5 Reasons Cyber Defense Is Like Healthcare
http://ift.tt/2i0L9og
Submitted November 29, 2017 at 07:11PM by Uminekoshi
via reddit http://ift.tt/2j0gLeM
http://ift.tt/2i0L9og
Submitted November 29, 2017 at 07:11PM by Uminekoshi
via reddit http://ift.tt/2j0gLeM
Nehemiah Security
5 Reasons Cyber Defense Is Like Healthcare - Nehemiah Security
Let’s face it, enterprise information systems can be large, complex ecosystems that preclude anyone from completely understanding all aspects of them. Thirty years ago, a few endpoints were cobbled together on a single LAN and everyone marveled at how characters…
Anatomy of an ASP.NET Identity PasswordHash
http://ift.tt/2Akh1PO
Submitted November 29, 2017 at 06:57PM by ruidfigueiredo
via reddit http://ift.tt/2Bx4B4y
http://ift.tt/2Akh1PO
Submitted November 29, 2017 at 06:57PM by ruidfigueiredo
via reddit http://ift.tt/2Bx4B4y
The Blinking Caret
Anatomy of an ASP.NET Identity PasswordHash - The Blinking Caret
This blog post explains how password storage is performed in ASP.NET Identity V2 and V3. It provides a guide on how to manually create a PasswordHash.
Exploring cmdkey: An Edge Case for Privilege Escalation
http://ift.tt/2AlGSqg
Submitted November 29, 2017 at 06:33PM by swizzlez_
via reddit http://ift.tt/2iikwPw
http://ift.tt/2AlGSqg
Submitted November 29, 2017 at 06:33PM by swizzlez_
via reddit http://ift.tt/2iikwPw
Peew.pw
Exploring cmdkey: An Edge Case for Privilege Escalation
In this post we look at how credentials cached via cmdkey.exe can be used as a method of privilege escalation on an internal penetration test.
The Best Employee Monitoring Software of 2017
http://ift.tt/2Af1yjj
Submitted November 29, 2017 at 08:46PM by Ndubs526
via reddit http://ift.tt/2AkZ5lw
http://ift.tt/2Af1yjj
Submitted November 29, 2017 at 08:46PM by Ndubs526
via reddit http://ift.tt/2AkZ5lw
PCMAG
The Best Employee Monitoring Software of 2017
It's important to have visibility into what your onsite and remote employees are doing while on the clock. We test five employee monitoring tools for tracking user productivity, application and website activity, screen capture and alerts, and much more.
Conference calls present a significant and overlooked security gap in the enterprise, according to a new research study from LoopUp
http://ift.tt/2ijAjxu
Submitted November 29, 2017 at 09:08PM by EvanConover
via reddit http://ift.tt/2Aj0s6R
http://ift.tt/2ijAjxu
Submitted November 29, 2017 at 09:08PM by EvanConover
via reddit http://ift.tt/2Aj0s6R
Infosecurity Magazine
Conference Calls a ‘Significant & Overlooked’ Security Gap in the Enterprise
66% of professionals use the same passcodes to dial-in to calls for up to a year or more
Choosing a password manager
http://ift.tt/2kdjlSl
Submitted November 29, 2017 at 10:06PM by nzwasp
via reddit http://ift.tt/2Bwy26U
http://ift.tt/2kdjlSl
Submitted November 29, 2017 at 10:06PM by nzwasp
via reddit http://ift.tt/2Bwy26U
Security Breach Online
Choosing a password manager - Security Breach Online
Credential theft is a challenging vulnerability to mitigate since it exploits a feature - that users must be able to log on to networks
"How Can I Tell This is an Attack? - Amazon Support Phish"
http://ift.tt/2kaNwt9
Submitted November 29, 2017 at 09:52PM by volci
via reddit http://ift.tt/2AHQOLE
http://ift.tt/2kaNwt9
Submitted November 29, 2017 at 09:52PM by volci
via reddit http://ift.tt/2AHQOLE
securingthehuman.sans.org
Security Awareness Blog | How Can I Tell This is an Attack? - Amazon Support Phish
Security Awareness Blog blog pertaining to How Can I Tell This is an Attack? - Amazon Support Phish
Apple releases Security Update patching root password vulnerability for High Sierra.
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 10:10PM by cuenta_tres
via reddit http://ift.tt/2ikLCp9
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 10:10PM by cuenta_tres
via reddit http://ift.tt/2ikLCp9
Apple Support
About the security content of Security Update 2017-001
This document describes the security content of Security Update 2017-001.
