BruteShark Version V1.2.5 Released: Identify open ports, domains and users simply by entering PCAP files. Export it to JSON with few clicks :-)
https://ift.tt/2WwZ39Q
Submitted October 01, 2021 at 05:10AM by BruteShark
via reddit https://ift.tt/3kVzfxi
https://ift.tt/2WwZ39Q
Submitted October 01, 2021 at 05:10AM by BruteShark
via reddit https://ift.tt/3kVzfxi
GitHub
Release Network Map Supports Domain Users And Data Transferred Amounts · odedshimon/BruteShark
This version contains few improvements and features:
First, the network map had upgraded by adding additional fields that enables to get insights about domain users and the amount of data transferr...
First, the network map had upgraded by adding additional fields that enables to get insights about domain users and the amount of data transferr...
SNIF ~ e2e TLS trust for IoT
https://snif.host
Submitted October 01, 2021 at 08:31AM by vesvault
via reddit https://ift.tt/2ZCFXjC
https://snif.host
Submitted October 01, 2021 at 08:31AM by vesvault
via reddit https://ift.tt/2ZCFXjC
reddit
SNIF ~ e2e TLS trust for IoT
Posted in r/netsec by u/vesvault • 1 point and 0 comments
DigitalOcean Hacktoberfest 2021
https://ift.tt/372IQee
Submitted October 01, 2021 at 12:26PM by keybeebig
via reddit https://ift.tt/3mbZ3VC
https://ift.tt/372IQee
Submitted October 01, 2021 at 12:26PM by keybeebig
via reddit https://ift.tt/3mbZ3VC
Hacktoberfest presented by DigitalOcean
Hacktoberfest '21
Drive-By Compromise: A Tale Of Four WiFi Routers
https://ift.tt/3B3O5Yc
Submitted October 01, 2021 at 05:48PM by IncludeSec
via reddit https://ift.tt/3AZNeYN
https://ift.tt/3B3O5Yc
Submitted October 01, 2021 at 05:48PM by IncludeSec
via reddit https://ift.tt/3AZNeYN
Include Security Research Blog
Drive-By Compromise: A Tale Of Four WiFi Routers - Include Security Research Blog
Determining the overall security posture of consumer electronics is an exceedingly hard task. In this post, we analyze four 'budget' devices.
WebGoat is a deliberately insecure application
https://ift.tt/1BjjBRy
Submitted October 02, 2021 at 09:19PM by binaryfor
via reddit https://ift.tt/2Wxv7u4
https://ift.tt/1BjjBRy
Submitted October 02, 2021 at 09:19PM by binaryfor
via reddit https://ift.tt/2Wxv7u4
GitHub
GitHub - WebGoat/WebGoat: WebGoat is a deliberately insecure application
WebGoat is a deliberately insecure application. Contribute to WebGoat/WebGoat development by creating an account on GitHub.
DroneSploit – A pentesting console framework dedicated to drones
https://ift.tt/36rpmgL
Submitted October 02, 2021 at 09:16PM by binaryfor
via reddit https://ift.tt/3osLymY
https://ift.tt/36rpmgL
Submitted October 02, 2021 at 09:16PM by binaryfor
via reddit https://ift.tt/3osLymY
GitHub
GitHub - dhondta/dronesploit: Drone pentesting framework console
Drone pentesting framework console. Contribute to dhondta/dronesploit development by creating an account on GitHub.
Alan post-exploitation framework v4.0 released
https://ift.tt/2Y4OAml
Submitted October 01, 2021 at 01:04PM by aparata_s4tan
via reddit https://ift.tt/3iqUbeb
https://ift.tt/2Y4OAml
Submitted October 01, 2021 at 01:04PM by aparata_s4tan
via reddit https://ift.tt/3iqUbeb
Blogspot
Alan post-exploitation framework v4.0 released
Twitter: @s4tan Download: GitHub Documentation: https://github.com/enkomio/AlanFramework/tree/main/doc I just released version 4...
The discovery of Gatekeeper bypass CVE-2021-1810
https://ift.tt/3mkUKHx
Submitted October 03, 2021 at 12:10PM by 0xdea
via reddit https://ift.tt/3ioCr2U
https://ift.tt/3mkUKHx
Submitted October 03, 2021 at 12:10PM by 0xdea
via reddit https://ift.tt/3ioCr2U
Authentication Encounter: OIDC vs OAuth2
https://ift.tt/2Wz30e0
Submitted October 03, 2021 at 12:56PM by prescojan
via reddit https://ift.tt/3l2Migw
https://ift.tt/2Wz30e0
Submitted October 03, 2021 at 12:56PM by prescojan
via reddit https://ift.tt/3l2Migw
Frontegg
Authentication Encounter: OIDC vs OAuth2 | Frontegg
Not sure about the winner in the OIDC vs OAuth2 encounter? We’ve got you covered with this detailed authentication comparison.
Working with the sales team during my consulting days was eye opening. In this edition, I argue that there are many lessons AppSec teams can learn from how Sales teams operate.
https://ift.tt/3mnNKcM
Submitted October 03, 2021 at 05:05PM by jubbaonjeans
via reddit https://ift.tt/3oySUpj
https://ift.tt/3mnNKcM
Submitted October 03, 2021 at 05:05PM by jubbaonjeans
via reddit https://ift.tt/3oySUpj
Substack
Edition 10: Selling AppSec
In AppSec, most Security controls are implemented by folks outside the Security team. You cannot improve your AppSec posture, without "selling" the virtue of AppSec to your stakeholders.
