2021–20090 and rooting some Buffalo
https://ift.tt/3ym5QAV
Submitted August 03, 2021 at 07:57PM by stargravy
via reddit https://ift.tt/3rOx0hc
https://ift.tt/3ym5QAV
Submitted August 03, 2021 at 07:57PM by stargravy
via reddit https://ift.tt/3rOx0hc
Medium
Bypassing Authentication on Arcadyan Routers with CVE-2021–20090 and rooting some Buffalo
A walkthrough of my first experience in router hacking
Variant analysis of the ‘Sequoia’ bug
https://ift.tt/3yArXDT
Submitted August 03, 2021 at 10:15PM by JordyZomer
via reddit https://ift.tt/3frdaUu
https://ift.tt/3yArXDT
Submitted August 03, 2021 at 10:15PM by JordyZomer
via reddit https://ift.tt/3frdaUu
pwning.systems
Variant analysis of the 'Sequoia' bug
I imagine we've all heard about the recent 'Sequoia' bug discovered by the Qualys Research team. It's a fascinating bug so I decided to do variant analysis using CodeQL!
Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
https://ift.tt/3jgurkd
Submitted August 03, 2021 at 11:04PM by 0xdea
via reddit https://ift.tt/2Vhobk4
dozer.nz
Developing an exploit for the Jira Data Center Ehcache RCE (CVE-2020-36239)
Overview
Trash Panda as a Service: Raccoon Stealer steals cookies, cryptocoins, and more
https://ift.tt/2Vw80iw
Submitted August 04, 2021 at 12:58AM by securehoney
via reddit https://ift.tt/3xlRM9g
https://ift.tt/2Vw80iw
Submitted August 04, 2021 at 12:58AM by securehoney
via reddit https://ift.tt/3xlRM9g
Sophos News
Trash Panda as a Service: Raccoon Stealer steals cookies, cryptocoins, and more
Cookie and credential stealing malware-as-a-service delivered by dropper-as-a-service now packs a “clipper” to steal crypto-transactions, and can drop other malware.
AppSweep, a free & developer friendly android app security scanning tool
https://ift.tt/3yqlivE
Submitted August 04, 2021 at 01:49PM by Floni
via reddit https://ift.tt/3jiqefT
https://ift.tt/3yqlivE
Submitted August 04, 2021 at 01:49PM by Floni
via reddit https://ift.tt/3jiqefT
reddit
AppSweep, a free & developer friendly android app security...
Posted in r/netsec by u/Floni • 4 points and 0 comments
SAML is insecure by design
https://ift.tt/2Vvl6wu
Submitted August 04, 2021 at 01:56PM by albinowax
via reddit https://ift.tt/3ChqCnp
https://ift.tt/2Vvl6wu
Submitted August 04, 2021 at 01:56PM by albinowax
via reddit https://ift.tt/3ChqCnp
joonas.fi
SAML is insecure by design
What is SAML? Security Assertion Markup Language (SAML) is an open standard for exchanging authentication and authorization data between parties.
Source: Wikipedia
SAML is often used for single-sign on (“Sign in with Google”, “Sign in with Twitter” etc.).…
Source: Wikipedia
SAML is often used for single-sign on (“Sign in with Google”, “Sign in with Twitter” etc.).…
Surveying China’s Digital Silk Road in the Western Balkans
https://ift.tt/3flopxB
Submitted August 04, 2021 at 05:22PM by Fuji_Dragon
via reddit https://ift.tt/3AdV0gT
https://ift.tt/3flopxB
Submitted August 04, 2021 at 05:22PM by Fuji_Dragon
via reddit https://ift.tt/3AdV0gT
War on the Rocks
Surveying China’s Digital Silk Road in the Western Balkans - War on the Rocks
If you walk down the streets of Serbia's capital, Belgrade, your face will almost certainly be recorded by one of the city's 1,000 Huawei security
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
https://ift.tt/3fiConC
Submitted August 04, 2021 at 07:11PM by TheDFIRReport
via reddit https://ift.tt/3rSUPnY
https://ift.tt/3fiConC
Submitted August 04, 2021 at 07:11PM by TheDFIRReport
via reddit https://ift.tt/3rSUPnY
The DFIR Report
BazarCall to Conti Ransomware via Trickbot and Cobalt Strike
Intro This report will go through an intrusion that went from an Excel file to domain wide ransomware. The threat actors used BazarCall to install Trickbot in the environment which downloaded and e…
Ubuntu's Snapcraft Packages Come With Extra Baggage: CVE-2020-27348
https://ift.tt/3yrhAls
Submitted August 04, 2021 at 09:02PM by gaasedelen
via reddit https://ift.tt/3rX1ii2
https://ift.tt/3yrhAls
Submitted August 04, 2021 at 09:02PM by gaasedelen
via reddit https://ift.tt/3rX1ii2
RET2 Systems Blog
Snapcraft Packages Come With Extra Baggage
Several months ago I found an issue (now CVE-2020-27348) with Ubuntu’s new package management system, Snapcraft. This bug introduced a classic pattern of ins...