ROKRAT Reloaded
http://ift.tt/2AmgYmg
Submitted November 29, 2017 at 10:08PM by kink0
via reddit http://ift.tt/2iiHdTN
http://ift.tt/2AmgYmg
Submitted November 29, 2017 at 10:08PM by kink0
via reddit http://ift.tt/2iiHdTN
Talosintelligence
ROKRAT Reloaded
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Gain Root Access ~Remotely~ with Newly Discovered Vulnerability Within macOS High Sierra
http://ift.tt/2zAewF7
Submitted November 29, 2017 at 10:38PM by goopcat
via reddit http://ift.tt/2j0I6xs
http://ift.tt/2zAewF7
Submitted November 29, 2017 at 10:38PM by goopcat
via reddit http://ift.tt/2j0I6xs
Independent Security Evaluators
Gain Root Access Remotely with Newly Discovered Vulnerability Within macOS High Sierra
How an attacker gains root remotely on macOS High Sierra (no password needed) and how to protect yourself from this vulnerability.
Security update for High Sierra root issue released
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 09:51PM by faderprime
via reddit http://ift.tt/2AmTq0Z
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 09:51PM by faderprime
via reddit http://ift.tt/2AmTq0Z
Apple Support
About the security content of Security Update 2017-001
This document describes the security content of Security Update 2017-001.
Apple has issued a patch regarding the root login problem
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 11:23PM by railedit
via reddit http://ift.tt/2zBNdKG
http://ift.tt/2k9Gsgq
Submitted November 29, 2017 at 11:23PM by railedit
via reddit http://ift.tt/2zBNdKG
Apple Support
About the security content of Security Update 2017-001
This document describes the security content of Security Update 2017-001.
Resources for android and iOS internal security mechanisms and comparison of them
Hello,I hate the "android vs iOS" flame war, so I'll just set the scope a bit. First of all I'm a pentester and security enthusiast, so I'm interested in deep tech stuff, not "apple got hacked" and "enable remote wipe" stuff.What I'm really searching is research material for both operating systems and devices. I want to do a personal research, as I'm really tempted to switch to iOS. The reason is that I want a smartphone secure enough to carry my private key.The threat model includes of course remote access, via internet or lan (both WiFi and 2g/3g/4g), local physical unauthorized access post-boot (unattended device with locked screen) and pre-boot.Nontrivial hardware tampering is out of scope (crack open the device). The serial console that the nexus 5/5x has on the headphone jack, is though IN scope.As a result, device specific resources might be needed (talking about android devices), as they have different hardware.I'm as much concerned about privacy as with security.Take into account that android has many flavors, so I want to compare only the most hardened (such as copperheados), without root or xposed framework.If you want to narrow your answer a bit, focus on the Pixel line by google (gets security updates by google first and supported and recommended by copperheados) and especially on the pixel XL and iPhone 8+ (as these are the devices I'm between). If you have another model/vendor in mind, that's cool too.
Submitted November 30, 2017 at 12:08AM by 01ttouch
via reddit http://ift.tt/2AgTTkQ
Hello,I hate the "android vs iOS" flame war, so I'll just set the scope a bit. First of all I'm a pentester and security enthusiast, so I'm interested in deep tech stuff, not "apple got hacked" and "enable remote wipe" stuff.What I'm really searching is research material for both operating systems and devices. I want to do a personal research, as I'm really tempted to switch to iOS. The reason is that I want a smartphone secure enough to carry my private key.The threat model includes of course remote access, via internet or lan (both WiFi and 2g/3g/4g), local physical unauthorized access post-boot (unattended device with locked screen) and pre-boot.Nontrivial hardware tampering is out of scope (crack open the device). The serial console that the nexus 5/5x has on the headphone jack, is though IN scope.As a result, device specific resources might be needed (talking about android devices), as they have different hardware.I'm as much concerned about privacy as with security.Take into account that android has many flavors, so I want to compare only the most hardened (such as copperheados), without root or xposed framework.If you want to narrow your answer a bit, focus on the Pixel line by google (gets security updates by google first and supported and recommended by copperheados) and especially on the pixel XL and iPhone 8+ (as these are the devices I'm between). If you have another model/vendor in mind, that's cool too.
Submitted November 30, 2017 at 12:08AM by 01ttouch
via reddit http://ift.tt/2AgTTkQ
reddit
Resources for android and iOS internal security... • r/security
Hello, I hate the "android vs iOS" flame war, so I'll just set the scope a bit. First of all I'm a pentester and security enthusiast, so I'm...
Is it dangerous to mine litecoin?
Does it open up your computer/network to hacking, etc?
Submitted November 30, 2017 at 01:05AM by Nateispineapple
via reddit http://ift.tt/2ikIARS
Does it open up your computer/network to hacking, etc?
Submitted November 30, 2017 at 01:05AM by Nateispineapple
via reddit http://ift.tt/2ikIARS
reddit
Is it dangerous to mine litecoin? • r/security
Does it open up your computer/network to hacking, etc?
Tips is help me to create a powerful password which also remember very easily for my online security. Very good, Give it a try
https://youtube.com/watch?v=wSA011eQ784
Submitted November 30, 2017 at 02:27AM by myS_Cross
via reddit http://ift.tt/2BleL7O
https://youtube.com/watch?v=wSA011eQ784
Submitted November 30, 2017 at 02:27AM by myS_Cross
via reddit http://ift.tt/2BleL7O
YouTube
Create Strong Passwords that You Can Actually Remember 👨💻
Passwords are essential thing to protect our sensitive informations, but when we are going to make stronger passwords we can not able to remember them. so in...
