Where there's a JTAG, there's a way: obtaining full system access via USB. (Uses Intel ME)
http://ift.tt/2xTznBQ
Submitted November 09, 2017 at 04:46PM by joosto
via reddit http://ift.tt/2zthj3Z
http://ift.tt/2xTznBQ
Submitted November 09, 2017 at 04:46PM by joosto
via reddit http://ift.tt/2zthj3Z
Netflix scam detected
http://ift.tt/2yK0l3Z
Submitted November 09, 2017 at 06:14PM by 3f0x9
via reddit http://ift.tt/2jdt7mL
http://ift.tt/2yK0l3Z
Submitted November 09, 2017 at 06:14PM by 3f0x9
via reddit http://ift.tt/2jdt7mL
IT SECURITY GURU
Netflix scam detected - IT SECURITY GURU
Millions of people who hold a Netflix account are currently exposed to the latest email phishing scam that is telling users that their account is suspended due to a problem validating their credit cards. Beware – this is a scam. View Full Story ORIGINAL SOURCE:…
Domain name permutation engine for detecting typo squatting, phishing and corporate espionage
http://ift.tt/1SheO7I
Submitted November 09, 2017 at 06:50PM by speckz
via reddit http://ift.tt/2m8ZDri
http://ift.tt/1SheO7I
Submitted November 09, 2017 at 06:50PM by speckz
via reddit http://ift.tt/2m8ZDri
GitHub
elceef/dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation - elceef/dnstwist
Senators push to ditch Social Security numbers in light of Equifax hack
http://ift.tt/2zH57zg
Submitted November 09, 2017 at 06:19PM by Astralarogance
via reddit http://ift.tt/2zo8quJ
http://ift.tt/2zH57zg
Submitted November 09, 2017 at 06:19PM by Astralarogance
via reddit http://ift.tt/2zo8quJ
TechCrunch
Senators push to ditch Social Security numbers in light of Equifax hack
Eyeing more secure alternatives to Social Security numbers, lawmakers in the U.S. are looking abroad. Today, the Senate Commerce Committee questioned former Yahoo CEO Marissa Mayer, Verizon Chief…
VestaCP root Privilege Escalation (PHP-FPM + Nginx)
http://ift.tt/2AiAzB6
Submitted November 09, 2017 at 06:55PM by TarqDirtyToMe
via reddit http://ift.tt/2yLMmux
http://ift.tt/2AiAzB6
Submitted November 09, 2017 at 06:55PM by TarqDirtyToMe
via reddit http://ift.tt/2yLMmux
Christopher Tarquini's Blog
VestaCP - Root Privilege Escalation
VestaCP allows for root privilege escalation from PHP leveraging Nginx configuration.
A DoS Attack against the C# Compiler
http://ift.tt/2hTJSzR
Submitted November 09, 2017 at 06:42PM by maxxori
via reddit http://ift.tt/2m8OkPF
http://ift.tt/2hTJSzR
Submitted November 09, 2017 at 06:42PM by maxxori
via reddit http://ift.tt/2m8OkPF
reddit
A DoS Attack against the C# Compiler • r/netsec
3 points and 0 comments so far on reddit
Security In 5: Episode 108 - Top 10 Security Tips For Your Network - 2 - Patch
http://ift.tt/2jfZ91H
Submitted November 09, 2017 at 07:43PM by BinaryBlog
via reddit http://ift.tt/2hn6b4a
http://ift.tt/2jfZ91H
Submitted November 09, 2017 at 07:43PM by BinaryBlog
via reddit http://ift.tt/2hn6b4a
Libsyn
Security In Five Podcast: Episode 108 - Top 10 Security Tips For Your Network - 2 - Patch
Continuing with the mini-series Top 10 Security Tips For Your Network number 2 is about patching. Equifax happened, ultimately, due to a lack of prompt patching. Updates to your network components and software fix bugs, improve performance but also close…
iMessagesBackdoor - Outlook All Over Again
http://ift.tt/2zYhvqK
Submitted November 09, 2017 at 08:51PM by Killswitch-GUI
via reddit http://ift.tt/2Ao3Vx9
http://ift.tt/2zYhvqK
Submitted November 09, 2017 at 08:51PM by Killswitch-GUI
via reddit http://ift.tt/2Ao3Vx9
GitHub
checkyfuntime/iMessagesBackdoor
iMessagesBackdoor - A noscript to help set up an event handler in order to install a persistent backdoor that can be activated by sending a message.
