Business Logic Ratings Bug
https://ift.tt/3jc8Dr8
Submitted August 25, 2021 at 06:22PM by mdulin2
via reddit https://ift.tt/38eMkKZ
https://ift.tt/3jc8Dr8
Submitted August 25, 2021 at 06:22PM by mdulin2
via reddit https://ift.tt/38eMkKZ
reddit
Business Logic Ratings Bug
Posted in r/netsec by u/mdulin2 • 8 points and 0 comments
Vulnerability in Bumble dating app reveals any user's exact location
https://ift.tt/3Bd3Coe
Submitted August 25, 2021 at 07:11PM by businesstrout
via reddit https://ift.tt/3Dh382d
https://ift.tt/3Bd3Coe
Submitted August 25, 2021 at 07:11PM by businesstrout
via reddit https://ift.tt/3Dh382d
Robert Heaton
Vulnerability in Bumble dating app reveals any user's exact location | Robert Heaton
The vulnerability in this post is real. The story and characters are obviously not.
ghidra2frida - The new bridge between Ghidra and Frida
https://ift.tt/3sYKJTr
Submitted August 25, 2021 at 07:53PM by 0xdea
via reddit https://ift.tt/3mtagCR
https://ift.tt/3sYKJTr
Submitted August 25, 2021 at 07:53PM by 0xdea
via reddit https://ift.tt/3mtagCR
hn security
ghidra2frida - The new bridge between Ghidra and Frida - hn security
Hi! Today I’m publishing a new […]
Issues with Indefinite Trust in Bluetooth - Include Security Research Blog
https://ift.tt/3zicTei
Submitted August 25, 2021 at 08:19PM by IncludeSec
via reddit https://ift.tt/38c2WmD
https://ift.tt/3zicTei
Submitted August 25, 2021 at 08:19PM by IncludeSec
via reddit https://ift.tt/38c2WmD
Include Security Research Blog
Issues with Indefinite Trust in Bluetooth - Include Security Research Blog
At IncludeSec we of course love to hack things, but we also love to use our skills and insights into security issues to explore innovative solutions, develop tools, and share resources. In this post we share a summary of a recent paper that I published with…
Meeting the new Executive Order requirements with Azure Security
https://ift.tt/3ko2wiS
Submitted August 26, 2021 at 01:11AM by SCI_Rusher
via reddit https://ift.tt/3mDHNdL
https://ift.tt/3ko2wiS
Submitted August 26, 2021 at 01:11AM by SCI_Rusher
via reddit https://ift.tt/3mDHNdL
TECHCOMMUNITY.MICROSOFT.COM
Meeting the Cybersecurity Executive Order requirements with Azure Security
In May 2021, the Biden Administration signed Executive Order (EO) 14028, placing cloud security at the forefront of national security. Federal agencies are at different stages in their digital transformations yet are all facing similar challenges: rapidly…
The Evolution of a Magecart Attack Leveraging the Recaptcha.tech Domain
https://ift.tt/3DkAI7K
Submitted August 26, 2021 at 02:25AM by amirshk
via reddit https://ift.tt/3jhcVxv
https://ift.tt/3DkAI7K
Submitted August 26, 2021 at 02:25AM by amirshk
via reddit https://ift.tt/3jhcVxv
PerimeterX
The Evolution of a Magecart Attack Leveraging the Recaptcha.tech Domain
PerimeterX Cybersecurity Researcher Ben Baryo discovered a skimmer served from recaptcha[.]tech and examined its progression over the course of two years.
Glowworm Attack - Optical TEMPEST Sound Recovery via a Device’s Power Indicator LED
https://ift.tt/2VIQx70
Submitted August 26, 2021 at 06:17AM by Gallus
via reddit https://ift.tt/38eHlu4
https://ift.tt/2VIQx70
Submitted August 26, 2021 at 06:17AM by Gallus
via reddit https://ift.tt/38eHlu4
Ben Nassi
Glowworm-Attack
In this paper, we identify a new class of optical TEMPEST attacks: recovering sound by analyzing optical emanations from a device’s power indicator LED. We analyze the response of the power indicator LED of various devices to sound and show that there is…
dmesg – Unix/Linux command, beginners introduction with examples
https://ift.tt/3Ab6vpR
Submitted August 26, 2021 at 10:06AM by mike_jack
via reddit https://ift.tt/3sOYRhL
https://ift.tt/3Ab6vpR
Submitted August 26, 2021 at 10:06AM by mike_jack
via reddit https://ift.tt/3sOYRhL
yCrash
dmesg – Unix/Linux command, beginners introduction with examples
‘dmesg’ (display message) is not a popular Unix/Linux command. However, it provides vital information that can be used for troubleshooting production performance problems.
Widespread credential phishing campaign abuses open redirector links
https://ift.tt/3zlP7y2
Submitted August 26, 2021 at 11:26PM by SCI_Rusher
via reddit https://ift.tt/2XVd4yh
https://ift.tt/3zlP7y2
Submitted August 26, 2021 at 11:26PM by SCI_Rusher
via reddit https://ift.tt/2XVd4yh
Search - Microsoft Bing
Where cultures converge
The Mosque-Cathedral of Córdoba is a chronicle of
Attack Surface Management. You’re (probably) doing it wrong.
https://ift.tt/2WvAlXl
Submitted August 27, 2021 at 01:32AM by smicallef
via reddit https://ift.tt/2Wu0LbN
https://ift.tt/2WvAlXl
Submitted August 27, 2021 at 01:32AM by smicallef
via reddit https://ift.tt/2Wu0LbN
Medium
Attack Surface Management. You’re (probably) doing it wrong.
