http://ift.tt/2zYcVcU
http://ift.tt/2zYcVcU
Submitted October 30, 2017 at 12:26AM by Mysterii8
via reddit http://ift.tt/2yZZN7i
http://ift.tt/2zYcVcU
Submitted October 30, 2017 at 12:26AM by Mysterii8
via reddit http://ift.tt/2yZZN7i
Medium
Short story about S3 bucket, python noscript, thousands of data and Australian Government
TL;DR If there is any list which contains leaks (email — password) from Amazon S3 we can add: 1470 records from AEC (Australian Electoral…
ROCA vulnerability - the full paper available online
ACM has just published the full paper in its Digital Library athttp://ift.tt/2zQqGcYSome interesting charts of the CPU cycles needed for particular key lengths - mostly academical, with the notable exception of 3k keys.The cost of the attack of 2k RSA keys seems to be derived from Amazon EC2 x2 instance (2 cores) - my feeling is that the cost is fairly conservative. GPU-optimized versions are bound to make 2k key cracking quite affordable.
Submitted October 30, 2017 at 09:08PM by dc352
via reddit http://ift.tt/2gMfJlc
ACM has just published the full paper in its Digital Library athttp://ift.tt/2zQqGcYSome interesting charts of the CPU cycles needed for particular key lengths - mostly academical, with the notable exception of 3k keys.The cost of the attack of 2k RSA keys seems to be derived from Amazon EC2 x2 instance (2 cores) - my feeling is that the cost is fairly conservative. GPU-optimized versions are bound to make 2k key cracking quite affordable.
Submitted October 30, 2017 at 09:08PM by dc352
via reddit http://ift.tt/2gMfJlc
reddit
ROCA vulnerability - the full paper available online • r/netsec
ACM has just published the full paper in its Digital Library at...
Introducing GoCrack: A Managed Password Cracking Tool
http://ift.tt/2homgDd
Submitted October 30, 2017 at 08:54PM by Extremite
via reddit http://ift.tt/2ziVPt4
http://ift.tt/2homgDd
Submitted October 30, 2017 at 08:54PM by Extremite
via reddit http://ift.tt/2ziVPt4
FireEye
Introducing GoCrack: A Managed Password Cracking Tool « Threat Research Blog
FireEye's Innovation and Custom Engineering team released a tool called GoCrack that allows red teams to efficiently manage password cracking tasks across multiple GPU servers by providing an easy-to-use, web-based real-time UI to create, view, and manage…
Our computers, ourselves: digital vs. biological security
http://ift.tt/2yUinjd
Submitted October 31, 2017 at 12:05AM by screen317
via reddit http://ift.tt/2ltsyWI
http://ift.tt/2yUinjd
Submitted October 31, 2017 at 12:05AM by screen317
via reddit http://ift.tt/2ltsyWI
Malwarebytes Labs
Our computers, ourselves: digital vs. biological security
How are computer and biological viruses the same? We compare the two, and what we do to fight them—it's digital vs. biological security.
Mozilla Wants to Distrust Dutch HTTPS Provider Because of Local Dystopian Law
http://ift.tt/2zi3qZf
Submitted October 30, 2017 at 11:48PM by DJRWolf
via reddit http://ift.tt/2xAKIHA
http://ift.tt/2zi3qZf
Submitted October 30, 2017 at 11:48PM by DJRWolf
via reddit http://ift.tt/2xAKIHA
BleepingComputer
Mozilla Wants to Distrust Dutch HTTPS Provider Because of Local Dystopian Law
Mozilla engineers are discussing plans to remove support for a state-operated Dutch TLS/HTTPS provider after the Dutch government has voted a new law that grants local authorities the power to intercept Internet communications using "false keys."
A Guide to Attacking Domain Trusts
http://ift.tt/2yZGZoH
Submitted October 31, 2017 at 01:05AM by juken
via reddit http://ift.tt/2yYdg1x
http://ift.tt/2yZGZoH
Submitted October 31, 2017 at 01:05AM by juken
via reddit http://ift.tt/2yYdg1x
Posts By SpecterOps Team Members
A Guide to Attacking Domain Trusts
It’s been a while (nearly 2 years) since I wrote a post purely on Active Directory domain trusts. After diving into group scoping, I realized a few subtle misconceptions I previously had concerning…
Linux Privilege Escalation using weak NFS permissions
http://ift.tt/2iiaWrV
Submitted October 31, 2017 at 02:20AM by InformationSecurity
via reddit http://ift.tt/2ihVax9
http://ift.tt/2iiaWrV
Submitted October 31, 2017 at 02:20AM by InformationSecurity
via reddit http://ift.tt/2ihVax9
Haider Mahmood Infosec Blog
Linux privilege escalation using weak NFS permissions
Linux privilege escalation, lateral movement in linux, Linux Privilege Escalation using weak NFS permissions, linux localroot access, NFS hacking.
