Security In 5: Episode 151 - Tools, Tips and Tricks - FCC Cyberplanner Website
http://ift.tt/2D8qr20
Submitted January 12, 2018 at 07:38PM by BinaryBlog
via reddit http://ift.tt/2mw5Uee
http://ift.tt/2D8qr20
Submitted January 12, 2018 at 07:38PM by BinaryBlog
via reddit http://ift.tt/2mw5Uee
Libsyn
Security In Five Podcast: Episode 151 - Tools, Tips and Tricks - FCC Cyberplanner Website
This week's tools, tips and tricks episode is a tip on gathering guidelines on building a cybersecurity program. The Federal Communication Commission has a website for Cybersecurity planning. There you can download great beginning resources, especially if…
Polymorphic and smaller versions of three shell-storm’s x64 shellcodes, including the smallest execve /bin/sh
http://ift.tt/2AVRmt2
Submitted January 12, 2018 at 07:44PM by 0x4ndr3
via reddit http://ift.tt/2ECOfIn
http://ift.tt/2AVRmt2
Submitted January 12, 2018 at 07:44PM by 0x4ndr3
via reddit http://ift.tt/2ECOfIn
Pentester's life
Polymorphic and smaller versions of three shell-storm’s x64 shellcodes, including the smallest execve /bin/sh
Looking at the smallest x64 shellcodes (section Linux / Intel x86-64) in shell-storm’s website, we find the following: Linux/x86-64 – reboot(POWER_OFF) – 19 bytes by zbt Linux/x86…
Reviewing AlwaysOnSSL - The new free & automated Certificate Authority
http://ift.tt/2Fux8dn
Submitted January 12, 2018 at 07:00PM by ayeshrajans
via reddit http://ift.tt/2ASBJ5q
http://ift.tt/2Fux8dn
Submitted January 12, 2018 at 07:00PM by ayeshrajans
via reddit http://ift.tt/2ASBJ5q
ayesh.me
AlwaysOnSSL - The new free & automated Certificate Authority
"New security flaw detected in Intel. It has nothing to do with the Spectre and Meltdown vulnerabilities, but has a huge "destructive potential" too." Local exploit though and have to stay on LAN
http://ift.tt/2mvLmm3
Submitted January 12, 2018 at 06:38PM by cpeacock15
via reddit http://ift.tt/2Dl2MJn
http://ift.tt/2mvLmm3
Submitted January 12, 2018 at 06:38PM by cpeacock15
via reddit http://ift.tt/2Dl2MJn
DW.COM
New security flaw detected in Intel hardware | Business| Economy and finance news from a German perspective | DW | 12.01.2018
Finnish cybersecurity specialist F-Secure has reported another serious flaw in Intel hardware. It has nothing to do with the Spectre and Meltdown vulnerabilities, but has a huge "destructive potential" too.
Chaining Bugs to Steal Yahoo Contacts!
http://ift.tt/2mutEzn
Submitted January 12, 2018 at 09:18PM by sxcurity
via reddit http://ift.tt/2FxTH0L
http://ift.tt/2mutEzn
Submitted January 12, 2018 at 09:18PM by sxcurity
via reddit http://ift.tt/2FxTH0L
www.sxcurity.pro
Chaining Bugs to Steal Yahoo Contacts!
👨🏻💻 Introduction & Background: This is a write-up of how I chained two vulnerabilities (an XSS and a CORS misconfiguration) that allowed me to steal contacts from a victim’s contact book. ...
