Return of Bleichenbacher's Oracle Threat (ROBOT)
https://robotattack.org
Submitted December 12, 2017 at 08:35PM by KernelJay
via reddit http://ift.tt/2BIOqEO
https://robotattack.org
Submitted December 12, 2017 at 08:35PM by KernelJay
via reddit http://ift.tt/2BIOqEO
robotattack.org
The ROBOT Attack
Return of Bleichenbacher's Oracle Threat - ROBOT is the return of a 19-year-old vulnerability that allows performing RSA decryption and signing operations with the private key of a TLS server.
VERT Threat Alert: Return of Bleichenbacher’s Oracle Threat (ROBOT)
http://ift.tt/2BeEuSR
Submitted December 12, 2017 at 08:37PM by nanooonanooo
via reddit http://ift.tt/2jBf0sf
http://ift.tt/2BeEuSR
Submitted December 12, 2017 at 08:37PM by nanooonanooo
via reddit http://ift.tt/2jBf0sf
The State of Security
VERT Threat Alert: Return of Bleichenbacher’s Oracle Threat (ROBOT)
A team of researchers has announced that TLS stacks from at least seven different vendors are vulnerable to a well-known 19-year-old protocol flaw (ROBOT).
The ROBOT Attack
http://ift.tt/2AdSOay
Submitted December 12, 2017 at 09:06PM by speckz
via reddit http://ift.tt/2z3I1BE
http://ift.tt/2AdSOay
Submitted December 12, 2017 at 09:06PM by speckz
via reddit http://ift.tt/2z3I1BE
robotattack.org
The ROBOT Attack
Return of Bleichenbacher's Oracle Threat - ROBOT is the return of a 19-year-old vulnerability that allows performing RSA decryption and signing operations with the private key of a TLS server.
HP leaves accidental keylogger in laptop keyboard driver
http://ift.tt/2ygl6Q0
Submitted December 12, 2017 at 08:56PM by EvanConover
via reddit http://ift.tt/2AdUlxe
http://ift.tt/2ygl6Q0
Submitted December 12, 2017 at 08:56PM by EvanConover
via reddit http://ift.tt/2AdUlxe
Naked Security
HP leaves accidental keylogger in laptop keyboard driver
HP didnt beat around the bush – when a researcher found a left-over keylogger, the company fessed up and fixed it fast. Result!
How secure is online backup/cloud services such as Crashplan, Backblaze, Dropbox, etc
No text found
Submitted December 12, 2017 at 08:45PM by mscaff
via reddit http://ift.tt/2z3I54m
No text found
Submitted December 12, 2017 at 08:45PM by mscaff
via reddit http://ift.tt/2z3I54m
reddit
How secure is online backup/cloud services such as... • r/security
2 points and 2 comments so far on reddit
Analysis of File-Spider Ransomware
http://ift.tt/2ygCOCO
Submitted December 12, 2017 at 10:35PM by bill__24
via reddit http://ift.tt/2kqKFIW
http://ift.tt/2ygCOCO
Submitted December 12, 2017 at 10:35PM by bill__24
via reddit http://ift.tt/2kqKFIW
Sdkhere
Analysis of File-Spider Ransomware
FileSpider Ransomware, Spider Ransomware, Spider, Ransomware, MSIL Ransomware
GDPR WARNING: Do not forget about mobile apps when planning for GDPR
http://ift.tt/2jSZk01
Submitted December 12, 2017 at 11:48PM by Mi3Security
via reddit http://ift.tt/2kqSiPC
http://ift.tt/2jSZk01
Submitted December 12, 2017 at 11:48PM by Mi3Security
via reddit http://ift.tt/2kqSiPC
Mi3 Security
GDPR WARNING: Do not forget about mobile apps when planning for GDPR
General Data Protection Regulation (GDPR) is the new regulation to protect EU citizens’ personal data, replacing the current directive from 1995 and establishing a single set of rules across the European Union. GDPR outlines a set of obligations for organizations…
Phishers Are Upping Their Game. So Should You.
http://ift.tt/2jTAcq7
Submitted December 12, 2017 at 11:42PM by volci
via reddit http://ift.tt/2yiGP9N
http://ift.tt/2jTAcq7
Submitted December 12, 2017 at 11:42PM by volci
via reddit http://ift.tt/2yiGP9N
reddit
Phishers Are Upping Their Game. So Should You. • r/security
2 points and 0 comments so far on reddit
Multiple vulnerabilities in glibc's ld.so
http://ift.tt/2Bb2O7F
Submitted December 12, 2017 at 11:13PM by petermal67
via reddit http://ift.tt/2l0Q39E
http://ift.tt/2Bb2O7F
Submitted December 12, 2017 at 11:13PM by petermal67
via reddit http://ift.tt/2l0Q39E
reddit
Multiple vulnerabilities in glibc's ld.so • r/netsec
2 points and 1 comments so far on reddit
Best Practices for Verifying Vuln Fixes
http://ift.tt/2BgXzUm
Submitted December 13, 2017 at 12:12AM by ju1i3k
via reddit http://ift.tt/2jzSfom
http://ift.tt/2BgXzUm
Submitted December 13, 2017 at 12:12AM by ju1i3k
via reddit http://ift.tt/2jzSfom
Cobalt.io
Best Practices for Verifying Vuln Fixes
The pen test lifecycle is coming to a close. The previous posts have weighed heavily on getting the process started and running smoothly…
Why you can break encryption on a CD but not a VPN connection?
