DigiCert to Acquire Symantec’s Website Security Business and Related PKI Solutions
http://ift.tt/2uXpWDi
Submitted August 03, 2017 at 02:48AM by lurker_mike
via reddit http://ift.tt/2u5oq38
http://ift.tt/2uXpWDi
Submitted August 03, 2017 at 02:48AM by lurker_mike
via reddit http://ift.tt/2u5oq38
HUNT - Data driven web hacking & manual testing (incl. burp ext)
http://ift.tt/2tVCkom
Submitted August 03, 2017 at 04:43AM by QforQ
via reddit http://ift.tt/2vk9E8y
http://ift.tt/2tVCkom
Submitted August 03, 2017 at 04:43AM by QforQ
via reddit http://ift.tt/2vk9E8y
GitHub
bugcrowdlabs/HUNT
Contribute to HUNT development by creating an account on GitHub.
DoS vulnerability in Varnish Cache
http://ift.tt/2u5VO9V
Submitted August 03, 2017 at 06:44AM by svmseric
via reddit http://ift.tt/2faDmX3
http://ift.tt/2u5VO9V
Submitted August 03, 2017 at 06:44AM by svmseric
via reddit http://ift.tt/2faDmX3
reddit
DoS vulnerability in Varnish Cache • r/netsec
1 points and 0 comments so far on reddit
Exploiting Script Injection Flaws in ReactJS Apps
http://ift.tt/2vrkdGd
Submitted August 03, 2017 at 10:34AM by digicat
via reddit http://ift.tt/2vr9TON
http://ift.tt/2vrkdGd
Submitted August 03, 2017 at 10:34AM by digicat
via reddit http://ift.tt/2vr9TON
Medium
Exploiting Script Injection Flaws in ReactJS Apps
ReactJS is a popular JavaScript library for building user interfaces. It enables client-rendered, “rich” web apps that load entirely…
TTP: Bypassing Symantec Email Security.cloud (AKA MessageLabs)
http://ift.tt/2vrqBxd
Submitted August 03, 2017 at 10:26AM by ridingwithnorse
via reddit http://ift.tt/2umnZwr
http://ift.tt/2vrqBxd
Submitted August 03, 2017 at 10:26AM by ridingwithnorse
via reddit http://ift.tt/2umnZwr
Introducing 306 Million Freely Downloadable Pwned Passwords
http://ift.tt/2v1txP1
Submitted August 03, 2017 at 02:39PM by pgl
via reddit http://ift.tt/2wodWbS
http://ift.tt/2v1txP1
Submitted August 03, 2017 at 02:39PM by pgl
via reddit http://ift.tt/2wodWbS
Troy Hunt
Introducing 306 Million Freely Downloadable Pwned Passwords
Edit: The following day, I loaded another set of passwords which has brought this up to 320M. More on why later on. Last week I wrote about Passwords Evolved: Authentication Guidance for the Modern Era with the aim of helping those building services which…
U.S. Senators introduce IoT bill affecting gov. procurement; good-faith research liability protections.
http://ift.tt/2f5WDZr
Submitted August 03, 2017 at 03:09PM by qsilicon
via reddit http://ift.tt/2womjE5
http://ift.tt/2f5WDZr
Submitted August 03, 2017 at 03:09PM by qsilicon
via reddit http://ift.tt/2womjE5
U.S. Senator Mark R. Warner
Senators Introduce Bipartisan Legislation to Improve Cybersecurity of “Internet-of-Things” (IoT) Devices
Bipartisan bill would establish minimum requirements for Internet-connected devices purchased by the federal government
The hackers behind the WannaCry ransomware attack have finally cashed out
http://ift.tt/2faHS85
Submitted August 03, 2017 at 04:44PM by keeferc
via reddit http://ift.tt/2u79O3a
http://ift.tt/2faHS85
Submitted August 03, 2017 at 04:44PM by keeferc
via reddit http://ift.tt/2u79O3a
Quartz
The hackers behind the WannaCry ransomware attack have finally cashed out
Few expected the money would ever move out of the accounts, as they were surely watched by law-enforcement agencies around the world.