FILE Structure Exploitation - 'vtable' check bypass
http://ift.tt/2Dqf43t
Submitted January 12, 2018 at 10:27PM by dhavalkapil
via reddit http://ift.tt/2mwSw9F
http://ift.tt/2Dqf43t
Submitted January 12, 2018 at 10:27PM by dhavalkapil
via reddit http://ift.tt/2mwSw9F
https://dhavalkapil.com
FILE Structure Exploitation ('vtable' check bypass)
Understanding the recent check on 'vtable' and a possible bypass technique
34C3 Tool Release: Cachegrab for TrustZone
http://ift.tt/2mw9Rjk
Submitted January 12, 2018 at 09:47PM by digicat
via reddit http://ift.tt/2FxdU6y
http://ift.tt/2mw9Rjk
Submitted January 12, 2018 at 09:47PM by digicat
via reddit http://ift.tt/2FxdU6y
reddit
34C3 Tool Release: Cachegrab for TrustZone • r/netsec
1 points and 0 comments so far on reddit
How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting
http://ift.tt/2mnLbbF
Submitted January 12, 2018 at 09:47PM by tunnelshade
via reddit http://ift.tt/2EB5Cta
http://ift.tt/2mnLbbF
Submitted January 12, 2018 at 09:47PM by tunnelshade
via reddit http://ift.tt/2EB5Cta
reddit
How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt... • r/netsec
7 points and 0 comments so far on reddit
With all the hubbub about Meltdown and Spectre, AMD CPUs are widely regarded as being perfectly safe. Well AMD chips may be safer, but they're not invulnerable.
http://ift.tt/2mlBNWc
Submitted January 12, 2018 at 09:53PM by yourbasicgeek
via reddit http://ift.tt/2mwGLjR
http://ift.tt/2mlBNWc
Submitted January 12, 2018 at 09:53PM by yourbasicgeek
via reddit http://ift.tt/2mwGLjR
ZDNet
AMD processors: Not as safe as you might have thought | ZDNet
With all the hub-bub about Meltdown and Spectre, AMD CPUs are widely regarded as being perfectly safe. Well AMD chips may be safer, but they're not invulnerable.
The Crucial Time for Critical Vulns
http://ift.tt/2mwIHZC
Submitted January 12, 2018 at 11:08PM by ju1i3k
via reddit http://ift.tt/2FvSRSf
http://ift.tt/2mwIHZC
Submitted January 12, 2018 at 11:08PM by ju1i3k
via reddit http://ift.tt/2FvSRSf
Cobalt.io
The Crucial Time for Critical Vulns
Time, like love, is a universal subject in songs. Time is also a universal theme when discussing vulns; it’s a key component of risk…
Challenge Your Threat Intelligence Assumptions: An Interview With Gavin Reid
http://ift.tt/2FyF1OL
Submitted January 13, 2018 at 12:02AM by volci
via reddit http://ift.tt/2FxjAxM
http://ift.tt/2FyF1OL
Submitted January 13, 2018 at 12:02AM by volci
via reddit http://ift.tt/2FxjAxM
Recorded Future
Challenge Your Threat Intelligence Assumptions: An Interview With Gavin Reid
We interviewed Gavin Reid, who recently joined Recorded Future as chief security architect, focusing on next-generation threats and the role that threat intelligence can play in identifying and combating them.
Intel AMT Security Issue Lets Attackers Bypass BIOS and BitLocker Passwords
http://ift.tt/2CYWPkv
Submitted January 13, 2018 at 01:57AM by 808hunna
via reddit http://ift.tt/2D6O2Bc
http://ift.tt/2CYWPkv
Submitted January 13, 2018 at 01:57AM by 808hunna
via reddit http://ift.tt/2D6O2Bc
BleepingComputer
Intel AMT Security Issue Lets Attackers Bypass BIOS and BitLocker Passwords
An F-Secure security researcher has found a way to use Intel's Active Management Technology (AMT) to bypass BIOS passwords, BitLocker credentials, and TPM pins and gain access to previously-secured corporate computers.
"2018 is barely two weeks old, and already it looks like we've got new piece of macOS malware! Hooray :)"
http://ift.tt/2D4DS3T
Submitted January 13, 2018 at 07:26AM by cpeacock15
via reddit http://ift.tt/2DrVinU
http://ift.tt/2D4DS3T
Submitted January 13, 2018 at 07:26AM by cpeacock15
via reddit http://ift.tt/2DrVinU
Tom's Guide
New Mac Malware Hijacks Web Connections: What to Do
This year's first known Mac malware is a DNS hijacker called 'MaMi.' It can also steal passwords, install new programs and take screenshots.
