Pins and Staples: Enhanced SSL Security
http://ift.tt/2zYng9j
Submitted November 20, 2017 at 09:31PM by fang0654
via reddit http://ift.tt/2zT3lKO
http://ift.tt/2zYng9j
Submitted November 20, 2017 at 09:31PM by fang0654
via reddit http://ift.tt/2zT3lKO
Depthsecurity
Pins and Staples: Enhanced SSL Security
With Chrome backing away from HTTP Public Key Pinning and other industry thought-leaders calling for its death, I figured I'd take some time to review some
Fully undetectable backdooring PE files
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:07PM by InformationSecurity
via reddit http://ift.tt/2AXUZiy
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:07PM by InformationSecurity
via reddit http://ift.tt/2AXUZiy
Haider Mahmood Infosec Blog
Fully undetectable backdooring PE files
Table of Contents1 Introduction2 Self Imposed Restrictions3 Methods used:4 Criteria for PE file selection for implanting backdoor4.1 ASLR: 4.2 Static Analysis5 Backdooring PE file6 Adding a new Section header method6.1 Hijack Execution Flow6.2 Adding Shellcode6.3…
Fully undetectable backdooring of portable executable files
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:43PM by InformationSecurity
via reddit http://ift.tt/2zVNNWV
http://ift.tt/2zms9f9
Submitted November 20, 2017 at 09:43PM by InformationSecurity
via reddit http://ift.tt/2zVNNWV
Haider Mahmood Infosec Blog
Fully undetectable backdooring PE files
Table of Contents1 Introduction2 Self Imposed Restrictions3 Methods used:4 Criteria for PE file selection for implanting backdoor4.1 ASLR: 4.2 Static Analysis5 Backdooring PE file6 Adding a new Section header method6.1 Hijack Execution Flow6.2 Adding Shellcode6.3…
Has BYOD taken over your office? Here are 3 strategies in securing your data
http://ift.tt/2izMxPE
Submitted November 20, 2017 at 09:57PM by dj3poka
via reddit http://ift.tt/2mKgIrL
http://ift.tt/2izMxPE
Submitted November 20, 2017 at 09:57PM by dj3poka
via reddit http://ift.tt/2mKgIrL
Tgdaily
Has BYOD taken over your office? Here are 3 strategies in securing your data
BYOD, or bring-your-own-device, had been a buzzword in the enterprise and small business community since the mid 2000s. When smartphones and tablets came into fashion, not all businesses were ready to spend for their employees’ device needs.
Glad to see this finally happening: U.S. nails Kentucky gas-pump skimmers. Made $3.5M from ~50 pumps
http://ift.tt/2zkTvlU
Submitted November 20, 2017 at 09:53PM by MadSecuritySquirrel
via reddit http://ift.tt/2mKgRvj
http://ift.tt/2zkTvlU
Submitted November 20, 2017 at 09:53PM by MadSecuritySquirrel
via reddit http://ift.tt/2mKgRvj
Arkansas Online
U.S. nails Kentucky gas-pump skimmers
LOUISVILLE, Ky. -- Federal authorities pointed Friday to multiple arrests and convictions in Kentucky as just the start of a crackdown on credit card skimmers who target gas pumps to steal personal information.
Android Bug Lets Attackers Record Audio & Screen Activity on 3 of 4 Smartphones
http://ift.tt/2zh6WmR
Submitted November 20, 2017 at 09:50PM by MadSecuritySquirrel
via reddit http://ift.tt/2zkTApI
http://ift.tt/2zh6WmR
Submitted November 20, 2017 at 09:50PM by MadSecuritySquirrel
via reddit http://ift.tt/2zkTApI
BleepingComputer
Android Bug Lets Attackers Record Audio & Screen Activity on 3 of 4 Smartphones
Android smartphones running Lolipop, Marshmallow, and Nougat, are vulnerable to an attack that exploits the MediaProjection service to capture the user's screen and record system audio
Modifying and Building Burp Extensions
http://ift.tt/2wyoTeK
Submitted November 20, 2017 at 10:29PM by Mempodipper
via reddit http://ift.tt/2zYTv8e
http://ift.tt/2wyoTeK
Submitted November 20, 2017 at 10:29PM by Mempodipper
via reddit http://ift.tt/2zYTv8e
DecidedlyGray
Modifying and Building Burp Extensions
Reference on modifying and repackaging, as well as compiling Burp Suite extensions from source.