A Collision Too-Perfect - Cheeky executables, both MD5 and SHA1 hashes are equal , different run output [CHALLENGE WRITEUP]
http://ift.tt/2tuXd4J
Submitted August 03, 2017 at 05:20PM by dalmoz
via reddit http://ift.tt/2un5U1i
http://ift.tt/2tuXd4J
Submitted August 03, 2017 at 05:20PM by dalmoz
via reddit http://ift.tt/2un5U1i
Hacker Noon
A Collision Too-Perfect
Cheeky executables, both MD5 and SHA1 hashes are equal , different run output (“Eat more hashes” Challenge Write-Up)
Toolkit for capturing MFA logons
http://ift.tt/2vw40jQ
Submitted August 03, 2017 at 05:15PM by disclosure5
via reddit http://ift.tt/2u6OL0I
http://ift.tt/2vw40jQ
Submitted August 03, 2017 at 05:15PM by disclosure5
via reddit http://ift.tt/2u6OL0I
GitHub
technion/3652fa
3652fa - Office 365 MFA capture toolkit
Write-Up: DEFCON 25 Recon Village OSINT CTF
http://ift.tt/2v2Pzkl
Submitted August 03, 2017 at 10:21PM by himanshudas
via reddit http://ift.tt/2waUBeD
http://ift.tt/2v2Pzkl
Submitted August 03, 2017 at 10:21PM by himanshudas
via reddit http://ift.tt/2waUBeD
www.digitalsecurity.fr
Write-Up: DEFCON 25 Recon Village OSINT CTF | Digital Security
This blogpost is a write-up of some online challenges we managed to solve during the DEFCON 25 Recon Village OSINT CTF.
Researcher Who Stopped WannaCry Ransomware Detained in US After DefCon [MalwareTech]
http://ift.tt/2vtds79
Submitted August 03, 2017 at 10:03PM by setcursorpos
via reddit http://ift.tt/2v2PEEE
http://ift.tt/2vtds79
Submitted August 03, 2017 at 10:03PM by setcursorpos
via reddit http://ift.tt/2v2PEEE
Motherboard
Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
Marcus Hutchins, AKA MalwareTech, previously registered a specific domain included in the ransomware’s code, which stopped the malware from spreading.
Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
http://ift.tt/2wpdRVc
Submitted August 03, 2017 at 11:00PM by n3versleeps
via reddit http://ift.tt/2vwGfIF
http://ift.tt/2wpdRVc
Submitted August 03, 2017 at 11:00PM by n3versleeps
via reddit http://ift.tt/2vwGfIF
Motherboard
Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
Marcus Hutchins, AKA MalwareTech, previously registered a specific domain included in the ransomware’s code, which stopped the malware from spreading.
Pythonizing the VMware Backdoor - ZDI researchers describe the VMware Backdoor RPC interface and how to write tools to analyze it.
http://ift.tt/2v0r49g
Submitted August 03, 2017 at 10:05PM by RedmondSecGnome
via reddit http://ift.tt/2hrT80p
http://ift.tt/2v0r49g
Submitted August 03, 2017 at 10:05PM by RedmondSecGnome
via reddit http://ift.tt/2hrT80p
Zero Day Initiative
Pythonizing the VMware Backdoor
In my previous VMware blog, I detailed how to exploit a Use-After-Free
vulnerability that affected drag-and-drop functionality and triggered
through the Backdoor RPC interface. After reading it, one of my ZDI
colleagues, Vincent Lee, asked me to add…
vulnerability that affected drag-and-drop functionality and triggered
through the Backdoor RPC interface. After reading it, one of my ZDI
colleagues, Vincent Lee, asked me to add…
CheckPlease: Implant-Security Modules in PowerShell, Python, Go, Ruby, Perl, C, and C#
http://ift.tt/2sCKEV8
Submitted August 04, 2017 at 06:06AM by arvanaghi
via reddit http://ift.tt/2hsUjfU
http://ift.tt/2sCKEV8
Submitted August 04, 2017 at 06:06AM by arvanaghi
via reddit http://ift.tt/2hsUjfU
GitHub
Arvanaghi/CheckPlease
CheckPlease - Payload-Agnostic Implant Security
Nessus Compliance Generator - Simple GUI for creating and editing nessus compliance files.