No text found
Submitted December 13, 2017 at 12:44AM by G0rd0nGekk0
via reddit http://ift.tt/2z47XNC
No text found
Submitted December 13, 2017 at 12:44AM by G0rd0nGekk0
via reddit http://ift.tt/2z47XNC
reddit
Why you can break encryption on a CD but not a VPN... • r/security
1 points and 1 comments so far on reddit
Looking to get into cybersecurity; Would love some advice.
Hello r/security. My name is Joel and I am fourteen years old. I would love to get into the cybersecurity field, although I don't know where to start.Here's a bit of information about my history within IT and security.I know consumer grade hardware inside-out; Enterprise grade not so much. I have studied to become a sysadmin, although I have been informed that the majority of sysadmins get treated like shit. This means that I have some experience within windows server, and networking. I know most things within windows, although I don't think that'll matter as I believe a lot of cybersecurity stuff is done on Kali, or another Linux distribution.The programming languages I know are: Python, C# and Powershell I know C# to the extent of someone in between 'beginner' and 'intermediate' As far as python goes, I don't really like the language too much; But I do know a bit of normal python e.g. No libraries, just basic stuff. I believe powershell is a noscripting language, but I do know a tiny bit of it.I don't explicitly know where I would like to go in the cybersecurity field, although I know that I want to work in it. To be fair, I don't even know what kind of jobs there are in the cybersecurity field.Essentially, I'm looking for a person to guide me within my cybersecurity career.Any advice on where I should start?I apologize if any of this appeared rude, as I'm not the greatest with phrasing things and grammar.
Submitted December 13, 2017 at 01:16AM by joelazot
via reddit http://ift.tt/2jTrbxd
Hello r/security. My name is Joel and I am fourteen years old. I would love to get into the cybersecurity field, although I don't know where to start.Here's a bit of information about my history within IT and security.I know consumer grade hardware inside-out; Enterprise grade not so much. I have studied to become a sysadmin, although I have been informed that the majority of sysadmins get treated like shit. This means that I have some experience within windows server, and networking. I know most things within windows, although I don't think that'll matter as I believe a lot of cybersecurity stuff is done on Kali, or another Linux distribution.The programming languages I know are: Python, C# and Powershell I know C# to the extent of someone in between 'beginner' and 'intermediate' As far as python goes, I don't really like the language too much; But I do know a bit of normal python e.g. No libraries, just basic stuff. I believe powershell is a noscripting language, but I do know a tiny bit of it.I don't explicitly know where I would like to go in the cybersecurity field, although I know that I want to work in it. To be fair, I don't even know what kind of jobs there are in the cybersecurity field.Essentially, I'm looking for a person to guide me within my cybersecurity career.Any advice on where I should start?I apologize if any of this appeared rude, as I'm not the greatest with phrasing things and grammar.
Submitted December 13, 2017 at 01:16AM by joelazot
via reddit http://ift.tt/2jTrbxd
reddit
Looking to get into cybersecurity; Would love some... • r/security
Hello r/security. My name is Joel and I am fourteen years old. I would love to get into the cybersecurity field, although I don't know where to...
Authoritative DNS Performance Analytics and Comparison
http://ift.tt/2pLNjgM
Submitted December 13, 2017 at 01:45AM by rmddos
via reddit http://ift.tt/2BEvBm3
http://ift.tt/2pLNjgM
Submitted December 13, 2017 at 01:45AM by rmddos
via reddit http://ift.tt/2BEvBm3
Dnsperf
DNS Performance
Compare the speed and uptime of enterprise and commercial DNS services
Detection and recovery of NSA’s covered up tracks
http://ift.tt/2kDyEUr
Submitted December 12, 2017 at 07:53PM by digicat
via reddit http://ift.tt/2jDHfX0
http://ift.tt/2kDyEUr
Submitted December 12, 2017 at 07:53PM by digicat
via reddit http://ift.tt/2jDHfX0
Fox-IT International blog
Detection and recovery of NSA’s covered up tracks
Part of the NSA cyber weapon framework DanderSpritz is eventlogedit, a piece of software capable of removing individual lines from Windows Event Log files. Now that this tool is leaked and public, …
Got a verification email from "Huobi", which is something I have never used. What do I do?
