Using a .scf file to capture domain or workgroup user credentials with responder.
http://ift.tt/2jD4Syu
Submitted November 20, 2017 at 03:31PM by myexploit2600
via reddit http://ift.tt/2B55YY3
http://ift.tt/2jD4Syu
Submitted November 20, 2017 at 03:31PM by myexploit2600
via reddit http://ift.tt/2B55YY3
1337red
Using a SCF file to Gather Hashes
Have you ever been on a internal network assessment and discovered an unauthenticated writable Windows-based file share? Well, in addition to finding potentially sensitive information, you can abus…
Global Security Advisory Services Market Size, Share & Security Advisory Services Market|TechSci Research
http://ift.tt/2zk4agI
Submitted November 20, 2017 at 05:15PM by techsciresearch1
via reddit http://ift.tt/2mIGzAA
http://ift.tt/2zk4agI
Submitted November 20, 2017 at 05:15PM by techsciresearch1
via reddit http://ift.tt/2mIGzAA
Techsciresearch
Global Security Advisory Services Market Size, Share & Security Advisory Services Market|TechSci Research
Global Security Advisory Services Size, Share, Outlook & Global Security Advisory Services Analysis By Service Type (Penetration Testing, Vulnerability Management, Risk Management Competition Forecast & Opportunities
Some 'security people are f*cking morons' says Linus Torvalds
http://ift.tt/2hE033C
Submitted November 20, 2017 at 06:56PM by speckz
via reddit http://ift.tt/2jFdcOn
http://ift.tt/2hE033C
Submitted November 20, 2017 at 06:56PM by speckz
via reddit http://ift.tt/2jFdcOn
www.theregister.co.uk
Some 'security people are f*cking morons' says Linus Torvalds
Linux Lord fires up over proposal to secure Linux by shutting down wonky processes
South Korea Winter Olympics: Cyber lessons from the past
http://ift.tt/2jG6nfo
Submitted November 20, 2017 at 06:02PM by Uminekoshi
via reddit http://ift.tt/2jGMViu
http://ift.tt/2jG6nfo
Submitted November 20, 2017 at 06:02PM by Uminekoshi
via reddit http://ift.tt/2jGMViu
Help Net Security
South Korea Winter Olympics: Cyber lessons from the past - Help Net Security
South Korea Winter Olympics offer an opportunity for cybercriminals to achieve notoriety and profit. There are lessons to be learned from the past.
CVE-2017-16544: A Busybox autocompletion vulnerability
http://ift.tt/2AWg1Oc
Submitted November 20, 2017 at 07:15PM by reddit_read_today
via reddit http://ift.tt/2zQhIQF
http://ift.tt/2AWg1Oc
Submitted November 20, 2017 at 07:15PM by reddit_read_today
via reddit http://ift.tt/2zQhIQF
Twistlock
CVE-2017-16544: A Busybox autocompletion vulnerability | Twistlock
CVE-2017-16544: A Busybox autocompletion vulnerability from Twistlock. Dev-to-Production Docker and container security for enterprises.
