Yahoo! Remote Code Execution via Spring Engine Server Side Template Injection
http://ift.tt/2zffiGE
Submitted December 25, 2017 at 01:20PM by chocoluvin
via reddit http://ift.tt/2Dbpan8
http://ift.tt/2zffiGE
Submitted December 25, 2017 at 01:20PM by chocoluvin
via reddit http://ift.tt/2Dbpan8
∞ Growing Web Security Blog
Yahoo! RCE via Spring Engine SSTI
This is write up in which I’ll explain a vulnerability I recently found, and reported through Yahoo’s bug bounty program. In web application security testing, doing reconnaissance is an…
Kali Linux on your Pocket: Kali 2017.3 on GPD 7 mini-laptop
http://ift.tt/2DKGUqL
Submitted December 25, 2017 at 04:55PM by Orlin82
via reddit http://ift.tt/2kS5qP2
http://ift.tt/2DKGUqL
Submitted December 25, 2017 at 04:55PM by Orlin82
via reddit http://ift.tt/2kS5qP2
Medium
Kali Linux on your Pocket: Kali 2017.3 on GPD 7 mini-laptop.
About teen weeks ago I bought a GPD Pocket 7 a mini-PC the size of a portable video game console that sports a quad-core Intel Z8750 CPU…
Machine Learning for Cybercriminals
http://ift.tt/2klG37J
Submitted December 25, 2017 at 08:31PM by alexander_polyakov
via reddit http://ift.tt/2kUFimy
http://ift.tt/2klG37J
Submitted December 25, 2017 at 08:31PM by alexander_polyakov
via reddit http://ift.tt/2kUFimy
ERPScan
Machine Learning for Cybercriminals
The article systemizes information on machine learning for cybercriminals deployment in malicious cyberspace to prepare security teams for imminent threats.
How I Got Paid $0 From the Uber Security Bug Bounty [x-post from /programming]
http://ift.tt/2BuvTZa
Submitted December 26, 2017 at 04:37AM by ElectroNeutrino
via reddit http://ift.tt/2ByQ5ZW
http://ift.tt/2BuvTZa
Submitted December 26, 2017 at 04:37AM by ElectroNeutrino
via reddit http://ift.tt/2ByQ5ZW
Bad passwords - this one from the DISA STIG
Recently learned the “standard” DISA STIG compliant password is asdf1234ASDF!@#$16 characters4-Of-4 compliantAnd stupidly-simple to guess
Submitted December 26, 2017 at 08:11AM by volci
via reddit http://ift.tt/2C9R32j
Recently learned the “standard” DISA STIG compliant password is asdf1234ASDF!@#$16 characters4-Of-4 compliantAnd stupidly-simple to guess
Submitted December 26, 2017 at 08:11AM by volci
via reddit http://ift.tt/2C9R32j
reddit
Bad passwords - this one from the DISA STIG • r/security
Recently learned the “standard” DISA STIG compliant password is asdf1234ASDF!@#$ 16 characters 4-Of-4 compliant And stupidly-simple to guess
Latest Virus Threats News - Cyware
http://ift.tt/2C6dvJH
Submitted December 26, 2017 at 04:32PM by cywarelabs12
via reddit http://ift.tt/2C7TzDV
http://ift.tt/2C6dvJH
Submitted December 26, 2017 at 04:32PM by cywarelabs12
via reddit http://ift.tt/2C7TzDV
Cyware
Latest Virus Threats News | Hackers Threats | Cyware
Cyware Present Cyber News on the go. Receive Brief extracts of Latest Virus Threats, Hackers Threats, Actors Threat articles, to keep you informed of the cyber incidents around the world.
Data Connectors Columbus - January 18, 2018
http://ift.tt/2DSoN23
Submitted December 26, 2017 at 05:01PM by cywarelabs12
via reddit http://ift.tt/2pBUfhZ
http://ift.tt/2DSoN23
Submitted December 26, 2017 at 05:01PM by cywarelabs12
via reddit http://ift.tt/2pBUfhZ
Cyware
Data Connectors Columbus | Cyware
The Columbus Cyber Security Conference features 40-60 vendor exhibits and 8-12 educational speaker sessions discussing current cyber-security issues such as cloud security, email security, VoIP, LAN security, wireless security & more. We give away numerous…
LTS SECURE CYBER SOC based on SOAR stack overcome today’s security Challenges
http://ltssoc.com/
Submitted December 26, 2017 at 05:42PM by hardiksoni28111988
via reddit http://ift.tt/2C9vpcd
http://ltssoc.com/
Submitted December 26, 2017 at 05:42PM by hardiksoni28111988
via reddit http://ift.tt/2C9vpcd
Ltssoc
Adaptive SOC platform for cyber security
LTS Secure Intelligence Driven SOC is integrated Context-aware Security protection platforms that provides and integrate prediction, prevention, detection and response capabilities by leveraging adaptive security framework.