I just received this email:Hello, Welcome to Huobi! You have recently received instructions to enter a one-time authentication code to create your Huobi account. Your code is: XXXXXX For security reasons, this code will expire in 30 minutes. Sincerely, The Huobi Team https://www.huobi.proI have no idea what Huobi is and I have never used it before. I immediately changed my email password. Is there anything else I should do?
Submitted December 13, 2017 at 02:29AM by noxumida
via reddit http://ift.tt/2BGHSGI
I just received this email:Hello, Welcome to Huobi! You have recently received instructions to enter a one-time authentication code to create your Huobi account. Your code is: XXXXXX For security reasons, this code will expire in 30 minutes. Sincerely, The Huobi Team https://www.huobi.proI have no idea what Huobi is and I have never used it before. I immediately changed my email password. Is there anything else I should do?
Submitted December 13, 2017 at 02:29AM by noxumida
via reddit http://ift.tt/2BGHSGI
Security ChatOps Checklist: How to Evaluate Your SOC’s Readiness For ChatOps
http://ift.tt/2l3S6dg
Submitted December 13, 2017 at 02:25AM by abhishekiyer
via reddit http://ift.tt/2AfU6BL
http://ift.tt/2l3S6dg
Submitted December 13, 2017 at 02:25AM by abhishekiyer
via reddit http://ift.tt/2AfU6BL
Demisto
Security ChatOps Checklist: How to Evaluate Your SOC’s Readiness For ChatOps
Security ChatOps is setting analysts abuzz. Learn how to evaluate your SOC's readiness to implement Security ChatOps with a comprehensive checklist.
Introducing Anubis, a new subdomain enumeration and information gathering tool
http://ift.tt/2BGWLcg
Submitted December 13, 2017 at 03:50AM by JonLuca
via reddit http://ift.tt/2z3QaWL
http://ift.tt/2BGWLcg
Submitted December 13, 2017 at 03:50AM by JonLuca
via reddit http://ift.tt/2z3QaWL
GitHub
jonluca/Anubis
🔓Subdomain enumeration and information gathering tool - jonluca/Anubis
What We Can Learn From The Uber Hack And Response
http://ift.tt/2AOAS7C
Submitted December 13, 2017 at 04:10AM by abhishekiyer
via reddit http://ift.tt/2BZmLLT
http://ift.tt/2AOAS7C
Submitted December 13, 2017 at 04:10AM by abhishekiyer
via reddit http://ift.tt/2BZmLLT
reddit
What We Can Learn From The Uber Hack And Response • r/security
1 points and 0 comments so far on reddit
Popular Destinations rerouted to Russia - 80 prefixes normally announced by organizations such Google, Apple, Facebook, Microsoft, Twitch, NTT Communications and Riot Games were redirected during two event windows of about three minutes each
http://ift.tt/2C6Ahyf
Submitted December 13, 2017 at 03:55AM by speckz
via reddit http://ift.tt/2BcV05Z
http://ift.tt/2C6Ahyf
Submitted December 13, 2017 at 03:55AM by speckz
via reddit http://ift.tt/2BcV05Z
reddit
Popular Destinations rerouted to Russia - 80 prefixes... • r/security
1 points and 0 comments so far on reddit
Anyone know when Duo Security will support Pulse Connect Secure 8.3Rx?
EDIT: I'm an idiot. I didn't have DNS configured properly on my new 8.3 Pulse VM, so it couldn't reach any URLs. Fixed DNS and Duo works...Original post below: At the moment, Duo only supports Pulse Connect Secure 8.2Rx. Anyone in the loop on when they may update their integration? I have the free Duo account, so I can't ask Duo directly.Source: http://ift.tt/2C7hYJn
Submitted December 13, 2017 at 05:04AM by iPhoid
via reddit http://ift.tt/2nUvU67
EDIT: I'm an idiot. I didn't have DNS configured properly on my new 8.3 Pulse VM, so it couldn't reach any URLs. Fixed DNS and Duo works...Original post below: At the moment, Duo only supports Pulse Connect Secure 8.2Rx. Anyone in the loop on when they may update their integration? I have the free Duo account, so I can't ask Duo directly.Source: http://ift.tt/2C7hYJn
Submitted December 13, 2017 at 05:04AM by iPhoid
via reddit http://ift.tt/2nUvU67
Duo Security
Two-Factor Authentication for Pulse Secure SSL VPN
Duo integrates with your Pulse Connect Secure SSL VPN to add tokenless two-factor authentication to any VPN login.
XXE - Things Are Getting Out of Band
http://ift.tt/2Axe6Ea
Submitted December 13, 2017 at 05:03AM by ZephrX112
via reddit http://ift.tt/2AOZmNU
http://ift.tt/2Axe6Ea
Submitted December 13, 2017 at 05:03AM by ZephrX112
via reddit http://ift.tt/2AOZmNU
ZeroSec - Adventures In Information Security
XXE - Things Are Getting Out of Band
XXE Out of Band testing, explaining how to execute XXE OOB attacks over HTTP & FTP. Additional explanation on XXE RCE.