Let's Encrypt tls-sni-01 disabled due to credible vulnerability report
http://ift.tt/2ErR92S
Submitted January 10, 2018 at 05:08PM by grepnork
via reddit http://ift.tt/2FkaXGF
http://ift.tt/2ErR92S
Submitted January 10, 2018 at 05:08PM by grepnork
via reddit http://ift.tt/2FkaXGF
letsencrypt.status.io
Let's Encrypt Status
Support for Let's Encrypt services is community-based and information on current status and outages can be found at: https://community.letsencrypt.org
Cisco Talos Blog: Multiple Vulns in CPP and Parity Ethereum Client
http://ift.tt/2mcaA88
Submitted January 10, 2018 at 07:04PM by WorksAtCisco
via reddit http://ift.tt/2EqXyLF
http://ift.tt/2mcaA88
Submitted January 10, 2018 at 07:04PM by WorksAtCisco
via reddit http://ift.tt/2EqXyLF
Talosintelligence
Vulnerability Spotlight: Multiple Vulnerabilities in the CPP and Parity Ethereum Client
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Splunk Specter and Meltdown Checker UF based on speed47
http://ift.tt/2COy2PR
Submitted January 10, 2018 at 07:03PM by jokinawa
via reddit http://ift.tt/2FjHpc1
http://ift.tt/2COy2PR
Submitted January 10, 2018 at 07:03PM by jokinawa
via reddit http://ift.tt/2FjHpc1
GitHub
stressboi/splunk-spectre-meltdown-uf-noscript
splunk-spectre-meltdown-uf-noscript - A noscript modified from speed47 to provide KV-pair results into a Splunk UF noscripted input
Rumble In The Jungo - A Code Execution Walkthrough - CVE-2018-5189
http://ift.tt/2ALNKcL
Submitted January 10, 2018 at 07:00PM by kurtisebear
via reddit http://ift.tt/2Et5QTn
http://ift.tt/2ALNKcL
Submitted January 10, 2018 at 07:00PM by kurtisebear
via reddit http://ift.tt/2Et5QTn
Fidus InfoSecurity | Cyber Security, Penetration Testing, Red Teaming
Rumble In The Jungo - A Code Execution Walkthrough - CVE-2018-5189
Code Execution (CVE-2018-5189) on Jungo Windriver with step by step walkthrough on discovery and exploitation.
Security In 5: Episode 149 - Top 10 Security Tips For Your Network - Don't Forget About Mobile And BYOD
http://ift.tt/2CWQyJs
Submitted January 10, 2018 at 07:33PM by BinaryBlog
via reddit http://ift.tt/2Fm0QB3
http://ift.tt/2CWQyJs
Submitted January 10, 2018 at 07:33PM by BinaryBlog
via reddit http://ift.tt/2Fm0QB3
Libsyn
Security In Five Podcast: Episode 149 - Top 10 Security Tips For Your Network - Don't Forget About Mobile And BYOD
Top 10 security tips for your network and we are at number 10 - Don't forget about mobile and BYOD. It may seem cheap, easy and flexible to allow employees to use their own personal devices to access company email and resources but you could be exposing yourself…
How come the Google Authenticator doesn't have a password?
Feels like another half assed google product
Submitted January 10, 2018 at 07:19PM by 8412risk
via reddit http://ift.tt/2EsJOjw
Feels like another half assed google product
Submitted January 10, 2018 at 07:19PM by 8412risk
via reddit http://ift.tt/2EsJOjw
reddit
How come the Google Authenticator doesn't have a... • r/security
Feels like another half assed google product
A vulnerability in an adult VR app exposes customers details
http://ift.tt/2qPvekb
Submitted January 10, 2018 at 01:40PM by digitalinterruption
via reddit http://ift.tt/2mmVLR6
http://ift.tt/2qPvekb
Submitted January 10, 2018 at 01:40PM by digitalinterruption
via reddit http://ift.tt/2mmVLR6
Continuous Cyber Security | UK | Digital Interruption
Attention SinVR users | Continuous Cyber Security | UK | Digital Interruption
SinVR adult virtual reality application vulnerability puts customers at risk from attackers.