Car stolen without using a key
http://ift.tt/2jpqLgY
Submitted November 30, 2017 at 03:09AM by whodewhode
via reddit http://ift.tt/2imPPZR
http://ift.tt/2jpqLgY
Submitted November 30, 2017 at 03:09AM by whodewhode
via reddit http://ift.tt/2imPPZR
BBC News
Car stolen without using a key
This footage from West Midlands Police shows two men pulling up outside a victim's house and stealing a car without needing to see the owner's keys.
MS15-011 Remote Execution Buffer Overflow Server 2003 SP2
i get there are no patches released for this OS version. a user with this expertise came back to me and asked if it's sufficient if he/she blocked TCP 445, i kicked off a Nmap scan, it shows 445 closed, but 137 & 139 are opened. is blocking 445 sufficient or do they need to do more with 137/139? anything will help, thank you!
Submitted November 30, 2017 at 03:39AM by xbadazzx
via reddit http://ift.tt/2Apghca
i get there are no patches released for this OS version. a user with this expertise came back to me and asked if it's sufficient if he/she blocked TCP 445, i kicked off a Nmap scan, it shows 445 closed, but 137 & 139 are opened. is blocking 445 sufficient or do they need to do more with 137/139? anything will help, thank you!
Submitted November 30, 2017 at 03:39AM by xbadazzx
via reddit http://ift.tt/2Apghca
reddit
MS15-011 Remote Execution Buffer Overflow Server 2003 SP2 • r/security
i get there are no patches released for this OS version. a user with this expertise came back to me and asked if it's sufficient if he/she blocked...
Security Now 639 News & Feedback | TWiT.TV
http://ift.tt/2zO5cBQ
Submitted November 30, 2017 at 05:03AM by dmp1ce
via reddit http://ift.tt/2AnXrCk
http://ift.tt/2zO5cBQ
Submitted November 30, 2017 at 05:03AM by dmp1ce
via reddit http://ift.tt/2AnXrCk
TWiT.tv
Security Now 639 News & Feedback | TWiT.TV
This week we discuss a new bad bug found in the majority of SMTP mailing agents, 54 high-end HP printers found to be remotely exploitable, more than 3/4ths of 433,000 websites are …
Hey r/security, looking for laptop recommendations for a crypto trader
Hello all, I am looking into getting a laptop for security reasons because I will be using the laptop for crypto trading and daily handling of crypto assets. Is there a specific laptop that would be best? I'm looking into purism laptops, but am looking for something a little cheaper. Any suggestions will be appreciated
Submitted November 30, 2017 at 06:01AM by xGhJuZcvijDhwQvvNzZT
via reddit http://ift.tt/2i3IScc
Hello all, I am looking into getting a laptop for security reasons because I will be using the laptop for crypto trading and daily handling of crypto assets. Is there a specific laptop that would be best? I'm looking into purism laptops, but am looking for something a little cheaper. Any suggestions will be appreciated
Submitted November 30, 2017 at 06:01AM by xGhJuZcvijDhwQvvNzZT
via reddit http://ift.tt/2i3IScc
reddit
Hey r/security, looking for laptop recommendations... • r/security
Hello all, I am looking into getting a laptop for security reasons because I will be using the laptop for crypto trading and daily handling of...
Fantastic article on Red Teaming
http://ift.tt/2ne04kI
Submitted November 30, 2017 at 06:34AM by Tawnii
via reddit http://ift.tt/2Alohux
http://ift.tt/2ne04kI
Submitted November 30, 2017 at 06:34AM by Tawnii
via reddit http://ift.tt/2Alohux
AlienVault
6 Animals Associated with Red Team
Sure, we've had some interesting, educational and factual blogs about Red Teaming in the past, such as:Red Teamers Can Learn Secrets by Purple Teaming
Red teams; a diary from the garden of Red versus Blue
Be a Red Teamer to be a Better Blue Teamer: Pen Testing…
Red teams; a diary from the garden of Red versus Blue
Be a Red Teamer to be a Better Blue Teamer: Pen Testing…
Here's What I'm Telling US Congress about Data Breaches
http://ift.tt/2AkR56I
Submitted November 30, 2017 at 06:07AM by ben_a_adams
via reddit http://ift.tt/2zOPu9r
http://ift.tt/2AkR56I
Submitted November 30, 2017 at 06:07AM by ben_a_adams
via reddit http://ift.tt/2zOPu9r
Troy Hunt
Here's What I'm Telling US Congress about Data Breaches
Last week I wrote about my upcoming congressional testimony and wow - you guys are awesome! Seriously, the feedback there was absolutely sensational and it's helped shaped what I'll be saying to the US Congress, including lifting specific wording and phrases…