Conditionally-Perfect Secrecy and a Provably-Secure Randomized Cipher [PDF]
https://ift.tt/3a8qyJL
Submitted October 03, 2021 at 07:34PM by Uberhipster
via reddit https://ift.tt/3mjEOVN
https://ift.tt/3a8qyJL
Submitted October 03, 2021 at 07:34PM by Uberhipster
via reddit https://ift.tt/3mjEOVN
Undectable backdooring of PE file using dual code caves & encoding
https://ift.tt/3a614Nn
Submitted October 04, 2021 at 02:46AM by InformationSecurity
via reddit https://ift.tt/2YeVy8X
https://ift.tt/3a614Nn
Submitted October 04, 2021 at 02:46AM by InformationSecurity
via reddit https://ift.tt/2YeVy8X
Haider Mahmood Infosec Blog
undetectable backdooring PE file
backdooring exe files, backdooring PE file, backdoor windows executable, fully undetectable backdoor, encoding shellcode, FUD,codecaves,
/r/netsec's Q4 2021 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 04, 2021 at 02:39AM by ranok
via reddit https://ift.tt/3FfhFfV
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted October 04, 2021 at 02:39AM by ranok
via reddit https://ift.tt/3FfhFfV
BazarLoader and the Conti Leaks
https://ift.tt/2ZVucVJ
Submitted October 04, 2021 at 07:07AM by TheDFIRReport
via reddit https://ift.tt/3l61eue
https://ift.tt/2ZVucVJ
Submitted October 04, 2021 at 07:07AM by TheDFIRReport
via reddit https://ift.tt/3l61eue
The DFIR Report
BazarLoader and the Conti Leaks
Intro In July, we observed an intrusion that started from a BazarLoader infection and lasted approximately three days. The threat actor’s main priority was to map the domain network, while lo…
OnionShare 2.3 >= 2.3.3 Vulnerabilities (CVE-2021-41868 and CVE-2021-41867)
https://ift.tt/3a1o53N
Submitted October 04, 2021 at 02:29PM by IHTeam
via reddit https://ift.tt/3uKnSf1
https://ift.tt/3a1o53N
Submitted October 04, 2021 at 02:29PM by IHTeam
via reddit https://ift.tt/3uKnSf1
Misconfigured Airflows Leak Credentials from Popular Services
https://ift.tt/3uCAwN0
Submitted October 04, 2021 at 08:43PM by Milafasents
via reddit https://ift.tt/3FdScn7
https://ift.tt/3uCAwN0
Submitted October 04, 2021 at 08:43PM by Milafasents
via reddit https://ift.tt/3FdScn7
Intezer
Misconfigured Airflows Leak Thousands of Credentials from Popular Services
Apache Airflow is the #1 starred open-source workflows application on GitHub.
Implicit Overflow Considered Harmful
https://ift.tt/3A7hPCp
Submitted October 04, 2021 at 08:41PM by pimterry
via reddit https://ift.tt/3a45qV0
https://ift.tt/3A7hPCp
Submitted October 04, 2021 at 08:41PM by pimterry
via reddit https://ift.tt/3a45qV0
Considerations on Codecrafting
Implicit Overflow Considered Harmful (and how to fix it)
A common problem in programming language design is the question of what the type of integral literals should be, and if they are untyped, what the rules for implicitly converting them to regular integer types should be. This is part of the more general problem…
Welcoming Dragonfly, a modern malware sandbox built on binary emulation tools
https://ift.tt/3a3HbGD
Submitted October 04, 2021 at 09:16PM by samaritan_o
via reddit https://ift.tt/3a20ss9
https://ift.tt/3a3HbGD
Submitted October 04, 2021 at 09:16PM by samaritan_o
via reddit https://ift.tt/3a20ss9
Certego
Dragonfly: your next generation malware sandbox
Certego has always been strongly involved in researching new ways to analyze malware. We have been working for some time on new projects aimed to...
List of public BGP hijacking incidents
https://ift.tt/3oyTYt8
Submitted October 04, 2021 at 10:16PM by dontbenebby
via reddit https://ift.tt/3AafVRl
https://ift.tt/3oyTYt8
Submitted October 04, 2021 at 10:16PM by dontbenebby
via reddit https://ift.tt/3AafVRl
Wikipedia
BGP hijacking
attack on Internet routing infrastructure
Now that whatsapp is down, it is a good time to get people to try signal out :)
https://ift.tt/2z1sLG4
Submitted October 04, 2021 at 11:53PM by abagnalejr
via reddit https://ift.tt/3otSwbu
https://ift.tt/2z1sLG4
Submitted October 04, 2021 at 11:53PM by abagnalejr
via reddit https://ift.tt/3otSwbu
Signal Messenger
Download Signal
Download Signal for Android, iOS, Linux, macOS, and Windows.
Atom Silo ransomware actors use Confluence exploit, DLL side-load for stealthy attack
https://ift.tt/3l7MIlI
Submitted October 05, 2021 at 01:49AM by ksr_malware
via reddit https://ift.tt/3DcrGIZ
https://ift.tt/3l7MIlI
Submitted October 05, 2021 at 01:49AM by ksr_malware
via reddit https://ift.tt/3DcrGIZ
Sophos News
Atom Silo ransomware actors use Confluence exploit, DLL side-load for stealthy attack
A new ransomware operator uses stealthy techniques, but borrows heavily from other players.