A Masscan Tutorial and Primer
http://ift.tt/2gLDVnN
Submitted October 31, 2017 at 02:50AM by danielrm26
via reddit http://ift.tt/2ig7ezf
http://ift.tt/2gLDVnN
Submitted October 31, 2017 at 02:50AM by danielrm26
via reddit http://ift.tt/2ig7ezf
Daniel Miessler
A Masscan Tutorial and Primer
Basics Background Installation Single-port Scans Multi-port Scans Scan Top Ports Options Scanning Fast Excluding Hosts Saving Your Configuration Output Nma
Can someone copy or install files into my laptop using a usb connected phone?
If so, is there a way for me to check for that?
Submitted October 31, 2017 at 04:53AM by Opportunityinrisk
via reddit http://ift.tt/2yY8DVx
If so, is there a way for me to check for that?
Submitted October 31, 2017 at 04:53AM by Opportunityinrisk
via reddit http://ift.tt/2yY8DVx
reddit
Can someone copy or install files into my laptop... • r/security
If so, is there a way for me to check for that?
Oracle Security Alert CVE-2017-10151
http://ift.tt/2xvrvHu
Submitted October 31, 2017 at 05:22AM by bagaudin
via reddit http://ift.tt/2iNoHTo
http://ift.tt/2xvrvHu
Submitted October 31, 2017 at 05:22AM by bagaudin
via reddit http://ift.tt/2iNoHTo
reddit
Oracle Security Alert CVE-2017-10151 • r/security
7 points and 0 comments so far on reddit
Sandbox your applications with Firejail
http://ift.tt/2hmeutt
Submitted October 31, 2017 at 06:38AM by unquietwiki
via reddit http://ift.tt/2z1V2dd
http://ift.tt/2hmeutt
Submitted October 31, 2017 at 06:38AM by unquietwiki
via reddit http://ift.tt/2z1V2dd
reddit
Sandbox your applications with Firejail • r/netsec
14 points and 0 comments so far on reddit
Heathrow Airport launching a probe after a USB was found
http://ift.tt/2lsxtqI
Submitted October 31, 2017 at 07:39AM by securitynewsIO
via reddit http://ift.tt/2zTdcNw
http://ift.tt/2lsxtqI
Submitted October 31, 2017 at 07:39AM by securitynewsIO
via reddit http://ift.tt/2zTdcNw
Protect - a comprehensive home security system from Ring
Ring introduced a comprehensive home security system called Protect to monitor the indoors of houses.
Submitted October 31, 2017 at 12:16PM by CIOBulletin
via reddit http://ift.tt/2iiZWdR
Ring introduced a comprehensive home security system called Protect to monitor the indoors of houses.
Submitted October 31, 2017 at 12:16PM by CIOBulletin
via reddit http://ift.tt/2iiZWdR
reddit
Protect - a comprehensive home security system from Ring • r/security
reddit: the front page of the internet
Blades Power Generation Brings Top-End Emergency Power Generation Units
Blade Power Generation specialises in meeting client demands with optimal emergency power generation. From manual and automatic transfer switches to used/new generator units, the company always maintains the British Standards in each of their exclusive offerings. They supply their power generation units for both personal homes and corporate offices. Plus, they cater to the extra security needs of large scale establishments.
Submitted October 31, 2017 at 11:48AM by bladespower
via reddit http://ift.tt/2gPnhn1
Blade Power Generation specialises in meeting client demands with optimal emergency power generation. From manual and automatic transfer switches to used/new generator units, the company always maintains the British Standards in each of their exclusive offerings. They supply their power generation units for both personal homes and corporate offices. Plus, they cater to the extra security needs of large scale establishments.
Submitted October 31, 2017 at 11:48AM by bladespower
via reddit http://ift.tt/2gPnhn1
reddit
Blades Power Generation Brings Top-End Emergency... • r/security
Blade Power Generation specialises in meeting client demands with optimal emergency power generation. From manual and automatic transfer switches...
Firefox takes a bite out of the canvas ‘super cookie’
http://ift.tt/2zgIIsx
Submitted October 31, 2017 at 12:39PM by wfpoulet
via reddit http://ift.tt/2hrk3al
http://ift.tt/2zgIIsx
Submitted October 31, 2017 at 12:39PM by wfpoulet
via reddit http://ift.tt/2hrk3al
Naked Security
Firefox takes a bite out of the canvas ‘super cookie’
Finally, one of the major browsers is doing something about canvas fingerprinting
Cybersecurity: Internet security 101: Six ways hackers can attack you and how to stay safe
http://ift.tt/2gUatj2
Submitted October 31, 2017 at 01:21PM by davidpatter
via reddit http://ift.tt/2A29Etf
http://ift.tt/2gUatj2
Submitted October 31, 2017 at 01:21PM by davidpatter
via reddit http://ift.tt/2A29Etf
The Economic Times
Internet security 101: Six ways hackers can attack you and how to stay safe
While an increasingly connected world makes our lives easier, it also poses great risk as we expose our personal data to cyber criminals or hackers.