In this post I talk about what it means to perform comprehensive Attack Surface Management by leveraging a broad spectrum of OSINT (Open…
ChaosDB - Vulnerability in Azure Cosmos DB affecting thousands of customers - Manual Actions Required
https://chaosdb.wiz.io/
Submitted August 27, 2021 at 05:27AM by sagitz_
via reddit https://ift.tt/3DmkSJK
https://chaosdb.wiz.io/
Submitted August 27, 2021 at 05:27AM by sagitz_
via reddit https://ift.tt/3DmkSJK
Wiz
ChaosDB: Unauthorized Privileged Access to Microsoft Azure Cosmos DB
A critical vulnerability in Azure's flagship Cosmos DB service affecting thousands of customers. Mitigation requires customers' manual actions.
Risky Business: Why CS Risk is Never Worth the Price
https://ift.tt/3ymi3EX
Submitted August 27, 2021 at 07:07AM by SnooSongs2448
via reddit https://ift.tt/3ykNJum
https://ift.tt/3ymi3EX
Submitted August 27, 2021 at 07:07AM by SnooSongs2448
via reddit https://ift.tt/3ykNJum
STACS - YARA based static credential scanner which supports binary file formats, and nested archives.
https://ift.tt/3Bi1ADC
Submitted August 27, 2021 at 02:20PM by Darkarnium
via reddit https://ift.tt/3sRbMQa
https://ift.tt/3Bi1ADC
Submitted August 27, 2021 at 02:20PM by Darkarnium
via reddit https://ift.tt/3sRbMQa
GitHub
GitHub - stacscan/stacs: Static Token And Credential Scanner
Static Token And Credential Scanner. Contribute to stacscan/stacs development by creating an account on GitHub.
Enhancing the security audit logging of Harbor with OpenResty
https://ift.tt/2WykLdi
Submitted August 27, 2021 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/3kxlEea
https://ift.tt/2WykLdi
Submitted August 27, 2021 at 04:58PM by Rewanth_Tammana
via reddit https://ift.tt/3kxlEea
Rewanth Tammana's Blog
Enhancing the security audit logging of Harbor with OpenResty
Enhancing the security audit logging of Harbor with OpenResty - Why and how I achieved the audit logging functionality in Harbor Private Container Registry
Fuzzing Windows’ RDP client and server
https://ift.tt/3DmMaQ2
Submitted August 27, 2021 at 06:28PM by jat0369
via reddit https://ift.tt/3kpirxk
https://ift.tt/3DmMaQ2
Submitted August 27, 2021 at 06:28PM by jat0369
via reddit https://ift.tt/3kpirxk
Cyberark
Fuzzing RDP: Holding the Stick at Both Ends
Introduction This post describes the work we’ve done on fuzzing the Windows RDP client and server, the challenges of doing so, and some of the results. The Remote Desktop Protocol (RDP) by...
Crypto miner attack: Sysrv-Hello Botnet targeting WordPress pods for crypto mining
https://ift.tt/2UTwToH
Submitted August 27, 2021 at 08:23PM by capitangolo
via reddit https://ift.tt/3ymjVgW
https://ift.tt/2UTwToH
Submitted August 27, 2021 at 08:23PM by capitangolo
via reddit https://ift.tt/3ymjVgW
AWS ReadOnlyAccess: Not Even Once
https://ift.tt/2WqXGJi
Submitted August 27, 2021 at 08:53PM by hotnops
via reddit https://ift.tt/2XTjZbe
https://ift.tt/2WqXGJi
Submitted August 27, 2021 at 08:53PM by hotnops
via reddit https://ift.tt/2XTjZbe
Medium
AWS ReadOnlyAccess: Not Even Once
A story of too much access and a false sense of security.
Everything you need to know about Pegasus Spyware
https://ift.tt/3BgxoZd
Submitted August 27, 2021 at 11:15PM by Techflashesinfo
via reddit https://ift.tt/38iUOkl
https://ift.tt/3BgxoZd
Submitted August 27, 2021 at 11:15PM by Techflashesinfo
via reddit https://ift.tt/38iUOkl
techflashes.com
Everything you need to know about Pegasus Spyware techflashes.com
This Pegasus Spyware virus is very dangerous and that spyware multiple ways attacks of that system that saw that article... techflashes.com
Lots of Sec tools unclear about what they mean when they talk about their “masking” & “transformation” features. HashiCorp Vault just made it clear what those terms mean for them.
https://ift.tt/3DklIqs
Submitted August 28, 2021 at 12:22AM by piedpiperpivot
via reddit https://ift.tt/3Ba6D90
https://ift.tt/3DklIqs
Submitted August 28, 2021 at 12:22AM by piedpiperpivot
via reddit https://ift.tt/3Ba6D90
Detecting Potential Bad Actors in OSS Contributions
https://ift.tt/3jkBwBy
Submitted August 28, 2021 at 03:07AM by ambray_
via reddit https://ift.tt/3yrAcRw
https://ift.tt/3jkBwBy
Submitted August 28, 2021 at 03:07AM by ambray_
via reddit https://ift.tt/3yrAcRw
blog.phylum.io
Detecting Potential Bad Actors in GitHub
Phylum is continually working to improve our author risk analysis to allow users to manage the risk presented by using code written by random strangers on the Internet. The work documented here provides valuable evidence as input into Phylum’s author risk…
DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover
https://ift.tt/3DtoedO
Submitted August 28, 2021 at 04:20PM by dwisiswant0
via reddit https://ift.tt/38jFCmW
https://ift.tt/3DtoedO
Submitted August 28, 2021 at 04:20PM by dwisiswant0
via reddit https://ift.tt/38jFCmW
GitHub
GitHub - pwnesia/dnstake: DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover
DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover - GitHub - pwnesia/dnstake: DNSTake — A fast tool to check missing hosted DNS zones that can lead to subd...