CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on everything
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
https://ift.tt/3qvxOsQ
Submitted November 12, 2021 at 03:19AM by Mydadpicksthefruit
via reddit https://ift.tt/3qukl4h
reddit
CVE-2002-20001 - disable Diffie-Hellman (DHE) key exchange on...
A community for technical news and discussion of information security and closely related topics.
Scanning Millions Of Publicly Exposed Docker Containers - Thousands Of Secrets Leaked
https://ift.tt/3CaYq4m
Submitted November 12, 2021 at 12:22PM by redhuntlabs
via reddit https://ift.tt/3Fcy1oC
https://ift.tt/3CaYq4m
Submitted November 12, 2021 at 12:22PM by redhuntlabs
via reddit https://ift.tt/3Fcy1oC
RedHunt Labs
Scanning Millions Of Publicly Exposed Docker Containers - Thousands Of Secrets Leaked (Wave 5) - RedHunt Labs
Docker is a popular tool that has become synonymous with containers. Docker can build images and run containers. The tool also allows its users to upload their docker images to Docker Hub - the container image registry from Docker Inc. that helps share images.…
Practical attacks against attribute-based encryption
https://ift.tt/3c3YLLF
Submitted November 12, 2021 at 07:47PM by tmlxs
via reddit https://ift.tt/3omGzTp
https://ift.tt/3c3YLLF
Submitted November 12, 2021 at 07:47PM by tmlxs
via reddit https://ift.tt/3omGzTp
Kudelski Security Research
Practical attacks against attribute-based encryption
This week at Black Hat Europe 2021, Marloes Venema (Radboud University Nijmegen) and me, presented our work on attacking attribute-based encryption implementations: Attribute-based encryption Attri…
New Threat Alert: Krane Malware
https://ift.tt/3C42Jys
Submitted November 12, 2021 at 06:58PM by kernelv0id
via reddit https://ift.tt/3F9sE9R
https://ift.tt/3C42Jys
Submitted November 12, 2021 at 06:58PM by kernelv0id
via reddit https://ift.tt/3F9sE9R
CUJO AI
New Threat Alert: Krane Malware
The discovery and analysis of a new threat: Krane malware – a cryptominer botnet that has the ability to spread laterally.
Spear Phishing And Subdomains Takeover
https://ift.tt/3C8gtIn
Submitted November 12, 2021 at 09:08PM by banginpadr
via reddit https://ift.tt/3H9IyTs
https://ift.tt/3C8gtIn
Submitted November 12, 2021 at 09:08PM by banginpadr
via reddit https://ift.tt/3H9IyTs
Medium
Spear Phishing And Subdomains Takeover
Familiarity is what makes spear phishing attacks successful.
TP-Link TLWR840N V5 EU router - Remote Code execution
https://ift.tt/3wEzRM2
Submitted November 12, 2021 at 10:45PM by k4m1ll0
via reddit https://ift.tt/3F27iv8
https://ift.tt/3wEzRM2
Submitted November 12, 2021 at 10:45PM by k4m1ll0
via reddit https://ift.tt/3F27iv8
K4M1Ll0
TP-Link TL-WR840N V5(EU) - RCE - CVE-2021-41653
exploit
RCE chain using Rails Active Storage XSS + ElectronJs Misconfigurations
https://ift.tt/3qMwAJZ
Submitted November 12, 2021 at 12:04AM by nibblesec
via reddit https://ift.tt/2YJRduC
https://ift.tt/3qMwAJZ
Submitted November 12, 2021 at 12:04AM by nibblesec
via reddit https://ift.tt/2YJRduC
fee - Execute ELF binaries without dropping files on disk
https://ift.tt/3qsvWky
Submitted November 13, 2021 at 12:43AM by crower
via reddit https://ift.tt/3wKoAKb
https://ift.tt/3qsvWky
Submitted November 13, 2021 at 12:43AM by crower
via reddit https://ift.tt/3wKoAKb
GitHub
GitHub - nnsee/fileless-elf-exec: Execute ELF files without dropping them on disk
Execute ELF files without dropping them on disk. Contribute to nnsee/fileless-elf-exec development by creating an account on GitHub.
[OPEN FOR 72HRS ONLY] - Private hacking / 0day dev / bug bounty community (Discord<->IRC bridge)
https://ift.tt/3DcS06e
Submitted November 13, 2021 at 05:02AM by 0x0MLT
via reddit https://ift.tt/3DcpuSh
https://ift.tt/3DcS06e
Submitted November 13, 2021 at 05:02AM by 0x0MLT
via reddit https://ift.tt/3DcpuSh
Discord
Discord - A New Way to Chat with Friends & Communities
Discord is the easiest way to communicate over voice, video, and text. Chat, hang out, and stay close with your friends and communities.
Israel Is Hacking the Phones of Palestinian NGOs and Palestinian Authority Officials
https://ift.tt/3cb17bC
Submitted November 14, 2021 at 04:43AM by richards1052
via reddit https://ift.tt/3FiqmFD
https://ift.tt/3cb17bC
Submitted November 14, 2021 at 04:43AM by richards1052
via reddit https://ift.tt/3FiqmFD
Jacobinmag
Israel Is Hacking the Phones of Palestinian NGOs
Israel has been caught hacking the phones of six Palestinian human rights staffers. It’s the latest incident in Israel’s larger web of blatantly undemocratic mass surveillance practices.