A Finger Vibration-based Security System "VibWrite" can work on any Solid Surface
Rutgers engineers have created VibWrite, a smart access system that senses finger vibrations to verify users. The low-cost security system could eventually be used to gain access to homes, apartment buildings, cars, appliances – anything with a solid surface.Everyone’s finger bone structure is unique, and their fingers apply different pressures on surfaces, so sensors that detect subtle physiological and behavioral differences can identify and authenticate a person.The market for smart security access systems is expected to grow rapidly, reaching nearly $10 billion by 2022. Today’s smart security access systems mainly rely on traditional techniques that use intercoms, cameras, cards or fingerprints to authenticate users. But these systems require costly equipment, complex hardware installation and diverse maintenance needs.The goal of VibWrite is to allow user verification when fingers touch any solid surface. VibWrite integrates passcode, behavioral and physiological characteristics. It builds on a touch-sensing technique by using vibration signals. It’s different than traditional, password-based approaches, which validate passwords instead of legitimate users, as well as behavioral biometrics-based solutions, which typically involve touch screens, fingerprint readers or other costly hardware and lead to privacy concerns and “smudge attacks” that trace oily residues on surfaces from fingers.Smart access systems that use fingerprinting and iris-recognition are very secure, but they’re probably more than 10 times as expensive as this new VibWrite system.
Submitted October 31, 2017 at 02:55PM by karthikaag
via reddit http://ift.tt/2zVpp46
Rutgers engineers have created VibWrite, a smart access system that senses finger vibrations to verify users. The low-cost security system could eventually be used to gain access to homes, apartment buildings, cars, appliances – anything with a solid surface.Everyone’s finger bone structure is unique, and their fingers apply different pressures on surfaces, so sensors that detect subtle physiological and behavioral differences can identify and authenticate a person.The market for smart security access systems is expected to grow rapidly, reaching nearly $10 billion by 2022. Today’s smart security access systems mainly rely on traditional techniques that use intercoms, cameras, cards or fingerprints to authenticate users. But these systems require costly equipment, complex hardware installation and diverse maintenance needs.The goal of VibWrite is to allow user verification when fingers touch any solid surface. VibWrite integrates passcode, behavioral and physiological characteristics. It builds on a touch-sensing technique by using vibration signals. It’s different than traditional, password-based approaches, which validate passwords instead of legitimate users, as well as behavioral biometrics-based solutions, which typically involve touch screens, fingerprint readers or other costly hardware and lead to privacy concerns and “smudge attacks” that trace oily residues on surfaces from fingers.Smart access systems that use fingerprinting and iris-recognition are very secure, but they’re probably more than 10 times as expensive as this new VibWrite system.
Submitted October 31, 2017 at 02:55PM by karthikaag
via reddit http://ift.tt/2zVpp46
YouTube
Finger Vibration-based Security System "VibWrite" can work on any Solid Surface
Rutgers engineers have created VibWrite, a smart access system that senses finger vibrations to verify users. The low-cost security system could eventually b...
PDF - ACIDRain: Concurrency-Related Attacks on Database-Backed Web Applications
http://ift.tt/2nmBJar
Submitted October 31, 2017 at 03:10PM by disclosure5
via reddit http://ift.tt/2z4CGKN
http://ift.tt/2nmBJar
Submitted October 31, 2017 at 03:10PM by disclosure5
via reddit http://ift.tt/2z4CGKN
Application Threat Modeling using STRIDE and DREAD
http://ift.tt/2z2vGfq
Submitted October 31, 2017 at 04:23PM by InformationSecurity
via reddit http://ift.tt/2z1gr6a
http://ift.tt/2z2vGfq
Submitted October 31, 2017 at 04:23PM by InformationSecurity
via reddit http://ift.tt/2z1gr6a
Haider Mahmood Infosec Blog
Application Threat Modeling using DREAD and STRIDE
Application Threat Modeling using DREAD and STRIDE, Risk assessment, Application Risk Modeling, risk Modeling, Application risk assessment methodology
Application Threat Modeling using DREAD and STRIDE
http://ift.tt/2z2vGfq
Submitted October 31, 2017 at 04:20PM by InformationSecurity
via reddit http://ift.tt/2hpMO71
http://ift.tt/2z2vGfq
Submitted October 31, 2017 at 04:20PM by InformationSecurity
via reddit http://ift.tt/2hpMO71
Haider Mahmood Infosec Blog
Application Threat Modeling using DREAD and STRIDE
Application Threat Modeling using DREAD and STRIDE, Risk assessment, Application Risk Modeling, risk Modeling, Application risk assessment methodology
Chrome Plugin that automatically checks software vulnerabilities in browsed websites
http://ift.tt/2yPWsaM
Submitted October 31, 2017 at 03:57PM by videns
via reddit http://ift.tt/2z4uRoh
http://ift.tt/2yPWsaM
Submitted October 31, 2017 at 03:57PM by videns
via reddit http://ift.tt/2z4uRoh
Google
Vulners Web Scanner
Tiny vulnerability scanner based on vulners.com vulnerability database. Scan websites while you surf internet!