BASELINE – SANS & Offensive-Security
http://ift.tt/2zI0N2Q
Submitted November 20, 2017 at 08:00PM by fullboy1001
via reddit http://ift.tt/2hP1pfU
http://ift.tt/2zI0N2Q
Submitted November 20, 2017 at 08:00PM by fullboy1001
via reddit http://ift.tt/2hP1pfU
FAST RELEASE
[Download] Offensive Security Training Videos - FAST RELEASE
BASELINE – SANS & Offensive-Security File size: 85 GB
BASELINE – SANS & Offensive-Security
http://ift.tt/2zI0N2Q
Submitted November 20, 2017 at 07:38PM by fastrls
via reddit http://ift.tt/2iyblaC
http://ift.tt/2zI0N2Q
Submitted November 20, 2017 at 07:38PM by fastrls
via reddit http://ift.tt/2iyblaC
FAST RELEASE
[Download] Offensive Security Training Videos - FAST RELEASE
BASELINE – SANS & Offensive-Security File size: 85 GB
Security In 5: Episode 115 - IoT Strikes Again - Bluetooth Flaw Impacts 20 Million Amazon and Google Home Devices
http://ift.tt/2B6PvTi
Submitted November 20, 2017 at 07:30PM by BinaryBlog
via reddit http://ift.tt/2z3KycA
http://ift.tt/2B6PvTi
Submitted November 20, 2017 at 07:30PM by BinaryBlog
via reddit http://ift.tt/2z3KycA
Libsyn
Security In Five Podcast: Episode 115 - IoT Strikes Again - Bluetooth Flaw Impacts 20 Million Amazon and Google Home Devices
The Internet of Things lack of security focus strikes again! This times it is a flaw in Bluetooth dubbed BlueBorne than impacts billions of mobiles devices and now your home devices too. This episode goes into the flaw, how it can be exploited and what you…
Pins and Staples: Enhanced SSL Security
http://ift.tt/2zYng9j
Submitted November 20, 2017 at 09:31PM by fang0654
via reddit http://ift.tt/2zT3lKO
http://ift.tt/2zYng9j
Submitted November 20, 2017 at 09:31PM by fang0654
via reddit http://ift.tt/2zT3lKO
Depthsecurity
Pins and Staples: Enhanced SSL Security
With Chrome backing away from HTTP Public Key Pinning and other industry thought-leaders calling for its death, I figured I'd take some time to review some
Fully undetectable backdooring PE files
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:07PM by InformationSecurity
via reddit http://ift.tt/2AXUZiy
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:07PM by InformationSecurity
via reddit http://ift.tt/2AXUZiy
Haider Mahmood Infosec Blog
Fully undetectable backdooring PE files
Table of Contents1 Introduction2 Self Imposed Restrictions3 Methods used:4 Criteria for PE file selection for implanting backdoor4.1 ASLR: 4.2 Static Analysis5 Backdooring PE file6 Adding a new Section header method6.1 Hijack Execution Flow6.2 Adding Shellcode6.3…
Fully undetectable backdooring of portable executable files
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:43PM by InformationSecurity
via reddit http://ift.tt/2zVNNWV
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:43PM by InformationSecurity
via reddit http://ift.tt/2zVNNWV
Haider Mahmood Infosec Blog
Fully undetectable backdooring PE files
Table of Contents1 Introduction2 Self Imposed Restrictions3 Methods used:4 Criteria for PE file selection for implanting backdoor4.1 ASLR: 4.2 Static Analysis5 Backdooring PE file6 Adding a new Section header method6.1 Hijack Execution Flow6.2 Adding Shellcode6.3…
Has BYOD taken over your office? Here are 3 strategies in securing your data
http://ift.tt/2izMxPE
Submitted November 20, 2017 at 09:57PM by dj3poka
via reddit http://ift.tt/2mKgIrL
http://ift.tt/2izMxPE
Submitted November 20, 2017 at 09:57PM by dj3poka
via reddit http://ift.tt/2mKgIrL
Tgdaily
Has BYOD taken over your office? Here are 3 strategies in securing your data
BYOD, or bring-your-own-device, had been a buzzword in the enterprise and small business community since the mid 2000s. When smartphones and tablets came into fashion, not all businesses were ready to spend for their employees’ device needs.
Glad to see this finally happening: U.S. nails Kentucky gas-pump skimmers. Made $3.5M from ~50 pumps
http://ift.tt/2zkTvlU
Submitted November 20, 2017 at 09:53PM by MadSecuritySquirrel
via reddit http://ift.tt/2mKgRvj
http://ift.tt/2zkTvlU
Submitted November 20, 2017 at 09:53PM by MadSecuritySquirrel
via reddit http://ift.tt/2mKgRvj
Arkansas Online
U.S. nails Kentucky gas-pump skimmers
LOUISVILLE, Ky. -- Federal authorities pointed Friday to multiple arrests and convictions in Kentucky as just the start of a crackdown on credit card skimmers who target gas pumps to steal personal information.