A publicly-disclosed UXSS vulnerability was being exploited against Opera users for over two years (2010 to late 2012)
http://ift.tt/2msFFES
Submitted January 13, 2018 at 08:45AM by Sephr
via reddit http://ift.tt/2mzl6Y4
http://ift.tt/2msFFES
Submitted January 13, 2018 at 08:45AM by Sephr
via reddit http://ift.tt/2mzl6Y4
Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture
http://ift.tt/2mrqZWk
Submitted January 13, 2018 at 11:19AM by volci
via reddit http://ift.tt/2DchNQb
http://ift.tt/2mrqZWk
Submitted January 13, 2018 at 11:19AM by volci
via reddit http://ift.tt/2DchNQb
Troy Hunt
Is India's Aadhaar System Really "Hack-Proof"? Assessing a Publicly Observable Security Posture
India's Aadhaar implementation is the largest biometric system in the world, holding about 1.2 billion locals' data. It's operating in an era of increasingly large repositories of personal data held by both private companies and governments alike. It's also…
An introduction book to ethical hacking for kids?
My newphew is 10, he was excitedly telling me the other day about how he hacked an android game. He didn't actually hack an Android game, I suspect it was a cheat of some kind that he found on Google.Anyway, I wanted to use that enthusiasm to spark an interest in computing, perhaps Cyber Security.I had an idea of getting him a "hacking" book, which would of course excite the devilish imagination of a 10 year old. But what I actually want is a book aimed at kids that takes them through the very basics of Ethical Hacking/Cyber security.Perhaps just a simplified denoscription of an IP address and then showing you how to ping/traceroute etc - with a denoscription of when you might need to do this kind of thing in an ethical hacking scenario - that kind of thing.Any ideas? I've searched around the usual places (Amazon etc) but can't find anything similar.
Submitted January 13, 2018 at 11:10AM by usernameisprobstoolo
via reddit http://ift.tt/2mqy2Pb
My newphew is 10, he was excitedly telling me the other day about how he hacked an android game. He didn't actually hack an Android game, I suspect it was a cheat of some kind that he found on Google.Anyway, I wanted to use that enthusiasm to spark an interest in computing, perhaps Cyber Security.I had an idea of getting him a "hacking" book, which would of course excite the devilish imagination of a 10 year old. But what I actually want is a book aimed at kids that takes them through the very basics of Ethical Hacking/Cyber security.Perhaps just a simplified denoscription of an IP address and then showing you how to ping/traceroute etc - with a denoscription of when you might need to do this kind of thing in an ethical hacking scenario - that kind of thing.Any ideas? I've searched around the usual places (Amazon etc) but can't find anything similar.
Submitted January 13, 2018 at 11:10AM by usernameisprobstoolo
via reddit http://ift.tt/2mqy2Pb
reddit
An introduction book to ethical hacking for kids? • r/security
My newphew is 10, he was excitedly telling me the other day about how he hacked an android game. He didn't *actually* hack an Android game, I...
DDoS Misusing DNS Resolvers - Some examples
http://ift.tt/2D6IE0T
Submitted January 13, 2018 at 12:40PM by nykzhang
via reddit http://ift.tt/2D9fEF4
http://ift.tt/2D6IE0T
Submitted January 13, 2018 at 12:40PM by nykzhang
via reddit http://ift.tt/2D9fEF4
Medium
DNS-based DDoS against Uber
For the last couple of weeks I have been testing DNS resolvers.
A club near my area somehow got hold of my private email?