"lspitzner"
http://ift.tt/2izMun0
Submitted November 20, 2017 at 11:37PM by volci
via reddit http://ift.tt/2zYmrNw
http://ift.tt/2izMun0
Submitted November 20, 2017 at 11:37PM by volci
via reddit http://ift.tt/2zYmrNw
securingthehuman.sans.org
Security Awareness Blog | lspitzner
Security Awareness Blog blog pertaining to lspitzner
VU#817544. Windows ASLR Vulnerability
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:35PM by bagaudin
via reddit http://ift.tt/2AWSOvq
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:35PM by bagaudin
via reddit http://ift.tt/2AWSOvq
www.kb.cert.org
Vulnerability Note VU#817544 - Windows 8 and later fail to properly randomize every application if system-wide mandatory ASLR is…
Microsoft Windows 8 introduced a change in how system-wide mandatory ASLR is implemented. This change requires system-wide bottom-up ASLR to be enabled for mandatory ASLR to receive entropy. Tools that enable system-wide ASLR without also setting bottom-up…
VU#817544. Windows ASLR Vulnerability
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:48PM by bagaudin
via reddit http://ift.tt/2zll52F
http://ift.tt/2zaxJ4a
Submitted November 20, 2017 at 11:48PM by bagaudin
via reddit http://ift.tt/2zll52F
www.kb.cert.org
Vulnerability Note VU#817544 - Windows 8 and later fail to properly randomize every application if system-wide mandatory ASLR is…
Microsoft Windows 8 introduced a change in how system-wide mandatory ASLR is implemented. This change requires system-wide bottom-up ASLR to be enabled for mandatory ASLR to receive entropy. Tools that enable system-wide ASLR without also setting bottom-up…
TP-Link serves no or outdated firmware on 30% of its European websites
http://ift.tt/2B7qDuP
Submitted November 20, 2017 at 11:29PM by Aeyoun
via reddit http://ift.tt/2hF1n6q
http://ift.tt/2B7qDuP
Submitted November 20, 2017 at 11:29PM by Aeyoun
via reddit http://ift.tt/2hF1n6q
Ctrl blog
TP-Link serves outdated or no firmware at all on 30% of its European websites
TP-Link uses the same firmware in most of Europe, but fails to keep their regional websites up to date with the latest versions.
Banking Trojan Gains Ability to Steal Facebook, Twitter and Gmail Accounts
http://ift.tt/2zNGmAN
Submitted November 21, 2017 at 12:02AM by volci
via reddit http://ift.tt/2AXWhd7
http://ift.tt/2zNGmAN
Submitted November 21, 2017 at 12:02AM by volci
via reddit http://ift.tt/2AXWhd7
The Hacker News
Banking Trojan Gains Ability to Steal Facebook, Twitter and Gmail Accounts
Security researchers have discovered a new variant of Terdot banking Trojan that steals social media and email accounts as well, along with bank account details.