Local Network ARP-Scan
http://ift.tt/2qQU2rN
Submitted January 10, 2018 at 07:39PM by berkdusunurx
via reddit http://ift.tt/2Dg5akU
http://ift.tt/2qQU2rN
Submitted January 10, 2018 at 07:39PM by berkdusunurx
via reddit http://ift.tt/2Dg5akU
www.berkdusunur.net
Local Network Discovery Studies (Lokal Ağda Keşif Çalışmaları)
Hello everyone. Today I will write about Local Network Discovery Studies What Is This Ifconfig? ifconfig is a system administrati...
VMware Horizon desktop agent privilege escalation vulnerability (CVE-2017-4946)
http://ift.tt/2COcZNm
Submitted January 10, 2018 at 09:21PM by h3xstream_
via reddit http://ift.tt/2DhN6qe
http://ift.tt/2COcZNm
Submitted January 10, 2018 at 09:21PM by h3xstream_
via reddit http://ift.tt/2DhN6qe
GoSecure
VMware Horizon (V4H/V4PA) desktop agent privilege escalation vulnerability (CVE-2017-4946) - GoSecure
The latest VMware Horizon vulnerability is via an attack vector that shouldn't be overlooked: bad Windows process handles management. Here's how and why.
Attack of the Week: Group Messaging in WhatsApp and Signal
http://ift.tt/2qKRNGy
Submitted January 10, 2018 at 08:34PM by vamediah
via reddit http://ift.tt/2CXM9GN
http://ift.tt/2qKRNGy
Submitted January 10, 2018 at 08:34PM by vamediah
via reddit http://ift.tt/2CXM9GN
A Few Thoughts on Cryptographic Engineering
Attack of the Week: Group Messaging in WhatsApp and Signal
If you’ve read this blog before, you know that secure messaging is one of my favorite topics. However, recently I’ve been a bit disappointed. My sadness comes from the fact that lately …
MS-ISAC Releases Advisory on PHP Vulnerabilities
http://ift.tt/2EpZPXs
Submitted January 10, 2018 at 10:10PM by ElectricJacob
via reddit http://ift.tt/2AMnNtK
http://ift.tt/2EpZPXs
Submitted January 10, 2018 at 10:10PM by ElectricJacob
via reddit http://ift.tt/2AMnNtK
www.us-cert.gov
MS-ISAC Releases Advisory on PHP Vulnerabilities | US-CERT
The Multi-State Information Sharing & Analysis Center (MS-ISAC) has released an advisory on multiple Hypertext Preprocessor (PHP) vulnerabilities. An attacker could exploit one of these vulnerabilities to take control of an affected system.NCCIC/US-CERT encourages…
Learn how to write a TCP Bind Shell in Assembly (ARM 32-bit)
http://ift.tt/2Dt9iMX
Submitted January 10, 2018 at 10:53PM by fox0x01
via reddit http://ift.tt/2mmyMFU
http://ift.tt/2Dt9iMX
Submitted January 10, 2018 at 10:53PM by fox0x01
via reddit http://ift.tt/2mmyMFU
Azeria-Labs
TCP Bind Shell in Assembly (ARM 32-bit)
Parity Ethereum Client <= v1.6.10 Dapp Browser webproxy token reuse same-origin policy bypass (with poc) (CVE-2017-18016)
http://ift.tt/2CYaprG
Submitted January 10, 2018 at 10:44PM by -tin-
via reddit http://ift.tt/2qQEu7C
http://ift.tt/2CYaprG
Submitted January 10, 2018 at 10:44PM by -tin-
via reddit http://ift.tt/2qQEu7C
GitHub
tintinweb/pub
pub - police line - do not cross...
Security Now 645 The Speculation Meltdown | TWiT.TV
http://ift.tt/2Db5W2h
Submitted January 10, 2018 at 11:35PM by dmp1ce
via reddit http://ift.tt/2FmPeOj
http://ift.tt/2Db5W2h
Submitted January 10, 2018 at 11:35PM by dmp1ce
via reddit http://ift.tt/2FmPeOj
TWiT.tv
Security Now 645 The Speculation Meltdown | TWiT.TV
This week, before we focus upon the industry-wide catastrophe enabled by precisely timing the instructed execution of all contemporary high-performance processor architectures... w…
Perfect SAP Penetration testing. Part 3: The Scope of Vulnerability Search
http://ift.tt/2Fjf1a2
Submitted January 10, 2018 at 11:37PM by vah_13
via reddit http://ift.tt/2D1km8E
http://ift.tt/2Fjf1a2
Submitted January 10, 2018 at 11:37PM by vah_13
via reddit http://ift.tt/2D1km8E
ERPScan
Perfect SAP Penetration testing. Part 3: The Scope of Vulnerability Search
This part of Perfect SAP Penetration testing series demonstrates that sometimes traditional approach does not work and describes how to do the impossible.