Sorry if this is isn't the appropiate subreddit for this, but I'm still a bit concerned about what happened to me the other day.Yesterday at 1PM I received an invitation email from a women's fitness club (????), hosting an event about eating healthy and properly or something like that. It was in my junk folder, so I thought it was some sort of scammer at first (which semt super strange, because I never get any scammers or actual spam mails).However, I've also noticed how the email mentioned the small city I live in. Apparently It was where the club was located in, so I opened the email and it was just a short wall of text, saying everyone's invited but theres an entry fee etc.After looking up their name in Google, I instantly knew who they were. It's some tiny women's fitness club named "heroine" next to my local bank, a mile away from my home.But I'm just confused on how they managed to get my email..?I never ever write down my personal email in public places, or if a person asks for it. It's a rare occasion but when asked, I usually make a completely new one, sometimes even on a whole new provider. Within 3 years I've only been asked for an email once (by my gym), and I created a completely new one in gmail, a provider which I do not use on my personal account.Anyone know what's going on?
Submitted January 13, 2018 at 02:04PM by KICKTYAN
via reddit http://ift.tt/2mrOvCP
Sorry if this is isn't the appropiate subreddit for this, but I'm still a bit concerned about what happened to me the other day.Yesterday at 1PM I received an invitation email from a women's fitness club (????), hosting an event about eating healthy and properly or something like that. It was in my junk folder, so I thought it was some sort of scammer at first (which semt super strange, because I never get any scammers or actual spam mails).However, I've also noticed how the email mentioned the small city I live in. Apparently It was where the club was located in, so I opened the email and it was just a short wall of text, saying everyone's invited but theres an entry fee etc.After looking up their name in Google, I instantly knew who they were. It's some tiny women's fitness club named "heroine" next to my local bank, a mile away from my home.But I'm just confused on how they managed to get my email..?I never ever write down my personal email in public places, or if a person asks for it. It's a rare occasion but when asked, I usually make a completely new one, sometimes even on a whole new provider. Within 3 years I've only been asked for an email once (by my gym), and I created a completely new one in gmail, a provider which I do not use on my personal account.Anyone know what's going on?
Submitted January 13, 2018 at 02:04PM by KICKTYAN
via reddit http://ift.tt/2mrOvCP
reddit
A club near my area somehow got hold of my private email? • r/security
Sorry if this is isn't the appropiate subreddit for this, but I'm still a bit concerned about what happened to me the other day. Yesterday at 1PM...
Sending arbitrary Last-Event-ID header values across origins using the EventSource API.
http://ift.tt/2mtbqxD
Submitted January 13, 2018 at 05:05PM by bayotop
via reddit http://ift.tt/2AWfcEE
http://ift.tt/2mtbqxD
Submitted January 13, 2018 at 05:05PM by bayotop
via reddit http://ift.tt/2AWfcEE
Gist
Sending arbitrary Last-Event-ID header values across origins using the EventSource API.
Hospital hit by ransomware: Attackers demand Bitcoin to release control of system
http://ift.tt/2FxzUOL
Submitted January 13, 2018 at 08:21PM by aafrn
via reddit http://ift.tt/2DdSZre
http://ift.tt/2FxzUOL
Submitted January 13, 2018 at 08:21PM by aafrn
via reddit http://ift.tt/2DdSZre
Daily Reporter
Hospital hit by ransomware: Attackers demand Bitcoin to release control of system
GREENFIELD — Hancock Health fell victim to a cyber attack Thursday, with a hacker demanding Bitcoin to relinquish control of part of the hospital’s computer system. Employees knew something was wrong Thursday night, when the network began running more slowly…
DDoS Misusing DNS Resolvers - Example against Uber
http://ift.tt/2D6IE0T
Submitted January 13, 2018 at 11:50PM by nykzhang
via reddit http://ift.tt/2D7BSIh
http://ift.tt/2D6IE0T
Submitted January 13, 2018 at 11:50PM by nykzhang
via reddit http://ift.tt/2D7BSIh
Medium
DNS-based DDoS against Uber
For the last couple of weeks I have been testing DNS resolvers.