Cisco: WebEx Various GPC Sanitization bypasses permit Arbitrary Remote Command Execution - project-zero
http://ift.tt/2uBjxi7
Submitted July 17, 2017 at 10:27PM by Extremite
via reddit http://ift.tt/2varMOY
http://ift.tt/2uBjxi7
Submitted July 17, 2017 at 10:27PM by Extremite
via reddit http://ift.tt/2varMOY
reddit
Cisco: WebEx Various GPC Sanitization bypasses permit... • r/netsec
1 points and 0 comments so far on reddit
H1702 CTF Writeup
http://ift.tt/2t8HTeP
Submitted July 17, 2017 at 10:13PM by teknogeek1
via reddit http://ift.tt/2vuwDtQ
http://ift.tt/2t8HTeP
Submitted July 17, 2017 at 10:13PM by teknogeek1
via reddit http://ift.tt/2vuwDtQ
reddit
H1702 CTF Writeup • r/netsec
1 points and 0 comments so far on reddit
The Synesthesia Shellcode Generator: Code Release and Future Directions
http://ift.tt/2vuw8js
Submitted July 17, 2017 at 10:51PM by rolfr
via reddit http://ift.tt/2u1WLgh
http://ift.tt/2vuw8js
Submitted July 17, 2017 at 10:51PM by rolfr
via reddit http://ift.tt/2u1WLgh
Möbius Strip Reverse Engineering
The Synesthesia Shellcode Generator: Code Release and Future Directions
Synesthesia is an idea that I published at EkoParty last year (slides and
video are available) regarding automated shellcode generation under
encoding restrictions. The presentation walked through an extended tutorial
on program synthesis, and showed…
video are available) regarding automated shellcode generation under
encoding restrictions. The presentation walked through an extended tutorial
on program synthesis, and showed…
Pay What You Want Cybersecurity Ebooks | 4 to 14 Books -- Humble Bundle
http://ift.tt/2tyu6h2
Submitted July 18, 2017 at 12:00AM by hash_salts
via reddit http://ift.tt/2vaHQjP
http://ift.tt/2tyu6h2
Submitted July 18, 2017 at 12:00AM by hash_salts
via reddit http://ift.tt/2vaHQjP
Humble Bundle
Humble Book Bundle: Cybersecurity presented by Wiley
Pay what you want for cybersecurity ebooks and support charity!
Cisco-Talos - pyrebox (PyREBox is a Python noscriptable Reverse Engineering sandbox).
http://ift.tt/2u31v5e
Submitted July 18, 2017 at 12:05PM by sanderD
via reddit http://ift.tt/2tAHlO7
http://ift.tt/2u31v5e
Submitted July 18, 2017 at 12:05PM by sanderD
via reddit http://ift.tt/2tAHlO7
GitHub
Cisco-Talos/pyrebox
Contribute to pyrebox development by creating an account on GitHub.
Decrypting DEF CON badge challenges
http://ift.tt/2vcXr2u
Submitted July 18, 2017 at 01:45PM by cr0mangia
via reddit http://ift.tt/2u4LsFE
http://ift.tt/2vcXr2u
Submitted July 18, 2017 at 01:45PM by cr0mangia
via reddit http://ift.tt/2u4LsFE
Help Net Security
Decrypting DEF CON badge challenges - Help Net Security
Here’s an introduction into the secret world of cryptography, device modding and hidden clues that happens at the world’s largest hacker gathering.
AWS Misconfigurations in PlayerUnknown's Battlegrounds Leading to Exposed S3 Bucket with Data Leakage.
http://ift.tt/2tb8dET
Submitted July 18, 2017 at 05:25PM by elliott954
via reddit http://ift.tt/2uv2iyF
http://ift.tt/2tb8dET
Submitted July 18, 2017 at 05:25PM by elliott954
via reddit http://ift.tt/2uv2iyF
reddit
AWS Misconfigurations in PlayerUnknown's Battlegrounds... • r/netsec
5 points and 3 comments so far on reddit
Detailed incident report for Gandi domain hijacking event on July 7, 2017
http://ift.tt/2udA5MU
Submitted July 18, 2017 at 06:17PM by campuscodi
via reddit http://ift.tt/2u5mkyE
http://ift.tt/2udA5MU
Submitted July 18, 2017 at 06:17PM by campuscodi
via reddit http://ift.tt/2u5mkyE
Gandi News
Detailed incident report
A detailed report on the July 7 incident impacting a total of 751 domains managed by our technical partner.
Bitdefender Remote Stack Buffer Overflow via 7z PPMD
http://ift.tt/2tBnSNl
Submitted July 18, 2017 at 06:02PM by landave
via reddit http://ift.tt/2uuR8Kc
http://ift.tt/2tBnSNl
Submitted July 18, 2017 at 06:02PM by landave
via reddit http://ift.tt/2uuR8Kc
landave.io
Bitdefender: Remote Stack Buffer Overflow via 7z PPMD - landave's blog
Blog about anti-virus software and its issues.
NorthSec 2017 Conference Videos have been Published
http://ift.tt/2uEKJwr
Submitted July 18, 2017 at 07:42PM by ouaibe
via reddit http://ift.tt/2u6ahkv
http://ift.tt/2uEKJwr
Submitted July 18, 2017 at 07:42PM by ouaibe
via reddit http://ift.tt/2u6ahkv
NorthSec
NorthSec 2017 Conference Videos - NorthSec
The videos from NorthSec 2017 Conference have finally been published, check them out! Past editions videos are also on our YouTube channel. Want to come to Montreal for NorthSec 2018? The CFP opens in November 2017, mark your calendars & propose something…
WSJ Parent Company Dow Jones Exposed Customer Data, misconfigured S3 bucket
http://ift.tt/2txHTEf
Submitted July 18, 2017 at 07:53PM by Confuzed_
via reddit http://ift.tt/2u53kia
http://ift.tt/2txHTEf
Submitted July 18, 2017 at 07:53PM by Confuzed_
via reddit http://ift.tt/2u53kia
Upguard
Cloud Leak: WSJ Parent Company Dow Jones Exposed Customer Data
Sensitive data points on millions of Dow Jones publication customers were exposed in a massive cloud leak.
