Protect JS/VBS/PS Payloads with Environmental and HTTP Keying
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
http://ift.tt/2z49e8S
Submitted November 15, 2017 at 10:04PM by ad4pt_
via reddit http://ift.tt/2z4wNhT
Adapt and Attack
Keying Payloads for Scripting Languages
Keying payloads is an effective method to evade sandbox detection, prevent antivirus detection, and slow down incident response. This post covers environmental keying and HTTP keying.
ZeroNights ICO Hacking Contest Writeup
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
http://ift.tt/2ihQTdY
Submitted November 15, 2017 at 11:22PM by alexlash
via reddit http://ift.tt/2juAFBO
ICO Security
ZeroNights ICO Hacking Contest Writeup
Prior to ZeroNights security conference, an ICO hacking contest had been announced. The first three contestants to solve the tasks could…
Blind Operator Mode - An open source "defensive" rootkit created for a VPN provider that wants to keep their customer's connections private
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
http://ift.tt/2iXBRcN
Submitted November 15, 2017 at 11:09PM by IncludeSec
via reddit http://ift.tt/2hBLyRx
PoshC2 v3 with SOCKS Proxy (SharpSocks)
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
http://ift.tt/2zJZEqZ
Submitted November 15, 2017 at 11:59PM by eth_
via reddit http://ift.tt/2hudgMB
Nettitude Labs
PoshC2 v3 with SOCKS Proxy (SharpSocks)
OVERVIEW We’ve been working on quite a few changes since the release of PoshC2 v2, our public Command & Control framework, back in December 2016. In this blog we’ll talk about the top changes a…
[News] MacPass 0.7 released (native macOS port of KeePass)
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub Link http://ift.tt/1j7w6AhChangelog:MacPass 0.7 introduces a lot of changes and a vast amount of bug fixes.Features:KDBX4 support (ChaCha Cipher, Argon2 Key Derivation)Database merge on file change as well as manual mergeTwofish Cipher for KDB and KDBX databasesFull support of the entry historyPartial support for multi-selection of entries and groupsSupport for custom iconsCreate custom icons from favorite icons for URLsEnhanced display in database settingsAuto-completion for tagsBackground color of entries is used to colorize default iconsAdded settings to enabled and change history support on databasesAdded additional enforce password change once optionAdded setting to lock database if user changes (e.g fast user switching)Moved custom fields to the general tab and removed additional tab.Removed a lot of annoyances when working with KDB filesEnhanced Auto-type candidate selection dialogBugfixes:fixed broken clearing of clipboard when copy is directly invoked via Cmd+C or menu item on text inputsfixed issues resulting in placeholders not being evaluated on Auto-typefixed multiple issues resulting in lost data after edits (notes in particular)removed many incompatibilities in KDBX output with other Keepass clientsKnown Issues:it's currently not possible to show protected custom attributes independently from their protected settingFor a complete list of changes see 0.6.2-alpha…0.7 and the corresponding submodule commitsVersion 0.7 requires macOS 10.10. Support for 10.8 and 10.9 has been dropped.
Submitted November 16, 2017 at 12:49AM by WalrusSwarm
via reddit http://ift.tt/2hu2ztm
GitHub
mstarke/MacPass
MacPass - A native OS X KeePass client
White House Blog: Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
http://ift.tt/2zDe8cq
Submitted November 16, 2017 at 12:33AM by jamesgalb
via reddit http://ift.tt/2zJ7XTW
whitehouse.gov
Improving and Making the Vulnerability Equities Process Transparent is the Right Thing to Do
There can be no doubt that America faces significant risk to our national security and public safety from cyber threats. During the past 25 years, we have moved much of what we value to a digital format and stored it in Internet-connected devices that are…
CVE-2017-12337: Cisco Voice Operating System-Based Products Unauthorized Access Vulnerability
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
http://ift.tt/2hu2xlh
Submitted November 15, 2017 at 11:54PM by bagaudin
via reddit http://ift.tt/2ijgFP6
Cisco
Cisco Security Threat and Vulnerability Intelligence
The Cisco Security portal provides actionable intelligence for security threats and vulnerabilities in Cisco products and services and third-party products.
Spammers using "send to a friend" form filler bots and Star Wars to trick spam filters
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
http://ift.tt/2zMaQkQ
Submitted November 16, 2017 at 01:02AM by buildops
via reddit http://ift.tt/2msFegZ
reddit
Spammers using "send to a friend" form filler bots and... • r/netsec
2 points and 0 comments so far on reddit
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
http://ift.tt/2mtmdeu
Submitted November 16, 2017 at 12:46AM by njv299
via reddit http://ift.tt/2AOJL0x
Hacker Noon
afl-unicorn: Part 2 — Fuzzing the ‘Unfuzzable’
Demonstrating how to use afl-unicorn against real-world userland applications
CVS says outages at pharmacies due to network problems
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
http://ift.tt/2zZgRNX
Submitted November 16, 2017 at 02:31AM by SecurityWiseGuy
via reddit http://ift.tt/2ALAoh7
CNBC
Some CVS pharmacies are blocking prenoscription refills, exec blames 'internal network' issues
The cause is not known yet, CVS Health's David Dorman tells CNBC.