Weekly Security Roundup 2017 - Week 51
http://ift.tt/2BDko1J
Submitted December 26, 2017 at 06:05PM by myalcin81
via reddit http://ift.tt/2DPQhp3
http://ift.tt/2BDko1J
Submitted December 26, 2017 at 06:05PM by myalcin81
via reddit http://ift.tt/2DPQhp3
Netsparker
Netsparker's Weekly Security Roundup 2017 - Week 51
A weekly security roundup by Netsparker for week 51 of 2017 - OWASP Top 10, explore Mailspoilt, EV Certificates and Google.
Security In 5: Episode 139 - Top 10 Passwords Used In 2017
http://ift.tt/2lcsjfb
Submitted December 26, 2017 at 07:31PM by BinaryBlog
via reddit http://ift.tt/2DhnLLQ
http://ift.tt/2lcsjfb
Submitted December 26, 2017 at 07:31PM by BinaryBlog
via reddit http://ift.tt/2DhnLLQ
Libsyn
Security In Five Podcast: Episode 139 - Top 10 Passwords Used In 2017
When breaches are disclosed or discovered on the Internet and Dark Web, researches pull together the data an analyze it. Each year a group called SplashData puts together a list of the Top 25 passwords used. The results are pretty sad. This episode runs down…
Some Botconf 2017 talks are up on the site
http://ift.tt/2ARkm6I
Submitted December 26, 2017 at 09:49PM by campuscodi
via reddit http://ift.tt/2C7Psri
http://ift.tt/2ARkm6I
Submitted December 26, 2017 at 09:49PM by campuscodi
via reddit http://ift.tt/2C7Psri
Botconf 2017
Botconf 2017 talks
Tuesday December 5th 2018
14:00-18:00
Workshop 1
Botnet Tracking and Data Analysis Using Open-Source Tools
Olivier Bilodeau; Masarah Paquet-Clouston
14:00-18:00
Workshop 2
Cyber Threat Intel & Incident Response with TheHive, Cortex…
14:00-18:00
Workshop 1
Botnet Tracking and Data Analysis Using Open-Source Tools
Olivier Bilodeau; Masarah Paquet-Clouston
14:00-18:00
Workshop 2
Cyber Threat Intel & Incident Response with TheHive, Cortex…
The Resolutions for a New Year of Vulns
http://ift.tt/2leQhqr
Submitted December 26, 2017 at 09:33PM by ju1i3k
via reddit http://ift.tt/2pGkEvp
http://ift.tt/2leQhqr
Submitted December 26, 2017 at 09:33PM by ju1i3k
via reddit http://ift.tt/2pGkEvp
Cobalt.io
The Resolutions for a New Year of Vulns
Throughout 2017 I explored vuln data to highlight strategies for measuring and maximizing the efficiency of vuln discovery. The primary…
Concise (Post-Christmas) Cryptography Challenges
http://ift.tt/2BSK7ah
Submitted December 26, 2017 at 10:27PM by civicode
via reddit http://ift.tt/2ldxLhQ
http://ift.tt/2BSK7ah
Submitted December 26, 2017 at 10:27PM by civicode
via reddit http://ift.tt/2ldxLhQ
reddit
Concise (Post-Christmas) Cryptography Challenges • r/netsec
1 points and 0 comments so far on reddit
Ham radio vs. hacker communities
http://ift.tt/2C8GutT
Submitted December 27, 2017 at 02:05AM by dn3t
via reddit http://ift.tt/2pASsd0
http://ift.tt/2C8GutT
Submitted December 27, 2017 at 02:05AM by dn3t
via reddit http://ift.tt/2pASsd0
techblog.vsza.hu
VSzA techblog - Ham radio vs. hacker communities
HW/SW x problems/solutions/hacking/abuse
Black Hat Europe 2017 Videos
https://www.youtube.com/playlist?list=PLH15HpR5qRsXtpLirwYHPWyqcEFPbr-uB
Submitted December 26, 2017 at 11:18PM by dezzion
via reddit http://ift.tt/2pDupu8
https://www.youtube.com/playlist?list=PLH15HpR5qRsXtpLirwYHPWyqcEFPbr-uB
Submitted December 26, 2017 at 11:18PM by dezzion
via reddit http://ift.tt/2pDupu8
YouTube
Black Hat Europe 2017 - YouTube
Black Hat Europe 2017 was held at the ExCeL London, December 4-7, 2017. Download Speaker Submitted Materials Here: https://www.blackhat.com/eu-17/briefings.html
[pt-br] FreeBSD Rootkits: A first step into kernel analysis #0 (Fundamentals)
https://www.youtube.com/watch?v=MbEhTkfuz3U
Submitted December 26, 2017 at 11:25AM by thewatcher_
via reddit http://ift.tt/2DUeuuF
https://www.youtube.com/watch?v=MbEhTkfuz3U
Submitted December 26, 2017 at 11:25AM by thewatcher_
via reddit http://ift.tt/2DUeuuF
YouTube
FreeBSD Rootkits: A first step into Kernel Analysis #0 (Fundamentals)
Esse vídeo faz parte de uma nova série lançada pelo MalwareverseBrasil, Iremos abordar todos os aspectos relacionados ao Kernel do FreeBSD e desenvolvimento de Rootkits para o SO.