GoodSAM CSRF/Stored XSS Chain (Account Compromise/Medical Info Theft).
http://ift.tt/2uyPC9t
Submitted July 18, 2017 at 03:52AM by L1nuxguy
via reddit http://ift.tt/2veBfoG
http://ift.tt/2uyPC9t
Submitted July 18, 2017 at 03:52AM by L1nuxguy
via reddit http://ift.tt/2veBfoG
James Hemmings ~ Blog
GoodSAM – CSRF/Stored XSS Chain Full Disclosure
I’ve been a user of the mobile/web application named “GoodSAM” which is an application where the Ambulance service in London or the East Midlands can dispatch “Responders…
Devil's Ivy Vulnerability
http://ift.tt/2uFbel8
Submitted July 18, 2017 at 09:13PM by ncrmn
via reddit http://ift.tt/2tmJilS
http://ift.tt/2uFbel8
Submitted July 18, 2017 at 09:13PM by ncrmn
via reddit http://ift.tt/2tmJilS
Senrio
Devil's Ivy: The Technical Details
Devil's Ivy is a vulnerability deep in the communication layer. When we began a security analysis of an Axis security camera, we had no idea we would find a vulnerability that affects so many devices. Read on for the technical writeup.
Formal verification of the WireGuard protocol using Tamarin Prover
http://ift.tt/2urREbS
Submitted July 18, 2017 at 08:47PM by zx2c4
via reddit http://ift.tt/2vy9RkP
http://ift.tt/2urREbS
Submitted July 18, 2017 at 08:47PM by zx2c4
via reddit http://ift.tt/2vy9RkP
Wireguard
Formal Verification - WireGuard
Real-World Rubber Ducky Attacks with Empire Stagers
http://ift.tt/2vylTuH
Submitted July 18, 2017 at 09:46PM by sc0tfree
via reddit http://ift.tt/2u6G30L
http://ift.tt/2vylTuH
Submitted July 18, 2017 at 09:46PM by sc0tfree
via reddit http://ift.tt/2u6G30L
sc0tfree
Real-World Rubber Ducky Attacks with Empire Stagers
Nine times out of ten, my goal when using a Rubber Ducky on pentests is to
launch an Empire or Meterpreter session. However, for the Ducky to type out
an entire stager often takes too much time to be practical for most
real-world USB attacks. This article…
launch an Empire or Meterpreter session. However, for the Ducky to type out
an entire stager often takes too much time to be practical for most
real-world USB attacks. This article…
Implementing Malware Command and Control Using Major CDNs and High-Traffic Domains
http://ift.tt/2tn0gRf
Submitted July 18, 2017 at 10:05PM by jat0369
via reddit http://ift.tt/2u5b97i
http://ift.tt/2tn0gRf
Submitted July 18, 2017 at 10:05PM by jat0369
via reddit http://ift.tt/2u5b97i
CyberArk
Implementing Malware Command and Control Using Major CDNs and High-Traffic Domains - CyberArk
Technical research from CyberArk Labs and Red Team security experts to help you think like an attacker by keeping you ahead of the latest threats.
Vendor-exclusive DDNS - is it a security risk?
http://ift.tt/2tn7p46
Submitted July 17, 2017 at 09:54PM by kilgotrout
via reddit http://ift.tt/2vyKEXp
http://ift.tt/2tn7p46
Submitted July 17, 2017 at 09:54PM by kilgotrout
via reddit http://ift.tt/2vyKEXp
Medium
Vendor-exclusive DDNS — is it a security risk?
Opinions expressed are solely my own and do not express the views or opinions of my employer. Information is provided for educational…
Six Security Vulnerabilities from a Year of HackerOne
http://ift.tt/2sl3wfx
Submitted July 19, 2017 at 02:15AM by hash_salts
via reddit http://ift.tt/2u6X8HW
http://ift.tt/2sl3wfx
Submitted July 19, 2017 at 02:15AM by hash_salts
via reddit http://ift.tt/2u6X8HW
Flexport Engineering
Six Security Vulnerabilities from a Year of HackerOne
We launched our HackerOne program a year ago to increase the security of Flexport.
A Security Audit of Firefox Accounts
http://ift.tt/2uzXzLH
Submitted July 19, 2017 at 02:02AM by jvehent
via reddit http://ift.tt/2tDSayR
http://ift.tt/2uzXzLH
Submitted July 19, 2017 at 02:02AM by jvehent
via reddit http://ift.tt/2tDSayR
Mozilla Security Blog
A Security Audit of Firefox Accounts
To provide transparency into our ongoing efforts to protect your privacy and security on the Internet, we are releasing a security audit of Firefox Accounts ...
Setting up a burner phone number using Twilio and 9 lines of code
http://ift.tt/2vAyZaJ
Submitted July 19, 2017 at 10:15AM by xxdesmus
via reddit http://ift.tt/2to899f
http://ift.tt/2vAyZaJ
Submitted July 19, 2017 at 10:15AM by xxdesmus
via reddit http://ift.tt/2to899f
Making and breaking things.
Quickly setting up a burner phone number using Twilio
Firstly the advice in this article is not designed for people who are trying to evade spying or some other stuff, it's just to avoid marketers or avoid giving your number to someone you don't want to. So I'm going over to the states at the end of this week