Toast Overlay weaponized to install several Android malware
http://ift.tt/2zq3q92
Submitted November 09, 2017 at 08:45PM by EvanConover
via reddit http://ift.tt/2hWIUmz
http://ift.tt/2zq3q92
Submitted November 09, 2017 at 08:45PM by EvanConover
via reddit http://ift.tt/2hWIUmz
Trendmicro
Toast Overlay Weaponized to Install Several Android Malware - TrendLabs Security Intelligence Blog
We uncovered new Android malware that can surreptitiously install other malware on the affected device via the Toast Overlay attack: TOASTAMIGO.
Local File Read via XSS in a PDF
http://ift.tt/2AkvHdT
Submitted November 09, 2017 at 02:14PM by albinowax
via reddit http://ift.tt/2jgfun3
http://ift.tt/2AkvHdT
Submitted November 09, 2017 at 02:14PM by albinowax
via reddit http://ift.tt/2jgfun3
www.noob.ninja
Local File Read via XSS in Dynamically Generated PDF
Hello Hunters, This time I am writing about a Vulnerability found in another private program(xyz.com) on Bugcrowd ...
Finding my first CVE: Analysis of a Remote DoS vulnerability in VirtualBox
http://ift.tt/2m14ydV
Submitted November 10, 2017 at 12:47AM by vaiii
via reddit http://ift.tt/2zuU2Ax
http://ift.tt/2m14ydV
Submitted November 10, 2017 at 12:47AM by vaiii
via reddit http://ift.tt/2zuU2Ax
reddit
Finding my first CVE: Analysis of a Remote DoS... • r/netsec
1 points and 0 comments so far on reddit
[Sharing] OReilly Security Conference 2017
check here: http://ift.tt/2zKI0UN
Submitted November 10, 2017 at 12:40AM by Fssuploader
via reddit http://ift.tt/2zpo0X8
check here: http://ift.tt/2zKI0UN
Submitted November 10, 2017 at 12:40AM by Fssuploader
via reddit http://ift.tt/2zpo0X8
FAST RELEASE
OReilly Security Conference 2017 - FAST RELEASE
OReilly Security Conference 2017 - New York, NY MP4 | Video: AVC 1920x1080 | Audio: AAC 48KHz 2ch | Duration: 2 Hours | 4.20 GB
[Sharing]Offensive Security Training Videos
check here: http://ift.tt/2zI0N2Q
Submitted November 10, 2017 at 12:01AM by fastrls
via reddit http://ift.tt/2AoMhcA
check here: http://ift.tt/2zI0N2Q
Submitted November 10, 2017 at 12:01AM by fastrls
via reddit http://ift.tt/2AoMhcA
FAST RELEASE
[Download] Offensive Security Training Videos - FAST RELEASE
BASELINE – SANS & Offensive-Security File size: 85 GB
Server Side Request Forgery (SSRF) Tricks
http://ift.tt/2zvyMsy
Submitted November 09, 2017 at 06:37AM by awqufohlmkse
via reddit http://ift.tt/2jemArS
http://ift.tt/2zvyMsy
Submitted November 09, 2017 at 06:37AM by awqufohlmkse
via reddit http://ift.tt/2jemArS
Pedro's blog
Server Side Request Forgery (SSRF)
This is a blog post summarising a few notes I’ve gathered around the internet, with the purpose of cementing them in my mind rather than adding anything new or attempting to broadcast them to…
0patching a Pretty Nasty Microsoft Word Type Confusion Vulnerability (CVE-2017-11826)
http://ift.tt/2yo88Ac
Submitted November 09, 2017 at 11:10PM by dielel
via reddit http://ift.tt/2AoOYLh
http://ift.tt/2yo88Ac
Submitted November 09, 2017 at 11:10PM by dielel
via reddit http://ift.tt/2AoOYLh
0patch.blogspot.co.uk
0patching a Pretty Nasty Microsoft Word Type Confusion Vulnerability (CVE-2017-11826)
by Mitja Kolsek, the 0patch Team In September 2017, Qihoo 360 Core Security detected an in-the-wild attack that leveraged an Office 0day ...