http://ift.tt/2u8Wlry
Submitted August 04, 2017 at 06:10AM by trustdarkness
via reddit http://ift.tt/2vuUiNY
http://ift.tt/2u8Wlry
Submitted August 04, 2017 at 06:10AM by trustdarkness
via reddit http://ift.tt/2vuUiNY
Cyber Operations, Analysis, and Research
Nessus Compliance Generator
Today we’re releasing a tool called Nessus Compliance Generator as open source under the BSD License. The full code can be found on the Argonne National Laboratory github. Nessus has many options to check for audit and compliance issues on
A generic unpacker for Android malware (as presented at DEF CON 25)
http://ift.tt/2fdFcGM
Submitted August 04, 2017 at 01:09PM by ynvb
via reddit http://ift.tt/2uqaA6R
http://ift.tt/2fdFcGM
Submitted August 04, 2017 at 01:09PM by ynvb
via reddit http://ift.tt/2uqaA6R
GitHub
CheckPointSW/android_unpacker
android_unpacker - A (hopefully) generic unpacker for packed Android apps.
A Python Package for Creating Backdoors - Coverutils
http://ift.tt/2vyJUpb
Submitted August 04, 2017 at 02:15PM by Evil1337
via reddit http://ift.tt/2v4DjzX
http://ift.tt/2vyJUpb
Submitted August 04, 2017 at 02:15PM by Evil1337
via reddit http://ift.tt/2v4DjzX
0x00sec - The Home of the Hacker
A Python Package for creating backdoors!
Hey, guys (and gals)! Long time no see. I 've been working hard on several projects and stuff lately so I was just an observer all that time. Observing this page and several projects starting on github, I was really impressed with how many backdoor projects…
Introducing ANGRYPUPPY
http://ift.tt/2vzbRgF
Submitted August 04, 2017 at 03:36PM by mdsec
via reddit http://ift.tt/2uqM59s
http://ift.tt/2vzbRgF
Submitted August 04, 2017 at 03:36PM by mdsec
via reddit http://ift.tt/2uqM59s
www.mdsec.co.uk
Introducing ANGRYPUPPY – MDSec
Automating lateral movement with ANGRYPUPPY
Using Hover to Compromise the Confidentiality of User Input on Android
http://ift.tt/2vyMDiB
Submitted August 04, 2017 at 04:43PM by lyinch
via reddit http://ift.tt/2wrBmwJ
http://ift.tt/2vyMDiB
Submitted August 04, 2017 at 04:43PM by lyinch
via reddit http://ift.tt/2wrBmwJ
How to get a Super Stelfy Shell (that AV doesn't pick up) - Tutorials - 0x00sec
http://ift.tt/2vw1c5B
Submitted August 04, 2017 at 05:51PM by maxxori
via reddit http://ift.tt/2vzbJ0M
http://ift.tt/2vw1c5B
Submitted August 04, 2017 at 05:51PM by maxxori
via reddit http://ift.tt/2vzbJ0M
0x00sec - The Home of the Hacker
How to get a Super Stelfy Shell (that AV doesn't pick up)
Getting Stealthy with Stelf Hello 0x00'ers! In this tutorial, I am going to be giving away some content that has been sought after for a long time. Everybody knows that most prebuilt tools such as Metasploit don't work, payloads generated by them, or…