A Sheep in Wolf’s Clothing – Finding RCE in HP’s Printer Fleet
http://ift.tt/2zmhbGJ
Submitted November 21, 2017 at 01:01AM by breen-machine
via reddit http://ift.tt/2zSwfLF
http://ift.tt/2zmhbGJ
Submitted November 21, 2017 at 01:01AM by breen-machine
via reddit http://ift.tt/2zSwfLF
Foxglovesecurity
A Sheep in Wolf’s Clothing – Finding RCE in HP’s Printer Fleet
By @breenmachine Sometimes the marketing department goes a little too far. Most of us who work in security have been there, non-technical people enthusiastic about selling the technical feat…
"The Security Awareness Board Game - At the EU #SecAwareSummit"
http://ift.tt/2mIBkRc
Submitted November 21, 2017 at 01:37AM by volci
via reddit http://ift.tt/2hQRwhE
http://ift.tt/2mIBkRc
Submitted November 21, 2017 at 01:37AM by volci
via reddit http://ift.tt/2hQRwhE
securingthehuman.sans.org
Security Awareness Blog | The Security Awareness Board Game - At the EU #SecAwareSummit
Security Awareness Blog blog pertaining to The Security Awareness Board Game - At the EU #SecAwareSummit
OWASP Top 10 - 2017 (pdf)
http://ift.tt/2z4aViD
Submitted November 21, 2017 at 02:21AM by based2
via reddit http://ift.tt/2B7UFye
http://ift.tt/2z4aViD
Submitted November 21, 2017 at 02:21AM by based2
via reddit http://ift.tt/2B7UFye
Man gets threats—not bug bounty—after finding DJI customer data in public view
http://ift.tt/2zbOV9y
Submitted November 21, 2017 at 02:51AM by speckz
via reddit http://ift.tt/2hPzY5q
http://ift.tt/2zbOV9y
Submitted November 21, 2017 at 02:51AM by speckz
via reddit http://ift.tt/2hPzY5q
Ars Technica
Man gets threats—not bug bounty—after finding DJI customer data in public view
A bug bounty hunter shared evidence; DJI called him a hacker and threatened with CFAA.
[Part 1] - Analysis the new Linux/AES.DDoS IoT malware
http://ift.tt/2mM3DhP
Submitted November 21, 2017 at 03:28AM by LloydLabs
via reddit http://ift.tt/2izGRFi
http://ift.tt/2mM3DhP
Submitted November 21, 2017 at 03:28AM by LloydLabs
via reddit http://ift.tt/2izGRFi
reddit
[Part 1] - Analysis the new Linux/AES.DDoS IoT malware • r/netsec
reddit: the front page of the internet
Intel audits their management engine and surprises fucking nobody
http://ift.tt/2iAjwDe
Submitted November 21, 2017 at 03:21AM by SlackerCrewsic
via reddit http://ift.tt/2AYeI1v
http://ift.tt/2iAjwDe
Submitted November 21, 2017 at 03:21AM by SlackerCrewsic
via reddit http://ift.tt/2AYeI1v
reddit
Intel audits their management engine and surprises... • r/netsec
3 points and 1 comments so far on reddit
Mobile banking Trojan sneaks into Google Play targeting Wells Fargo, Chase and Citibank customers
http://ift.tt/2z2CvNa
Submitted November 21, 2017 at 04:05AM by EvanConover
via reddit http://ift.tt/2zlakNN
http://ift.tt/2z2CvNa
Submitted November 21, 2017 at 04:05AM by EvanConover
via reddit http://ift.tt/2zlakNN
Avast
Mobile banking Trojan sneaks into Google Play targeting Wells Fargo, Chase and Citibank customers
Malicious mobile BankBot Trojan injected into everyday apps, taking advantage of unknowing users whose banking apps could be compromised
[Part 1] - Analysing the new Linux/AES.DDoS IoT malware.
http://ift.tt/2mM3DhP
Submitted November 21, 2017 at 03:49AM by LloydLabs
via reddit http://ift.tt/2jH3fA1
http://ift.tt/2mM3DhP
Submitted November 21, 2017 at 03:49AM by LloydLabs
via reddit http://ift.tt/2jH3fA1
reddit
[Part 1] - Analysing the new Linux/AES.DDoS IoT malware. • r/netsec
1 points and 0 comments so far on reddit
The Humble Book Bundle: Java presented by O’Reilly is Live
http://ift.tt/2znSCcf
Submitted November 21, 2017 at 04:28AM by 13378
via reddit http://ift.tt/2hFVfuL
http://ift.tt/2znSCcf
Submitted November 21, 2017 at 04:28AM by 13378
via reddit http://ift.tt/2hFVfuL
Humble Bundle
Humble Book Bundle: Java by O'Reilly
Pay what you want for books on Java and support charity!