OpenSSL command cheatsheet
http://ift.tt/2mfodDC
Submitted January 11, 2018 at 01:56AM by alsam88
via reddit http://ift.tt/2AMhTsJ
http://ift.tt/2mfodDC
Submitted January 11, 2018 at 01:56AM by alsam88
via reddit http://ift.tt/2AMhTsJ
Medium
OpenSSL command cheatsheet
Most common openssl commands and use cases
Commercial vs. Federal
What skills should one concentrate on if they are looking to move from the Federal area of security (NIST, FISMA, FISCAM, Compliance, etc.) to the commercial side of things (Finance, etc?). I have about 15 years on the Federal side (live in DC) and am thinking about making the move to commercial for more options, both professionally and places I can move to.
Submitted January 11, 2018 at 01:39AM by lampshade2818
via reddit http://ift.tt/2D2HjYP
What skills should one concentrate on if they are looking to move from the Federal area of security (NIST, FISMA, FISCAM, Compliance, etc.) to the commercial side of things (Finance, etc?). I have about 15 years on the Federal side (live in DC) and am thinking about making the move to commercial for more options, both professionally and places I can move to.
Submitted January 11, 2018 at 01:39AM by lampshade2818
via reddit http://ift.tt/2D2HjYP
reddit
Commercial vs. Federal • r/security
What skills should one concentrate on if they are looking to move from the Federal area of security (NIST, FISMA, FISCAM, Compliance, etc.) to the...
Reverse Engineering the OBi200 Google Voice Appliance: Part 3
http://ift.tt/2CYJNqj
Submitted January 11, 2018 at 02:14AM by rwestergren
via reddit http://ift.tt/2Euo1YD
http://ift.tt/2CYJNqj
Submitted January 11, 2018 at 02:14AM by rwestergren
via reddit http://ift.tt/2Euo1YD
Randy Westergren
Reverse Engineering the OBi200 Google Voice Appliance: Part 3 - Randy Westergren
In part 1 of this series, I analyzed the firmware of the OBi200 and walked through exploiting some RCE vulns to pop a shell. In part 2, I covered the process of identifying and connecting to the board’s undocumented UART port to access the console. This post…
macOS High Sierra's App Store System Preferences Can Be Unlocked With Any Password
http://ift.tt/2DitVwD
Submitted January 11, 2018 at 01:30AM by nplus
via reddit http://ift.tt/2mlxATi
http://ift.tt/2DitVwD
Submitted January 11, 2018 at 01:30AM by nplus
via reddit http://ift.tt/2mlxATi
Macrumors
macOS High Sierra's App Store System Preferences Can Be Unlocked With Any Password [Updated]
A bug report submitted on Open Radar this week has revealed a security flaw in the current version of macOS High Sierra that allows the App Store...
EMC, VMware security bugs throw gasoline on cloud security fire
http://ift.tt/2DfVkiT
Submitted January 11, 2018 at 02:55AM by DerBootsMann
via reddit http://ift.tt/2mf634Y
http://ift.tt/2DfVkiT
Submitted January 11, 2018 at 02:55AM by DerBootsMann
via reddit http://ift.tt/2mf634Y
Ars Technica
EMC, VMware security bugs throw gasoline on cloud security fire
Backups of virtual machines on some hosts could be accessed or altered by an attacker.
Solving the SANS 2017 Holiday Hack Challenge
http://ift.tt/2Ex6L4T
Submitted January 11, 2018 at 04:33AM by the-useless-one
via reddit http://ift.tt/2CNDDpJ
http://ift.tt/2Ex6L4T
Submitted January 11, 2018 at 04:33AM by the-useless-one
via reddit http://ift.tt/2CNDDpJ
All Your Base Are Belong To Me
SANS Christmas Challenge 2017
'Tis the season to be pwning, falalalala lalalala. As usual, here's my write-up for the 2017 SANS Christmas Challenge. We're greeted by Sam the Snowman, who exposes the situation to us. The North Pole is under siege, attacked by giant falling snowballs, and…