2017 Collegiate Penetration Testing Competition (CPTC) Review
http://ift.tt/2hhI03g
Submitted November 09, 2017 at 09:43PM by utmp
via reddit http://ift.tt/2hrLaoJ
http://ift.tt/2hhI03g
Submitted November 09, 2017 at 09:43PM by utmp
via reddit http://ift.tt/2hrLaoJ
lockboxx.blogspot.co.uk
Collegiate Penetration Testing Competition (CPTC) 2017 Review
A blog about information security, hacking, and protecting digital infrastructure. Penetration testing, malware analysis, and intrusion detection.
ROCA vulnerability - there is 59,446,254 Spanish e-IDs - but last 2 years' worth had their certificates revoked
http://ift.tt/2AwsCsm[translation with Google Translate]To strengthen the security of electronic certificates of the e-ID cards ... the functionality of the digital certificates will be deactivated ......Until the necessary technical solutions are implemented (which will be done in the near future) ..More information about the vulnerability is at http://ift.tt/2goKrUN.On-line certificate test is at http://ift.tt/2ylpMrM - including links to off-line tester and an email responder (roca@keychest.net)
Submitted November 10, 2017 at 02:27AM by dc352
via reddit http://ift.tt/2map4sn
http://ift.tt/2AwsCsm[translation with Google Translate]To strengthen the security of electronic certificates of the e-ID cards ... the functionality of the digital certificates will be deactivated ......Until the necessary technical solutions are implemented (which will be done in the near future) ..More information about the vulnerability is at http://ift.tt/2goKrUN.On-line certificate test is at http://ift.tt/2ylpMrM - including links to off-line tester and an email responder (roca@keychest.net)
Submitted November 10, 2017 at 02:27AM by dc352
via reddit http://ift.tt/2map4sn
www.dnielectronico.es
Portal del DNI Electronico, Cuerpo Nacional de Policía
WEB OFICIAL DNIE ELECTRONICO Y PASAPORTE
Attacking .NET Serialization
http://ift.tt/2iIeKD0
Submitted November 10, 2017 at 03:59AM by overflowingInt
via reddit http://ift.tt/2hot7jl
http://ift.tt/2iIeKD0
Submitted November 10, 2017 at 03:59AM by overflowingInt
via reddit http://ift.tt/2hot7jl
Speaker Deck
Attacking .NET Serialization
2016 was the year of Java deserialization apocalypse. Although Java Deserialization attacks were known for years, the publication of the Apache Commons Collection Remote Code Execution (RCE from now on) gadget finally brought this forgotten vulnerability…
Weaponization of social media and search engines may spark ultimate cyberwar - SiliconANGLE
http://ift.tt/2ApysLh
Submitted November 10, 2017 at 04:16AM by SecurityTrust
via reddit http://ift.tt/2iJC97k
http://ift.tt/2ApysLh
Submitted November 10, 2017 at 04:16AM by SecurityTrust
via reddit http://ift.tt/2iJC97k
SiliconANGLE
Weaponization of social media and search engines may spark ultimate cyberwar
The co-founder of an influential cybersecurity think thank believes that weaponization of major social media websites and search engines will lay the foundation for cyberwarfare on a scale unimaginabl
Dashlane-2017 Password Power Rankings
http://ift.tt/2uHT4Ls
Submitted November 10, 2017 at 06:08AM by DarkWorld25
via reddit http://ift.tt/2jeUEUM
http://ift.tt/2uHT4Ls
Submitted November 10, 2017 at 06:08AM by DarkWorld25
via reddit http://ift.tt/2jeUEUM
Dashlane Blog
Dashlane’s 2017 Password Power Rankings: How Consumer & Enterprise Websites Handle User Security
We examined the password policies of 40 popular consumer & enterprise websites. Today, we’re sharing the results in our 2017 Password Power Rankings.
How We Deliver Global SSL with Let's Encrypt
http://ift.tt/2jgIevX
Submitted November 10, 2017 at 07:27AM by rmddos
via reddit http://ift.tt/2jgBRst
http://ift.tt/2jgIevX
Submitted November 10, 2017 at 07:27AM by rmddos
via reddit http://ift.tt/2jgBRst
Fly Articles
How We Deliver Global SSL with Let's Encrypt
Fly is proud to sponsor Let's Encrypt. We've been hard at work making Let's Encrypt TLS certificates as simple and safe as possible for developers and creators of all kinds. Within this article we'll explore how Fly applies Let's Encrypt certificates to servers…