How to perform simple malware behavior analysis?
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've already tried to submit to hybrid-analysis.com, but it gives me an error.What tool could I use that is not too difficulty to learn (as disassembly, etc.)?Thanks
Submitted November 16, 2017 at 02:42AM by joaopaocha
via reddit http://ift.tt/2jvwQfr
reddit
How to perform simple malware behavior analysis? • r/security
So, I can scan this file for viruses, but what I really want to see is his exactly behavior. What registry does it change, what files, etc. I've...
No boundaries: Exfiltration of personal data by session-replay noscripts
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
http://ift.tt/2A0gjr3
Submitted November 16, 2017 at 03:10AM by danwin
via reddit http://ift.tt/2ARQ978
reddit
No boundaries: Exfiltration of personal data by... • r/netsec
1 points and 0 comments so far on reddit
Parsing Untrusted File Formats Safely
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
http://ift.tt/2AIKQWH
Submitted November 16, 2017 at 05:14AM by defunct_io
via reddit http://ift.tt/2zI2DQA
GitHub
google/puffs
puffs - Parsing Untrusted File Formats Safely
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
http://ift.tt/2zEf9Rm
Submitted November 16, 2017 at 10:15AM by antdude
via reddit http://ift.tt/2iZxnCP
Motherboard
Forbes '30 Under 30' Conference Website Exposed Attendees' Personal Information
A former honoree discovered a security flaw in Forbes’ system that revealed phone numbers, emails, and date of birth.
Plus Accounts for Students! (ProtonMail)
http://ift.tt/2mvgZii
Submitted November 16, 2017 at 10:56AM by sixw
via reddit http://ift.tt/2infEFV
http://ift.tt/2mvgZii
Submitted November 16, 2017 at 10:56AM by sixw
via reddit http://ift.tt/2infEFV
Customer Feedback for ProtonMail
Plus Account with EDU Email
-> Free plus account for uni/post-secondary students
- Can be featured in github's student pack (https://education.github.com/pack)
- Account upgrade could simply expire at the end of educational term
- Custom domain options allow students to use their…
- Can be featured in github's student pack (https://education.github.com/pack)
- Account upgrade could simply expire at the end of educational term
- Custom domain options allow students to use their…
What is the best password manager according to you?
No text found
Submitted November 16, 2017 at 12:39PM by HugoTRB
via reddit http://ift.tt/2hDeade
No text found
Submitted November 16, 2017 at 12:39PM by HugoTRB
via reddit http://ift.tt/2hDeade
reddit
What is the best password manager according to you? • r/security
2 points and 2 comments so far on reddit
Week 45 in Information Security, 2017
http://ift.tt/2ALNGdD
Submitted November 16, 2017 at 04:57PM by undercomm
via reddit http://ift.tt/2in9Yvn
http://ift.tt/2ALNGdD
Submitted November 16, 2017 at 04:57PM by undercomm
via reddit http://ift.tt/2in9Yvn
Malgregator
InfoSec Week 45, 2017
Researchers exploited antivirus software quarantine mechanism to gain privileges by manipulating the restore process from the virus...
Security in the Hybrid Cloud: Connect Advanced Threat Analytics to Azure Security Center
http://ift.tt/2hDkjGx
Submitted November 16, 2017 at 03:45PM by NISMO1968
via reddit http://ift.tt/2A3WBea
http://ift.tt/2hDkjGx
Submitted November 16, 2017 at 03:45PM by NISMO1968
via reddit http://ift.tt/2A3WBea
Starwindsoftware
Security in the Hybrid Cloud: Connect Advanced Threat Analytics to Azure Security Center | StarWind Blog
Microsoft Advanced Threat Analytics (ATA) combines several of the latest security enhancements. Learn how to connect the ATA platform to Azure.
Contact Lean Security
http://ift.tt/2zHz1Dc
Submitted November 16, 2017 at 05:48PM by leanassurance
via reddit http://ift.tt/2A2MWEJ
http://ift.tt/2zHz1Dc
Submitted November 16, 2017 at 05:48PM by leanassurance
via reddit http://ift.tt/2A2MWEJ
Web And Mobile App Security Assurance
Contact Us
Let's Chat
Bug bounty hunter walks away on 30k$ bounty from DJI (drone maker)
http://ift.tt/2A42Z4Y
Submitted November 16, 2017 at 05:58PM by moutonplacide
via reddit http://ift.tt/2ASuxrl
http://ift.tt/2A42Z4Y
Submitted November 16, 2017 at 05:58PM by moutonplacide
via reddit http://ift.tt/2ASuxrl
A fed only browser isolation platform (beta).
http://ift.tt/2pveD3F
Submitted November 16, 2017 at 07:23PM by Buleknows
via reddit http://ift.tt/2hw35a9
http://ift.tt/2pveD3F
Submitted November 16, 2017 at 07:23PM by Buleknows
via reddit http://ift.tt/2hw35a9
Tucloud
Safeweb Engine | Browser Isolation Platform
The Safeweb Engine is an award winning browser isolation technology, based on a unique containerization and grid distributed architecture. Developed by tuCloud the Safeweb Engine is capable of supporting millions of simultaneous remote browsing users.