Oracle released 4 hotfixes patch in Jolt protocol {CVE-2017-10269} CVSS 10.0/10.0
http://ift.tt/2hxJNFb
Submitted November 15, 2017 at 07:56PM by vah_13
via reddit http://ift.tt/2AHpGrZ
http://ift.tt/2hxJNFb
Submitted November 15, 2017 at 07:56PM by vah_13
via reddit http://ift.tt/2AHpGrZ
reddit
Oracle released 4 hotfixes patch in Jolt protocol... • r/security
1 points and 0 comments so far on reddit
Security In 5: Episode 112 - Why You Should Setup The Guest Network On Your Home Wi-Fi
http://ift.tt/2ijztO0
Submitted November 15, 2017 at 07:36PM by BinaryBlog
via reddit http://ift.tt/2AJaESs
http://ift.tt/2ijztO0
Submitted November 15, 2017 at 07:36PM by BinaryBlog
via reddit http://ift.tt/2AJaESs
Libsyn
Security In Five Podcast: Episode 112 - Why You Should Setup The Guest Network On Your Home Wi-Fi
Most of us have home Wi-Fi. When friends, family and visitors come over they may expect to get on your Wi-Fi to get Internet access. There are various reasons why you should not be allowing them access to your primary Wi-Fi network but instead use the Guest…
Redsnarf : Read team tool
http://ift.tt/2ekWA63
Submitted November 15, 2017 at 08:45PM by fireh7nter
via reddit http://ift.tt/2yIxd9b
http://ift.tt/2ekWA63
Submitted November 15, 2017 at 08:45PM by fireh7nter
via reddit http://ift.tt/2yIxd9b
GitHub
nccgroup/redsnarf
redsnarf - RedSnarf is a pen-testing / red-teaming tool for Windows environments
New EMOTET Hijacks a Windows API, Evades Sandbox and Analysis
http://ift.tt/2iZ0JB1
Submitted November 15, 2017 at 08:39PM by EvanConover
via reddit http://ift.tt/2APBb1u
http://ift.tt/2iZ0JB1
Submitted November 15, 2017 at 08:39PM by EvanConover
via reddit http://ift.tt/2APBb1u
Trendmicro
New EMOTET Hijacks a Windows API, Evades Sandbox and Analysis - TrendLabs Security Intelligence Blog
We discussed the re-emergence of banking malware EMOTET in September and how it has adopted a wider scope since it wasn’t picky about the industries it attacks. We recently discovered that EMOTET has a new iteration (detected as TSPY_EMOTET.SMD10) with a…
Sith Spam Bots Take a Page from a Star Wars Novel(s)
http://ift.tt/2zMaQkQ
Submitted November 15, 2017 at 09:20PM by whitehattracker
via reddit http://ift.tt/2A0vKzo
http://ift.tt/2zMaQkQ
Submitted November 15, 2017 at 09:20PM by whitehattracker
via reddit http://ift.tt/2A0vKzo
reddit
Sith Spam Bots Take a Page from a Star Wars Novel(s) • r/security
1 points and 0 comments so far on reddit
Bsides Lisbon 2017 Videos
https://www.youtube.com/playlist?list=PLbuNP88_wbNx3RfhlCMhjlIEKg4t8YopL
Submitted November 15, 2017 at 04:54PM by clviper
via reddit http://ift.tt/2zF7zGs
https://www.youtube.com/playlist?list=PLbuNP88_wbNx3RfhlCMhjlIEKg4t8YopL
Submitted November 15, 2017 at 04:54PM by clviper
via reddit http://ift.tt/2zF7zGs
YouTube
BSidesLisbon 2017 - YouTube
BSidesLisbon is the premier technical information security conference in Portugal. It is a community organized, not for profit, conference started in 2013 an...
What happens when you try to guess the type of a void pointer (CVE-2017-16379)
http://ift.tt/2APS8c4
Submitted November 15, 2017 at 09:43PM by Cybellum
via reddit http://ift.tt/2zGSqnA
http://ift.tt/2APS8c4
Submitted November 15, 2017 at 09:43PM by Cybellum
via reddit http://ift.tt/2zGSqnA
Cybellum
CY-2017-011: Type Confusion in Adobe Acrobat | Cybellum
Protect JS/VBS/PS Payloads with Environmental and HTTP Keying
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
Adapt and Attack
Keying Payloads for Scripting Languages
Keying payloads is an effective method to evade sandbox detection, prevent antivirus detection, and slow down incident response. This post covers environmental keying and HTTP keying.
ZeroNights ICO Hacking Contest Writeup
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
ICO Security
ZeroNights ICO Hacking Contest Writeup
Prior to ZeroNights security conference, an ICO hacking contest had been announced. The first three contestants to solve the tasks could…
Blind Operator Mode - An open source "defensive" rootkit created for a VPN provider that wants to keep their customer's connections private
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
PoshC2 v3 with SOCKS Proxy (SharpSocks)
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
Nettitude Labs
PoshC2 v3 with SOCKS Proxy (SharpSocks)
OVERVIEW We’ve been working on quite a few changes since the release of PoshC2 v2, our public Command & Control framework, back in December 2016. In this blog we’ll talk about the top changes a…
[News] MacPass 0.7 released (native macOS port of KeePass)
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub
mstarke/MacPass
MacPass - A native OS X KeePass client
White House Blog: Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
whitehouse.gov
Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
There can be no doubt that America faces significant risk to our national security and public safety from cyber threats. During the past 25 years, we have moved much of what we value to a digital format and stored it in Internet-connected devices that are…
CVE-2017-12337: Cisco Voice Operating System-Based Products Unauthorized Access Vulnerability
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
Cisco
Cisco Security Threat and Vulnerability Intelligence
The Cisco Security portal provides actionable intelligence for security threats and vulnerabilities in Cisco products and services and third-party products.
Spammers using "send to a friend" form filler bots and Star Wars to trick spam filters
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
reddit
Spammers using "send to a friend" form filler bots and... • r/netsec
2 points and 0 comments so far on reddit
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
Hacker Noon
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
Demonstrating how to use afl-unicorn against real-world userland applications
CVS says outages at pharmacies due to network problems
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
CNBC
Some CVS pharmacies are blocking prenoscription refills, exec blames 'internal network' issues
The cause is not known yet, CVS Health's David Dorman tells CNBC.
How to perform simple malware behavior analysis?
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
reddit
How to perform simple malware behavior analysis? • r/security
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've...
No boundaries: Exfiltration of personal data by session-replay noscripts
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
reddit
No boundaries: Exfiltration of personal data by... • r/netsec
1 points and 0 comments so far on reddit
Parsing Untrusted File Formats Safely
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
GitHub
google/puffs
puffs - Parsing Untrusted File Formats Safely
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
Motherboard
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
A former honoree discovered a security flaw in Forbes’ system that revealed phone numbers, emails, and date of birth.