Arbitrary file write in node tar - CVE-2021-32804
https://ift.tt/3il6WqU
Submitted August 04, 2021 at 09:42PM by Photogurt
via reddit https://ift.tt/3fwwEqG
https://ift.tt/3il6WqU
Submitted August 04, 2021 at 09:42PM by Photogurt
via reddit https://ift.tt/3fwwEqG
reddit
Arbitrary file write in node tar - CVE-2021-32804
Posted in r/netsec by u/Photogurt • 2 points and 1 comment
Hotcobalt - New Cobalt Strike DoS Vulnerability That Lets You Halt Operations - SentinelLabs
https://ift.tt/37gGSHc
Submitted August 04, 2021 at 08:08PM by digicat
via reddit https://ift.tt/3lwsrXC
https://ift.tt/37gGSHc
Submitted August 04, 2021 at 08:08PM by digicat
via reddit https://ift.tt/3lwsrXC
SentinelOne
Hotcobalt - New Cobalt Strike DoS Vulnerability That Lets You Halt Operations - SentinelLabs
CVE-2021-36798 is a vulnerability in Cobalt Strike server that could allow victims to register a fake Beacon and DoS attackers.
Possible security issue involving the Firebase JWT library for PHP (Algorithm Confusion with Key IDs)
https://ift.tt/3jo2VkD
Submitted August 04, 2021 at 11:02PM by paragon_init
via reddit https://ift.tt/3Cji3sa
https://ift.tt/3jo2VkD
Submitted August 04, 2021 at 11:02PM by paragon_init
via reddit https://ift.tt/3Cji3sa
GitHub
Possibility of Reintroducing HS256/RSA256 Type Confusion · Issue #351 · firebase/php-jwt
This is a follow-up to the HS256/RS256 Type Confusion attack against the JWT protocol. Now, firebase/php-jwt attempts to side-step this risk by forcing the user to hard-code the algorithms they wis...
Playing with PuTTY
https://ift.tt/3jfvukh
Submitted August 05, 2021 at 12:02AM by 0xdea
via reddit https://ift.tt/3io6CI7
https://ift.tt/3jfvukh
Submitted August 05, 2021 at 12:02AM by 0xdea
via reddit https://ift.tt/3io6CI7
Facebook SSRF
https://ift.tt/37aU9Rq
Submitted August 05, 2021 at 12:21AM by mangojangofett
via reddit https://ift.tt/3jlMm9g
https://ift.tt/37aU9Rq
Submitted August 05, 2021 at 12:21AM by mangojangofett
via reddit https://ift.tt/3jlMm9g
There aren't the access_tokens you're looking for
Facebook SSRF - There aren't the access_tokens you're looking for
Facebook Server Side Request Forgery (SSRF)The following could have given the ability to make arbitrary HTTP requests to servers within Facebook’s production network Facebook SSRF via /me/personas There exists a SSRF in the graph.facebook.com/me/personas…
Exploring the SameSite cookie attribute for preventing CSRF
https://ift.tt/37gajcv
Submitted August 05, 2021 at 04:19AM by ScottContini
via reddit https://ift.tt/3A8Rt3i
https://ift.tt/37gajcv
Submitted August 05, 2021 at 04:19AM by ScottContini
via reddit https://ift.tt/3A8Rt3i
simonwillison.net
Exploring the SameSite cookie attribute for preventing CSRF
In reading Yan Zhu’s excellent write-up of the JSON CSRF vulnerability she found in OkCupid one thing puzzled me: I was under the impression that browsers these days default to …
How to Create Unlimited Rotating Proxies in AWS
https://ift.tt/3kfTNhA
Submitted August 05, 2021 at 05:07AM by AlexandriaLazos
via reddit https://ift.tt/2Vg1BZn
https://ift.tt/3kfTNhA
Submitted August 05, 2021 at 05:07AM by AlexandriaLazos
via reddit https://ift.tt/2Vg1BZn
Medium
How to Create Unlimited Rotating IP Addresses with AWS
We can increase our capabilities to distribute our HTTP requests over a larger and larger pool of networks.
GitHub - GhostPack/ForgeCert: "Golden" certificates
https://ift.tt/2TXBiXa
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3Aamnbx
https://ift.tt/2TXBiXa
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3Aamnbx
GitHub
GitHub - GhostPack/ForgeCert: "Golden" certificates
"Golden" certificates. Contribute to GhostPack/ForgeCert development by creating an account on GitHub.
GitHub - GhostPack/Certify: Active Directory certificate abuse.
https://ift.tt/3fxf8Tj
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3xqypvq
https://ift.tt/3fxf8Tj
Submitted August 05, 2021 at 07:17AM by mubix
via reddit https://ift.tt/3xqypvq
GitHub
GitHub - GhostPack/Certify: Active Directory certificate abuse.
Active Directory certificate abuse. Contribute to GhostPack/Certify development by creating an account on GitHub.