Android Bug Lets Attackers Record Audio & Screen Activity on 3 of 4 Smartphones
http://ift.tt/2zh6WmR
Submitted November 20, 2017 at 09:50PM by MadSecuritySquirrel
via reddit http://ift.tt/2zkTApI
http://ift.tt/2zh6WmR
Submitted November 20, 2017 at 09:50PM by MadSecuritySquirrel
via reddit http://ift.tt/2zkTApI
BleepingComputer
Android Bug Lets Attackers Record Audio & Screen Activity on 3 of 4 Smartphones
Android smartphones running Lolipop, Marshmallow, and Nougat, are vulnerable to an attack that exploits the MediaProjection service to capture the user's screen and record system audio
Modifying and Building Burp Extensions
http://ift.tt/2wyoTeK
Submitted November 20, 2017 at 10:29PM by Mempodipper
via reddit http://ift.tt/2zYTv8e
http://ift.tt/2wyoTeK
Submitted November 20, 2017 at 10:29PM by Mempodipper
via reddit http://ift.tt/2zYTv8e
DecidedlyGray
Modifying and Building Burp Extensions
Reference on modifying and repackaging, as well as compiling Burp Suite extensions from source.
"lspitzner"
http://ift.tt/2izMun0
Submitted November 20, 2017 at 11:37PM by volci
via reddit http://ift.tt/2zYmrNw
http://ift.tt/2izMun0
Submitted November 20, 2017 at 11:37PM by volci
via reddit http://ift.tt/2zYmrNw
securingthehuman.sans.org
Security Awareness Blog | lspitzner
Security Awareness Blog blog pertaining to lspitzner
VU#817544. Windows ASLR Vulnerability
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:35PM by bagaudin
via reddit http://ift.tt/2AWSOvq
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:35PM by bagaudin
via reddit http://ift.tt/2AWSOvq
www.kb.cert.org
Vulnerability Note VU#817544 - Windows 8 and later fail to properly randomize every application if system-wide mandatory ASLR is…
Microsoft Windows 8 introduced a change in how system-wide mandatory ASLR is implemented. This change requires system-wide bottom-up ASLR to be enabled for mandatory ASLR to receive entropy. Tools that enable system-wide ASLR without also setting bottom-up…
VU#817544. Windows ASLR Vulnerability
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:48PM by bagaudin
via reddit http://ift.tt/2zll52F
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:48PM by bagaudin
via reddit http://ift.tt/2zll52F
www.kb.cert.org
Vulnerability Note VU#817544 - Windows 8 and later fail to properly randomize every application if system-wide mandatory ASLR is…
Microsoft Windows 8 introduced a change in how system-wide mandatory ASLR is implemented. This change requires system-wide bottom-up ASLR to be enabled for mandatory ASLR to receive entropy. Tools that enable system-wide ASLR without also setting bottom-up…
TP-Link serves no or outdated firmware on 30% of its European websites
http://ift.tt/2B7qDuP
Submitted November 20, 2017 at 11:29PM by Aeyoun
via reddit http://ift.tt/2hF1n6q
http://ift.tt/2B7qDuP
Submitted November 20, 2017 at 11:29PM by Aeyoun
via reddit http://ift.tt/2hF1n6q
Ctrl blog
TP-Link serves outdated or no firmware at all on 30% of its European websites
TP-Link uses the same firmware in most of Europe, but fails to keep their regional websites up to date with the latest versions.
Banking Trojan Gains Ability to Steal Facebook, Twitter and Gmail Accounts
http://ift.tt/2zNGmAN
Submitted November 21, 2017 at 12:02AM by volci
via reddit http://ift.tt/2AXWhd7
http://ift.tt/2zNGmAN
Submitted November 21, 2017 at 12:02AM by volci
via reddit http://ift.tt/2AXWhd7
The Hacker News
Banking Trojan Gains Ability to Steal Facebook, Twitter and Gmail Accounts
Security researchers have discovered a new variant of Terdot banking Trojan that steals social media and email accounts as well, along with bank account details.
A Sheep in Wolf’s Clothing – Finding RCE in HP’s Printer Fleet
http://ift.tt/2zmhbGJ
Submitted November 21, 2017 at 01:01AM by breen-machine
via reddit http://ift.tt/2zSwfLF
http://ift.tt/2zmhbGJ
Submitted November 21, 2017 at 01:01AM by breen-machine
via reddit http://ift.tt/2zSwfLF
Foxglovesecurity
A Sheep in Wolf’s Clothing – Finding RCE in HP’s Printer Fleet
By @breenmachine Sometimes the marketing department goes a little too far. Most of us who work in security have been there, non-technical people enthusiastic about selling the technical feat…