Professor: Thiago Peixoto (@th1ag0p3x)
Telegram: https://news.1rj.ru/str/MalwareverseBR
Professor: Thiago Peixoto (@th1ag0p3x)
Telegram: https://news.1rj.ru/str/MalwareverseBR
Three Years Later, Hundreds of Sites Still Use Backdoored WordPress Plugins
http://ift.tt/2CbGVpX
Submitted December 27, 2017 at 03:26AM by DJRWolf
via reddit http://ift.tt/2DTsZi2
http://ift.tt/2CbGVpX
Submitted December 27, 2017 at 03:26AM by DJRWolf
via reddit http://ift.tt/2DTsZi2
BleepingComputer
Three Years Later, Hundreds of Sites Still Use Backdoored WordPress Plugins
More than a year after revealing the presence of intentionally malicious code inside the source code of 14 WordPress plugins, experts warn that hundreds of sites are still using the boobytrapped components.
slurp: s3 bucket enumerator part two release (new features including keyword and list enumeration)
http://ift.tt/2ldl7zv
Submitted December 25, 2017 at 07:03AM by jggZW4K8GiuLk
via reddit http://ift.tt/2BUy8JD
http://ift.tt/2ldl7zv
Submitted December 25, 2017 at 07:03AM by jggZW4K8GiuLk
via reddit http://ift.tt/2BUy8JD
GitHub
bbb31/slurp
slurp - S3 bucket enumerator
Data Obfuscation & Crypto in the Season 3 Finale of Mr. Robot (Spoilers)
http://ift.tt/2pAzeEm
Submitted December 27, 2017 at 06:56AM by jszym
via reddit http://ift.tt/2CcqKso
http://ift.tt/2pAzeEm
Submitted December 27, 2017 at 06:56AM by jszym
via reddit http://ift.tt/2CcqKso
Jszym
Mr. Robot Hides Data on Audio Disks, And So Can You! (Season 3 Spoilers)
The finale of season 3 of Mr. Robot involves some serious data obfuscation. Let's do a tear-down and make improvements.
4 Reasons Social Security Disability Claims Are Denied
http://ift.tt/2zB9WWw
Submitted December 27, 2017 at 12:49PM by parmelelawfirm
via reddit http://ift.tt/2BWfBMN
http://ift.tt/2zB9WWw
Submitted December 27, 2017 at 12:49PM by parmelelawfirm
via reddit http://ift.tt/2BWfBMN
Politicaldigestonline
4 Reasons Social Security Disability Claims Are Denied -
If you’re filing for social security disability, a denied claim can leave you feeling dead in your tracks. However, you may have hope if you enlist the assistance of a Social Security attorney, who can teach you about the disability requirements needed to…
Missing NMAP plugin released: vulnerability detection and exploit suggestion. #sorryNessus
http://ift.tt/2BYsGp6
Submitted December 27, 2017 at 02:35PM by isox_xx
via reddit http://ift.tt/2BYOxN6
http://ift.tt/2BYsGp6
Submitted December 27, 2017 at 02:35PM by isox_xx
via reddit http://ift.tt/2BYOxN6
GitHub
vulnersCom/nmap-vulners
NSE noscript based on Vulners.com API. Contribute to vulnersCom/nmap-vulners development by creating an account on GitHub.