Exploiting CSP in Webkit to Break Authentication & Authorization
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 10:41AM by 1lastBr3ath
via reddit https://ift.tt/3ndVUGw
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 10:41AM by 1lastBr3ath
via reddit https://ift.tt/3ndVUGw
threatnix.io
Exploiting CSP in Webkit to Break Authentication & Authorization
This blog post will discuss our findings that we presented in our Blackhat Europe talk noscriptd "Exploiting CSP in Webkit to break Authentication/Authorization", a vulnerability that enabled us to takeover user accounts on most of the web applications out thereby…
Exploiting CSP in Webkit to Break Authentication & Authorization
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 04:20PM by antfigunio
via reddit https://ift.tt/3caABzm
https://ift.tt/3C7WGZK
Submitted November 14, 2021 at 04:20PM by antfigunio
via reddit https://ift.tt/3caABzm
threatnix.io
Exploiting CSP in Webkit to Break Authentication & Authorization
This blog post will discuss our findings that we presented in our Blackhat Europe talk noscriptd "Exploiting CSP in Webkit to break Authentication/Authorization", a vulnerability that enabled us to takeover user accounts on most of the web applications out thereby…
Revealing LAMBERTS/LONGHORN Malware Capabilities using a step-by-step approach
https://ift.tt/3wGCgpI
Submitted November 14, 2021 at 07:50PM by CyberMasterV
via reddit https://ift.tt/3Dinmbs
https://ift.tt/3wGCgpI
Submitted November 14, 2021 at 07:50PM by CyberMasterV
via reddit https://ift.tt/3Dinmbs
reddit
Revealing LAMBERTS/LONGHORN Malware Capabilities using a...
Posted in r/netsec by u/CyberMasterV • 26 points and 6 comments
Living Off Trusted Sites (LOTS) Project Attackers are using popular legitimate domains when conducting phishing, C&C, exfiltration and downloading tools to evade detection. The list of websites below allow attackers to use their domain or subdomain
https://ift.tt/3CjV52V
Submitted November 14, 2021 at 11:29PM by digicat
via reddit https://ift.tt/3orBhpI
https://ift.tt/3CjV52V
Submitted November 14, 2021 at 11:29PM by digicat
via reddit https://ift.tt/3orBhpI
reddit
Living Off Trusted Sites (LOTS) Project Attackers are using...
Posted in r/netsec by u/digicat • 153 points and 14 comments
RCE in Concrete CMS by exploiting a double race condition (and some php tricks)
https://ift.tt/31Sf5gE
Submitted November 15, 2021 at 12:54PM by adrian_rt
via reddit https://ift.tt/31Sfj7u
https://ift.tt/31Sf5gE
Submitted November 15, 2021 at 12:54PM by adrian_rt
via reddit https://ift.tt/31Sfj7u
Cyber Security Services - London
Multiple Concrete CMS vulnerabilities ( part1 - RCE )
Multiple vulnerabilities in concrete cms. File upload, double race condition, RCE, turbo intruder.
Running a WiFi-less Home Network: Security Paranoid Edition
https://ift.tt/3DmrzLA
Submitted November 15, 2021 at 06:46PM by Robbedoes_
via reddit https://ift.tt/3FeVW79
https://ift.tt/3DmrzLA
Submitted November 15, 2021 at 06:46PM by Robbedoes_
via reddit https://ift.tt/3FeVW79
Medium
Running a WiFi-less Home Network: Security Paranoid Edition
And a few reason why you should consider it.
Exchange Exploit Leads to Domain Wide Ransomware
https://ift.tt/3wLCEDb
Submitted November 15, 2021 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/3HmOIjk
https://ift.tt/3wLCEDb
Submitted November 15, 2021 at 05:54PM by TheDFIRReport
via reddit https://ift.tt/3HmOIjk
The DFIR Report
Exchange Exploit Leads to Domain Wide Ransomware
In late September 2021, we observed an intrusion in which initial access was gained by the threat actor exploiting multiple vulnerabilities in Microsoft Exchange. The threat actors in this case wer…
T-Reqs: HTTP Request Smuggling with Differential Fuzzing
https://ift.tt/30wbXqv
Submitted November 15, 2021 at 07:52PM by albinowax
via reddit https://ift.tt/3qIuSZQ
https://ift.tt/30wbXqv
Submitted November 15, 2021 at 07:52PM by albinowax
via reddit https://ift.tt/3qIuSZQ
Domain Persistence - Golden Certificate
https://ift.tt/3HmxUJa
Submitted November 15, 2021 at 09:49PM by netbiosX
via reddit https://ift.tt/3oz3YAO
https://ift.tt/3HmxUJa
Submitted November 15, 2021 at 09:49PM by netbiosX
via reddit https://ift.tt/3oz3YAO
Penetration Testing Lab
Golden Certificate
Domain persistence techniques enable red teams that have compromised the domain to operate with the highest level of privileges in a large period. One of the most common domain persistence techniqu…
Blacksmith – Rowhammer is back on DDR4
https://ift.tt/3qEUZRn
Submitted November 15, 2021 at 09:37PM by braincrowd
via reddit https://ift.tt/3kGp0wy
https://ift.tt/3qEUZRn
Submitted November 15, 2021 at 09:37PM by braincrowd
via reddit https://ift.tt/3kGp0wy
reddit
Blacksmith – Rowhammer is back on DDR4
Posted in r/netsec by u/braincrowd • 1 point and 0 comments
Taking the pain out of C2 infrastructure (Part 2)
https://ift.tt/3DnqN0A
Submitted November 16, 2021 at 12:15AM by scopedsecurity
via reddit https://ift.tt/3ngNyO7
https://ift.tt/3DnqN0A
Submitted November 16, 2021 at 12:15AM by scopedsecurity
via reddit https://ift.tt/3ngNyO7
Substack
Taking the pain out of C2 infrastructure (Part 2)
Modernizing the CIA's operational infrastructure. Multi/Hybrid Cloud Docker Swarm clusters and mesh VPN networks 🐿